Article Summary
Enable button-based Google Workspace OAuth Single Sign-On in AutoRFP so users sign in with their existing Google Workspace credentials instead of an AutoRFP password — a fast, one-click setup with no custom SAML configuration required.
Estimated Time
5–10 minutes.
Prerequisites
Admin permissions in AutoRFP.
Google Workspace admin rights sufficient to authorize the OAuth connection — the account used to complete the Authenticate step must be able to grant AutoRFP the requested permissions. [[NEEDS SME CONFIRMATION: exact Google Workspace admin role required — Super Admin vs. a delegated admin role]]
All users must have work email addresses matching between AutoRFP and Google Workspace.
Coordination with your team about the upcoming login method change.
‼️ CRITICAL: SSO is an organization-wide change that affects how all users sign in. All users will need to sign in using Google Workspace, and password-based login will be disabled after SSO is enforced.
Step-by-Step Instructions
Step 1: Access Organizational Settings
Navigate to Organizational Settings from the main menu.
Select Integrations.
Locate the SSO section.
Step 2: Select Google Workspace
In the SSO section, select Google Workspace as your identity provider.
Note: The user enabling Google SSO must be an admin in AutoRFP and have Google Workspace admin rights sufficient to authorize the OAuth connection.
Step 3: Authenticate
Click the Authenticate button for Google Workspace.
Sign in using your Google Workspace account credentials.
Confirm the email address matches your current AutoRFP account — authentication will fail if emails don't match.
Grant the requested permissions when prompted, to allow AutoRFP to complete the OAuth connection.
Step 4: Enforce SSO
After successful authentication, click Enforce SSO.
Review the confirmation message carefully.
Confirm that you want to enable SSO for your organization.
Step 5: Communicate Changes to Users
Notify all users about the SSO implementation.
Inform them they'll use their Google Workspace credentials to log in.
Explain what to expect during their next login, including the one-time password migration prompt.
Please note: AutoRFP will require users with existing passwords to enter their AutoRFP.ai password one more time to transfer them to SSO. This happens only once.
What Changes for Users
The table below explains what changes for AutoRFP users once you enforce Google SSO.
Aspect | After enforcement |
Signing in | Users enter their work email on the AutoRFP sign-in screen and are redirected to Google to authenticate. |
Passwords | AutoRFP passwords are no longer used for sign-in. Access is governed by the user's Google Workspace account status. |
First sign-in after enforcement | A user who previously signed in with an AutoRFP password may be asked to enter that password one final time to migrate their account to SSO. This is expected and happens only once. |
Disabling SSO | An administrator can turn SSO back off from AutoRFP's Integrations settings. This restores password-based sign-in, but any user who signed in via SSO while it was active will need to reset their password to sign in with a password again. |
🛠️ Troubleshooting
Common problems admins and users run into when enabling Google SSO in AutoRFP, and how to resolve each one.
Email mismatch between the Google account and AutoRFP account
Authentication fails if the email address on the Google Workspace account doesn't match the email on the existing AutoRFP account. Confirm the two addresses match exactly before retrying. [[NEEDS SME CONFIRMATION: whether an admin can self-serve a fix by editing the AutoRFP account email, or whether this requires contacting AutoRFP support]]
User signs in with a personal Gmail account instead of their Workspace account
A personal @gmail.com account will not match the user's AutoRFP work email, so authentication is expected to fail the same way as any other email mismatch. Have the user sign out of any personal Google account and sign in with their Google Workspace account instead. [[NEEDS SME CONFIRMATION: whether AutoRFP shows a distinct error for a personal Gmail account versus a generic email-mismatch error]]
Popup blocked during the Authenticate step
The Google sign-in window is a popup. If a browser or extension blocks popups for AutoRFP, the Authenticate step may appear to do nothing when selected. Allow popups for your AutoRFP domain and try again. [[NEEDS SME CONFIRMATION: exact behavior when the popup is blocked — silent no-op vs. a visible error message]]
Admin permissions insufficient in Google Workspace to complete the OAuth grant
The signed-in Google account may lack the Workspace admin rights needed to authorize AutoRFP's OAuth connection at the domain level. Have the user retry with an account that holds sufficient Google Workspace admin rights. [[NEEDS SME CONFIRMATION: the exact Google Workspace admin role required, and whether Google shows an "admin approval required" prompt rather than failing the grant outright]]
💡 Tips & Best Practices
Verify all user email addresses match between AutoRFP.ai and Google Workspace before enforcing SSO.
Verify you have the necessary admin permissions in AutoRFP.ai.
Confirm the Google Workspace account you'll use to authenticate has sufficient admin rights to grant the OAuth connection.
✋🏼 Common Mistakes to Avoid
Enabling SSO without notifying users — creates confusion and login failures.
Disabling SSO without planning for password resets — locks users out of accounts.
Forgetting that SSO is organization-wide — affects all users immediately.
Attempting to authenticate with a Google Workspace account that doesn't have sufficient admin rights to grant the OAuth connection.
Related Guides
Need Help?
💬 Live Chat: Available in-app
📚 Learning Centre: learn.autorfp.ai/en


