Overview
This document contains instructions to configure Single Sign-On (SSO) into the Blueink
eSignature App using a Google Workspace connection.
The target audience for this document is Blueink Customers who use Google Workspace as their IdP (Identity Provider).
If you want to setup SSO using a different IdP or connection type, please visit help.blueink.com for additional guides.
Prerequisites
These instructions should be followed by someone who is an Admin of your Google Workspace account, or who otherwise has permissions to create and configure customer applications in Workspace ID.
Summary Instructions
A quick summary of the steps is as follows. Detailed instructions, with screenshots, can be found in the following section.
Log into Google Workspace Admin Console (https://admin.google.com/) as an Administrator, or as a user with permissions to create and configure Workspace ID applications
Click Web and mobile apps under Apps
Select Add custom SAML app from the Add app dropdown
Enter the name of your application and (optionally) a description and your application's logo. Click Continue.
Enter the name of your application and (e.g. “Blueink”) and optional description and your application's logo
Copy the following information under Option 2 and send it to Blueink. Blueink will respond when we have configured the SSO on our end.
IdP Entity ID: the Entity ID from Google
IdP SSO URL: the SSO URL from Google
x509 Certificate: the Certificate from Google
In the Google Admin Console, enter the following information provided by Blueink into the Service provider details form and then click Continue
ACS URL: acs_url provided by Blueink
Entity ID: audience_uri provided by Blueink
Name ID format: EMAIL
Name ID: Basic Information > Primary email
On the next screen add the following two Attributes and click Finish
Google Directory attributes: First name; App attributes: firstName
Google Directory attributes: Last name; App attributes: lastName
Navigate to the User access page for your new Google Workspace app
Grant access to the Groups or Organizational Units of your choice. For the purposes of this guide, you can also simply set the Service status to ON for everyone in the All users in this account tab
Test a login with Using an email address of a User that already exists in your Blueink
eSignature Account.
Log out, and then visit this URL to login:
Detailed Instructions
Log into the Google Workspace Admin Console (https://admin.google.com/) as an Administrator, or as a user with permissions to create and configure Workspace ID applications.
Click Web and mobile apps under Apps:
Select Add custom SAML app from the Add app dropdown:
Enter the name of your application and (optionally) a description and your application's logo. Click Continue.
Send SSO URL, Entity ID, and Certificate to Blueink
Copy the SSO URL, Entity ID, and Certificate from Option 2. Please send these details via email to your Blueink Account rep, or to the Blueink support person assisting with your SSO configuration.
IdP Entity ID: the Entity ID from Google
IdP SSO URL: the SSO URL from Google
x509 Certificate: the Certificate from Google
Blueink will setup the SSO connection on our end, and respond to you once that is complete. Typically this process is quick.
The screenshot below shows where to find the SSO URL, Entity ID, and Certificate.
In the Google Admin Console, enter the following information provided by Blueink into the Service provider details form and then click Continue:
ACS URL: acs_url provided by Blueink
Entity ID: audience_uri provided by Blueink
Name ID format: EMAIL
Name ID: Basic Information > Primary email
Attributes
On the next screen add the following two Attributes:
Google Directory attributes: First name; App attributes: firstName
Google Directory attributes: Last name; App attributes: lastName
Click Finish.
Add Users and Groups
Navigate to the User access page for your new Google Workspace app:
Grant access to the Groups or Organizational Units of your choice. For the purposes of this guide, you can also simply set the Service status to ON for everyone in the All users in this account tab:
Test Your Blueink SSO Connection
Now that you have an SSO Connection set up, you can test it out as follows:
Log out of any active Blueink sessions in your browser
Visit the test SSO login page at: https://secure.blueink.com/auth/login
Enter your email address
You should be redirected to your Microsoft Entra login page and prompted to enter your credentials
You should then be redirected back to the Blueink dashboard and be logged in to your Blueink eSignature Account
If you have any issues, don't hesitate to reach out to [email protected].
Conclusion:
By following these instructions, you'll be able to configure Single Sign-On (SSO) in Blueink eSignature App using a Google Workspace SAML connection. Should you require support during the setup process, please don't hesitate to reach out to [email protected]. Kindly note that the metadata URL should also be sent to this email address for assistance with SSO setup.