Google Workspace SCIM Setup
Configure Google Workspace SCIM provisioning for Doow.
Configure Google Workspace to automatically provision and deprovision users to Doow.
See Google's Set up automated user provisioning guide for full details.
Prerequisites
- Have the SCIM Base URL and Bearer Token from Doow ready (see Configure Doow).
- You must be a Google Workspace super administrator.
Create or select an application
- Sign in to the Google Admin console.
- Go to Apps → Web and mobile apps.
- If you already have a Doow application, select it. Otherwise:
- Select Add app → Add custom SAML app or Add custom app.
- Enter "Doow" as the name and complete the basic setup.
Enable auto-provisioning
- Select Auto-provisioning from the left menu.
- Select Set up auto-provisioning.
Enter Doow credentials
- Paste the SCIM Base URL from Doow into the Endpoint URL field.
- Paste the Bearer Token from Doow into the Bearer token field.
- Select Test connection to verify.
Configure attribute mappings
- Map Google Workspace attributes to Doow:
| Google attribute | Doow attribute |
|---|---|
Primary email | userName |
First name | name.givenName |
Last name | name.familyName |
- Configure any additional attribute mappings as needed.
Configure provisioning scope
- Choose which users to provision:
- All users in your organization — provisions everyone.
- Selected organizational units — provisions users in specific OUs.
- Groups — provisions users in specific groups.
Activate provisioning
- Review your configuration.
- Select Activate to enable auto-provisioning.
Deprovisioning behavior
When a user is removed from the provisioning scope (removed from a group, moved out of an OU, or suspended):
- Google sends a deactivation request to Doow.
- The user's access to Doow is revoked.
- The user remains in Doow but cannot sign in.
Next steps
Return to SCIM Provisioning for troubleshooting and additional configuration options.
Was this page helpful?