# Setting Up SSO with Google Workspace

**Category:** [Security & Access](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/security-access)
**Updated:** 2026-10-04

## Overview

Allow your team to sign in to TotalCtrl using their Google Workspace (Gmail) accounts.
## Step 1 — Create an OAuth app in Google Cloud Console

- Go to Google Cloud Console → **APIs & Services → Credentials → Create credentials → OAuth client ID**.
- Application type: **Web application**.
- Under **Authorised redirect URIs**, add:
- `https://www.totalctrl.app/auth/login/sso/[your-account-uuid]/callback`
- Copy the **Client ID** and **Client secret**.

## Step 2 — Configure SSO in TotalCtrl

- Go to **Settings → Security → SSO → New SSO configuration**.
- Select **Google** as the provider.
- Paste the Client ID and Client secret.
- Set **Domain hint** to your company domain.
- Toggle the configuration **Active** and save.

---

## Related Articles

- [Single Sign-On (SSO)](https://help.totalctrl.app/en-US/articles/single-sign-on-sso)
- [Two-Factor Authentication (2FA)](https://help.totalctrl.app/en-US/articles/two-factor-authentication-2fa)
- [Setting Up SSO with Okta or a Custom OIDC Provider](https://help.totalctrl.app/en-US/articles/setting-up-sso-with-okta-or-a-custom-oidc-provider)
- [API Tokens](https://help.totalctrl.app/en-US/articles/api-tokens)
- [Setting Up SSO with Microsoft / Azure AD](https://help.totalctrl.app/en-US/articles/setting-up-sso-with-microsoft-azure-ad)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)