This guide walks you through configuring Single Sign-On (SSO) between Google Workspace and RollCall using SAML 2.0.
Overview
By completing this setup, your users will be able to:
Log into RollCall using their Google Workspace credentials
Avoid managing separate passwords
Experience a secure and seamless login process
? Before You Begin
Make sure you have:
Admin access to Google Admin Console
Access to the RollCall SSO Setup Wizard
Your school’s RollCall domain (e.g.
schoolname.rollcall.com.au)
⚙️ Step-by-Step Configuration (Google Workspace)
Step 1 – Access Google Admin Console
Go to: https://admin.google.com
Navigate to:
Apps → Web and mobile appsClick:
Add app → Add custom SAML app
Step 2 – Create the Application
Enter the app name:
RollCall(Optional) Upload a RollCall logo
Click Continue
Step 3 – Download Google IdP Details
On the Google Identity Provider details screen:
Click Download Metadata
Take note of:
SSO URL
Entity ID
? You will use this information in the RollCall SSO setup wizard.
Step 4 – Configure Service Provider Details
In the Service Provider Details section:
| Field | Value |
|---|---|
| ACS URL | Provided by RollCall (e.g. https://konect-api-v2.rollcall.com.au/rollcall-sso/v1/acs/) |
| Entity ID | Provided by RollCall (e.g. schoolCodeRollCallSSO) |
? These values are available in the RollCall SSO setup wizard.
Step 5 – Configure Attribute Mapping
Map the following attributes:
| RollCall Attribute | Google Field |
|---|---|
| Primary Email | |
| firstName | First Name |
| lastName | Last Name |
? These mappings ensure users are correctly identified and created in RollCall.
Step 6 – Enable the Application for Users
After saving the app, go to User Access
Turn the app ON for:
All users
orSpecific groups (recommended for testing)
? Recommended for testing:
Enable access for a small test group first
Complete Setup in RollCall
Once Google Workspace is configured:
Open the RollCall SSO Setup Wizard
Upload your metadata file
Confirm attribute mappings
Run a Test Login
Click Activate SSO
Testing the Integration
Before going live:
Use a test account
Confirm:
Successful login via Google
User is matched correctly in RollCall
❗ Troubleshooting Tips
| Issue | Likely Cause | Solution |
|---|---|---|
| User cannot log in | App not enabled | Turn ON for user/group |
| User not found | Email mismatch | Ensure Google email matches RollCall |
| Login fails | Incorrect ACS/Entity ID | Re-check RollCall values |
| Missing user info | Attribute mapping incorrect | Verify mappings |
? Key Notes
RollCall uses email address to identify users
SSO must be activated after testing
Each school’s configuration is secure and isolated
✅ Summary
By completing this setup:
Users log in via Google Workspace
Authentication is handled securely via SAML
Admins maintain control via Google Admin Console
Here to link to:
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article