How to set up Viewer Access (SSO) with Google

Learn how to require Google sign-in for private Flos using Viewer Access (SSO), including Google Cloud Console setup and Custom Domain configuration.

Crafted using Floik

Google Workspace SSO is a Viewer Access option that requires anyone opening a private Flo to sign in with their organization's Google Workspace account first.

Why use it

Private Flos can already be shared with email-gated access, but Google Workspace SSO adds a stronger layer of control — viewers must authenticate with their organization's Google Workspace account before they can view the content, rather than just providing an email address.

How to set it up

In Floik:

  1. Go to Settings, then open Viewer Access (SSO).
  2. Click Add, then select Google Workspace.
  3. Copy the Redirect URI shown on this page — you'll need it for the Google Cloud Console setup below.

In Google Cloud Console:
4. Create a new project, or select an existing one to use for this setup.
5. Go to APIs & Services, then OAuth consent screen.
6. Enter your App name and support email.
7. Under Audience (User type), choose one:

  • Internal — restricts sign-in to users within your own Google Workspace. Only available if your project belongs to one.
  • External — allows any Google account to sign in. In Testing mode, only added test users can access it; once verified and in Production, any Google account can sign in.
  1. Click Next.
  2. Under Contact Information, enter the email address Google should use to notify you of any changes to your project.
  3. On the Finish step, check the box to agree to Google's API Services User Data Policy, then click Continue.
  4. Click Create to finish setting up the OAuth consent screen.
  5. Go to the Clients section and click Create client.
  6. Choose Web application as the application type.
  7. Under Authorized redirect URIs, paste the Redirect URI you copied from Floik in step 3.
  8. Click Create. Google generates a Client ID and Client Secret — copy both, and keep the Client Secret safe since it shouldn't be shared.

Back in Floik:
16. Return to Viewer Access (SSO) settings.
17. Paste the Client ID and Client Secret into their respective fields.
18. (Optional) If you've set up a Custom Domain for your Flos, select it from the Domain dropdown. If you haven't, this field shows "No domains available" — you can proceed without it, and your protected Flo is served under Floik's default URL instead.
19. Click Save and Activate.
20. When sharing a private Flo, select Google Workspace SSO as the access option.

Once set up, viewers opening the Flo are prompted to sign in with their Google Workspace account before they can view it.

Best practices

  • Keep your Client Secret private — don't share it outside your team.
  • Choose Internal audience type if only members of your own Google Workspace should ever need access.
  • If using External with Testing mode, verify the sign-in flow with a test user before publishing broadly.

✨ Create using AI Seamlessly – Chrome Browser Extension Required! ✨

Trusted by enterprises & innovative SaaS companies

University of Connecticut
Rise up
Precision Pumping Systems
BHSF
Certiverse