CloudrawSetup guides
Download PDF
Sign-in setup · For IT admins

Google Workspace

Sign in with Google Workspace accounts through an OAuth client in your Google Cloud project.

Last updated 6 October 2026 · Download this guide as PDF

Overview

With Google Workspace your people sign in to Cloudraw Connect with their Google work account. Google checks the password and 2-Step Verification. Cloudraw never sees the password.

You create an OAuth client in a Google Cloud project that belongs to your Workspace organization, then paste its ID and secret into Cloudraw. Allow about 15 minutes.

You need

  • A Google Workspace account that can create projects and OAuth clients in the Google Cloud console for your organization.
  • A Google Workspace super admin for the 2-Step Verification settings, if you want to change them.
  • The Owner or Security admin role in the Cloudraw admin console.

Step 1. Copy the redirect URI from Cloudraw

  1. Open Identity & SSOIn the Cloudraw admin console go to Settings→Identity & SSO. Turn on Workspace sign-in if it is not on yet.
  2. Copy the redirect URIIn Your identity provider, copy the value under Redirect URI (add this at your provider). It looks like this: https://id-stg.cloudraw.com/ui/login/login/externalidp/callback
  1. Open the Google Cloud consoleGo to console.cloud.google.com, signed in with your Workspace account. Create a project (for example cloudraw-sign-in) or pick an existing one that belongs to your organization.
  2. Open the consent screen settingsGo to APIs & Services→OAuth consent screen. In newer consoles this is called Google Auth Platform; click Get started there.
  3. App informationApp name: Cloudraw. User support e-mail: your IT address.
  4. Audience: InternalChoose Internal. Only users in your Google Workspace organization can then sign in, and Google does not need to review the app.
  5. Contact e-mailAdd your IT address and finish.
  6. ScopesCloudraw only asks for openid, email and profile. These are basic scopes, and you do not need to add anything sensitive.
Important: choose Internal

The Internal audience is what limits sign-in to your own organization. With External, any Google account could reach your workspace's sign-in page and create an account in your workspace. That account still cannot reach anything without your access and device trust rules, but it would use a seat. Always use Internal.

Step 3. Create the OAuth client

  1. Create the clientGo to APIs & Services→Credentials→Create credentials→OAuth client ID (or Google Auth Platform→Clients→Create client).
  2. Application typeChoose Web application and name it Cloudraw.
  3. Authorized redirect URIUnder Authorized redirect URIs click Add URI and paste the Cloudraw redirect URI. Leave Authorized JavaScript origins empty.
  4. Create and copyClick Create. Copy the Client ID (ends in .apps.googleusercontent.com) and the Client secret. Google may show the secret only once, so you can also download the JSON file.

Step 4. Connect Google in Cloudraw

  1. Choose GoogleIn Settings→Identity & SSO→Your identity provider, choose Google.
  2. Paste the valuesSee the table below.
  3. Save and testSave, then sign in from Cloudraw Connect on a test computer. You should land on Google's account chooser.
Cloudraw fieldValueRequired
Client IDThe OAuth client IDYes
Client secretThe OAuth client secretYes
Button labelWhat the sign-in button says. Default: "Google".No
Only allow sign-in through the providerOn: people go straight to Google, and Cloudraw passwords are turned off. Off: the Cloudraw sign-in page shows a password form and a "Sign in with Google" button.No

People and groups

A person who signs in through Google for the first time is added to People automatically and uses a seat. You can also add people in advance under People→Add a person with their Google e-mail address.

Cloudraw has no SCIM provisioning from Google Workspace, so groups are not imported from Google. Create Cloudraw groups (for example Finance, Engineering) and use them in access rules. See Organize people with groups.

When you suspend or delete a user in Google Workspace, they can no longer sign in to Cloudraw. Computers they already enrolled keep following your device trust and access rules, so also Suspend the person in Cloudraw. Their devices then lose access at once.

2-Step Verification at Google

For Google users, the second sign-in step is Google's own 2-Step Verification. Cloudraw does not add its own e-mail code for Google users, unless the workspace sent Cloudraw invitations before Google was connected. See Two-factor authentication.

To require 2-Step Verification:

  1. Open the Admin consoleGo to admin.google.com, then Security→Authentication→2-step verification.
  2. Allow itTick Allow users to turn on 2-Step Verification.
  3. Enforce itSet Enforcement to On (or Turn on from a date), with a new-user enrollment period so people have time to set it up.
  4. Choose methodsUnder Methods, prefer Only security key or Any except verification codes via text, phone call for stronger protection.
Tip

You can apply 2-Step Verification to one organizational unit first, for example IT, before rolling it out to everyone.

Troubleshooting

Message or symptomCause and fix
Google: Error 400: redirect_uri_mismatchThe redirect URI in the OAuth client is not exactly the one Cloudraw shows. Paste it again under Authorized redirect URIs of the Web application client.
Google: Error 403: org_internalThe person is signing in with an account outside your Workspace organization, for example a personal Gmail. They must use their work account.
Google: invalid_clientWrong client ID or secret. Paste them again in Cloudraw.
Cloudraw: "The provider could not be configured" when savingCheck the client ID and secret for typos or extra spaces.
Cloudraw Connect: "seat quota reached"All seats on your plan are used.