Skip to main content
Connect Google Workspace to let members sign in through your identity provider and keep their access to your Hyperline account aligned with your directory.
Single sign-on and user provisioning are enterprise features available on demand. Contact Hyperline through the in-app chat to enable them for your account.
Google Workspace is currently the only supported identity provider. A member with the Manage authentication permission configures a separate connection for each Hyperline account.

Before you start

You need:
  • A Hyperline role that includes the Manage authentication permission. This permission also gates enabling or disabling multi-factor authentication. See Users & permissions.
  • A Google Workspace administrator account
  • The Google Admin SDK Directory API enabled for users and groups
  • Pop-ups allowed for Hyperline in your browser

Understand the connection

Single sign-on and directory synchronization are configured separately:
A connection can show Connected for single sign-on while directory synchronization still requires configuration. Provision users in Hyperline only controls whether Hyperline applies synchronized directory data to account memberships.

Connect Google Workspace

1

Navigate to Settings > General

2

Click Set up in the Single sign-on section

3

Complete the Google Workspace setup assistant

Configure single sign-on and verify your Google Workspace domain.
4

Return to Hyperline

Hyperline displays the identity provider, domain, and connection status.
5

Configure directory synchronization

Click Configure next to Directory synchronization from Google Workspace, then authorize access with a Google Workspace administrator account. Grant access to both users and groups.
6

Wait for synchronization to complete

Hyperline displays In progress while Google Workspace data is being synchronized, then Connected when it is ready.
Directory synchronization can take a few minutes after administrator authorization. Keep the authorization window open until it confirms completion.

Reconfigure single sign-on

Click Reconfigure to reopen the setup assistant for the existing connection. Use it to update single sign-on or finish domain verification without deleting the connection. When you close the setup assistant, Hyperline refreshes the connection details and statuses automatically. To authorize user and group synchronization, use Configure in the directory synchronization line instead.

Manage directory synchronization

Once directory synchronization is connected, Hyperline displays:
  • Last synchronization: the date, time, and result of the latest synchronization
  • Synchronize now: fetches the latest users and groups from Google Workspace
  • Provision users in Hyperline: controls whether synchronized users become members of this Hyperline account
Click Synchronize now, then confirm the action. Synchronization continues in the background and can take a few minutes. If it fails, hover over Failed to view the error returned by the identity provider.
Google Workspace directory synchronization runs automatically. You can also start it manually, but a new manual synchronization cannot start if the connection was synchronized during the previous 30 minutes.

Provision users in Hyperline

After directory synchronization is connected, enable Provision users in Hyperline and click Save changes. Hyperline then imports existing directory users and continues to apply user and group changes. Provisioning follows these rules:
  • A new directory user creates a member in this Hyperline account.
  • If the email address already belongs to a Hyperline user, Hyperline links that user instead of creating a duplicate.
  • Profile and group changes update the provisioned member and their assigned role.
  • Suspending a Google Workspace user removes their provisioned access. Unsuspending them restores the existing membership instead of creating a duplicate.
  • Deleting a directory user removes every provisioned Hyperline membership linked to that identity, except account owner memberships.
  • Account owners are never automatically removed or suspended by directory synchronization.
You can continue to invite and manage members manually. A user can have a manually managed membership in one Hyperline account and a provisioned membership in another. Directory changes only control memberships marked Provisioned; they do not remove manually managed access. Provisioned memberships display a Provisioned label in Settings > Team > Members. Their role and removal actions are disabled because their access is controlled through Google Workspace. Update the directory or role provisioning rules instead.

Assign roles from Google groups

Configure role provisioning from Settings > Team > Roles.
1

Open Role provisioning

2

Click Add mapping

3

Select a Google group and a Hyperline role

4

Save the mapping

Each Google group can be mapped once. Use the actions menu on an existing mapping to edit its Hyperline role or delete the mapping. If a user belongs to several mapped groups, the first matching mapping determines their role. When no group matches, Hyperline assigns the Default role configured in Role provisioning. If no specific provisioning default is selected when provisioning is enabled, Hyperline uses the account’s standard default role. Adding, editing, or deleting a mapping, or changing the default role, reconciles existing provisioned memberships automatically.
If a recently created Google group does not appear when you add a mapping, return to Settings > General and click Synchronize now. Wait for the synchronization to complete, then reopen the group selector.

Troubleshoot configuration

Single sign-on is connected, but directory synchronization is not

This is expected when only the authentication setup is complete. Click Configure in the directory synchronization line and authorize access with a Google Workspace administrator account.

Google groups are unavailable

Confirm that the Google Admin SDK Directory API is enabled and that the administrator granted access to both users and groups. Configure directory synchronization again if authorization is still required, then start a manual synchronization.

Synchronization failed

Hover over Failed next to the latest synchronization to view the provider error. Resolve the reported Google Workspace configuration or authorization issue, then click Synchronize now.