
With Google SSO, your staff and portal users sign in to Xcellerate OPS with their Google Workspace or Google account instead of a separate password. You connect it with an OAuth client from your own Google Cloud project. It suits MSPs and service businesses that already run on Google Workspace.
TL;DR
- Add the Google SSO card under Settings → Integrations → Authentication.
- In Google Cloud, create a Web application OAuth client with the redirect URI from OPS, then paste the client ID and secret on the card.
- OPS matches the Google email address to an existing user. No accounts are created automatically.
Before you start
- You are an admin of your OPS workspace. Only admins can change these settings.
- You have a Google Cloud project with an OAuth consent screen and can create an OAuth client ID of type Web application.
- The people who will sign in already exist as users in OPS, with the same email address as their Google account.
Step 1: add the Google SSO card
- Go to Settings → Data and security → Integrations.
- Drag Google SSO from the catalog on the right into the Authentication category, or click it.
- The card Allow sign-in with Google appears.
The Integrations page with empty categories (Mailbox, Authentication, Payments, Billing) and the catalog of available integrations on the right.
Step 2: copy the redirect URI
Below the cards you see Register this redirect URI with each provider. Copy the URI shown there. It follows the pattern https://auth.<platform-domain>/sso/google/callback. One URI serves all workspaces.
Step 3: create the OAuth client in Google Cloud
- In your Google Cloud project, create an OAuth client ID of type Web application.
- Add the copied URI as an authorized redirect URI.
- Note the client ID (in the form
xxxx.apps.googleusercontent.com) and the client secret. OPS requests the scopesopenid email profileat sign-in.
Step 4: fill in the card and enable it
- Paste the Client ID and Client secret on the card.
- Switch on Enable on the login page.
- Click Save. You see "Sign-in options saved."
Step 5: profile pictures and a test
- Optional: switch on Profile pictures from the sign-in account. The toggle appears once a provider is enabled and saves immediately.
- Test: open your workspace login page and use the Google button with an account whose email matches an existing OPS user.
What happens after you connect
- The login page shows a Google button. OPS matches the Google email address to an existing user in your workspace. Staff land in the app, client portal users in the portal.
- SSO counts as a strong sign-in factor, so workspaces that require passkeys still accept it. Read more about security and access control.
- With pictures on, OPS stores the Google picture for people with no uploaded picture and no Gravatar. This runs in the background, refreshes at most every 30 days and never overwrites an uploaded or deliberately removed picture.
Good to know
- Invite users first. Disabled (offboarded) users are refused, even with a valid Google sign-in.
- Google always shows an account picker.
- The client secret field is write-only. Leave it blank to keep the saved secret.
- You can only remove a card after you Disable it. Removing it also clears the stored client ID and secret.
- OPS never sees Google passwords; sign-in uses OAuth 2.0 / OpenID Connect.
Troubleshooting
- "No account exists in this workspace for that identity." There is no active OPS user with that Google email address.
- "Your identity provider did not return an email address." Google returned no email address.
- "Sign-in could not be completed. Please try again." The sign-in took longer than 10 minutes or the code exchange failed. Check the client secret in particular.
- "Disable this integration before removing it." Click Disable first.
Get started
Want your team to sign in with Google? Get started for free and connect Google SSO from Settings. See all EU integrations too.

