Skip to content

Google Workspace

TapPass Cloud supports Single Sign-On with Google Workspace. TapPass is registered as a single OAuth application owned by TapPass — you do not create an OAuth client. Because TapPass only requests basic sign-in claims (openid, profile, email), your users can normally sign in and consent for themselves.

You only need an administrator step if your Workspace restricts unconfigured third-party apps (Admin console → API controls set to block unconfigured apps). In that case an administrator marks the TapPass application Trusted one time.

Unlike Microsoft Entra, Google has no single admin-consent link. Trusting an app is a short click-path in the Google Admin console, below.

  1. Sign in to the Google Admin console with a super administrator account.

  2. Go to Security → Access and data control → API controls.

  3. Under App access control, click Manage Third-Party App Access.

  4. Click Configure new app → OAuth App Name Or Client ID.

  5. Search by OAuth client ID and paste the TapPass Cloud client ID:

    215638106444-j33hq0nbe8lkd6vh6jsmdbfliqgoago1.apps.googleusercontent.com
  6. Select the TapPass result, choose the scope of the change (your whole organization, or specific organizational units), and set access to Trusted.

  7. Save. Your users can now sign in with Sign in with Google without hitting the unconfigured-app block.

TapPass sends Google’s hd (hosted-domain) hint so the sign-in screen only offers accounts from your Workspace domain, and rejects personal Gmail accounts. No configuration is required on your side.

“Access blocked: authorization error” / “This app is blocked”

Section titled ““Access blocked: authorization error” / “This app is blocked””

Your Workspace blocks unconfigured third-party apps and TapPass hasn’t been trusted yet. Complete the Trust the TapPass application steps above.

TapPass maps users to your organization by their verified Google email. If you need a hard gate on top of that, restrict the TapPass app’s access to specific organizational units in step 6, or contact your TapPass representative about a domain allowlist.