Skip to main content
Enterprise organizations can connect Google Workspace for dashboard sign-in. Aixy keeps the organization’s roles, projects, API keys, and permissions; the identity provider authenticates the person signing in.

Connect Google Workspace

  1. As an Owner or Org admin, open Single Sign-On from the account settings menu and choose Connect identity provider → Google Workspace.
  2. Create a Google Web OAuth application and register the exact callback URL shown in the editor.
  3. Enter the client ID, client secret, connection name, and Google Workspace domain.
  4. Choose a project-only default role, including a custom role, and project assignments for newly provisioned members.
  5. Save, completing the recent sign-in confirmation when prompted.
Use the callback displayed by Aixy. Keep the secret in the setup form and avoid reloading while confirming your identity; the form draft is held only in memory.

Verify member access

Enter your email at sign-in and choose Continue with organization SSO. Test with a project-role account and confirm its role and projects in Users. Existing users with organization-administration permissions explicitly link from a recent passkey-authenticated session; matching their email alone does not link a protected account. SSO can provision a Project user or Project admin with the configured default projects. Protected organization roles remain an explicit Owner decision. An authenticated organization picker can start SSO for the selected organization. If email discovery is ambiguous, sign in with your personal password or passkey and choose the organization. SSO proof applies to its originating organization and to organizations you create while signed in or explicitly join through an invitation using that provider. Returning to those organizations requires the same active provider and membership in the original organization. Their own required SSO policy still applies; the proof does not unlock unrelated memberships or allow account password/passkey changes.

Require SSO

Before enabling Require Single Sign-On, the Owner must register a passkey and confirm the recovery Owner. Verify the Google connection and the Owner’s recovery sign-in first. Enabling required SSO revokes local sessions for that organization and requires its identity provider before entering it. Personal password recovery does not bypass this policy. The designated Owner retains a passkey recovery path. Keep this account available and protected; disable required SSO before disconnecting its identity provider.

Offboard a member

Use user suspension in Aixy to revoke sessions, project API keys, and MCP tokens. Treat Aixy offboarding as an explicit administration step. Removing an identity connection blocks new logins and revokes its SSO sessions while cleanup completes.