- Google Workspace for authentication and Google directory synchronization
- SAML and SCIM for SAML authentication and SCIM user and group provisioning
Before you start
You need:- A Hyperline role that includes the Manage authentication permission. This permission also gates enabling or disabling multi-factor authentication. See Users & permissions
- Pop-ups allowed for Hyperline in your browser
- A Google Workspace administrator account
- The Google Admin SDK Directory API enabled for users and groups
Understand the connection
Authentication and provisioning use different mechanisms depending on your identity provider:Connect Google Workspace
Navigate to Settings > General
Click Set up in the Single sign-on section and select Google Workspace
Complete the Google Workspace setup assistant
Return to Hyperline
Configure directory synchronization
Wait for synchronization to complete
Connect SAML and SCIM
Navigate to Settings > General
Click Set up in the Single sign-on section and select SAML and SCIM
Complete the setup assistant
Return to Hyperline
Confirm that SCIM provisioning is configured
Reconfigure single sign-on
Click Reconfigure to reopen the setup assistant for the existing connection. Use it to update single sign-on, finish domain verification, or complete SCIM configuration without deleting the connection. When you close the setup assistant, Hyperline refreshes the connection details and statuses automatically. For Google Workspace, use Configure in the directory synchronization line to authorize user and group synchronization. For SAML connections, configure SCIM in the setup assistant and your identity provider.Manage directory synchronization
Once directory synchronization is connected, Hyperline displays:- Last synchronization: the date, time, and result of the latest synchronization
- Synchronize now: fetches the latest users and groups from Google Workspace
- Provision users in Hyperline: controls whether synchronized users become members of this Hyperline account
Provision users in Hyperline
After Google directory synchronization or SCIM provisioning is configured, enable Provision users in Hyperline and click Save changes. Hyperline then applies user and group changes received from the identity provider. Provisioning follows these rules:- A new directory or SCIM user creates a member in this Hyperline account.
- If the email address already belongs to a Hyperline user, Hyperline links that user instead of creating a duplicate.
- Profile and group changes update the provisioned member and their assigned role.
- Suspending or blocking a user in the identity provider removes their provisioned access. Restoring them reactivates the existing membership instead of creating a duplicate.
- Deleting a user in the identity provider removes every provisioned Hyperline membership linked to that identity, except account owner memberships.
- Account owners are never automatically removed or suspended by identity provider provisioning.
Assign roles from identity provider groups
Configure role provisioning from Settings > Team > Roles.Open Role provisioning
Click Add mapping
Select an identity provider group and a Hyperline role
Save the mapping

