Single Sign-On (SSO) lets your team sign in to GC AI using your organization’s existing identity provider (IdP). GC AI supports SSO through WorkOS, which is compatible with any IdP that supports SAML or OIDC protocols.
Your organization must use an IdP that supports SAML or OIDC (e.g. Okta, Azure AD, OneLogin, Google Workspace, JumpCloud)
You need access to your IdP’s admin console to create a new application
Domain verification must be completed before SSO can be enabled
You can also invite your IT admin into your organization on a trial seat to complete the SSO setup. Just provide their email to support@gc.ai and we will add them.
After completing the configuration, select Test Connection to verify everything works. A successful test confirms that your IdP and GC AI can communicate properly.If the test fails, see the troubleshooting section below.
If you run a test of your SAML SSO connection and it does not pass, the most common causes are:Missing or incorrect attribute mappingsYour IdP must send the required attributes (id, email, firstName, lastName) in the SAML assertion. If any are missing or mapped to the wrong field names, the connection test fails.How to fix:
Open your IdP’s admin console and navigate to the GC AI SAML application.
Check the attribute statements (sometimes called “attribute mappings” or “parameters”).
Verify each required attribute is mapped to the correct user field in your directory.
Save and re-run the test.
Incorrect ACS URL or Entity IDIf the ACS URL or SP Entity ID in your IdP does not match what GC AI provided during setup, the SAML handshake fails.How to fix:
Go back to the SSO configuration link in GC AI and copy the ACS URL and SP Entity ID exactly as shown.
Paste them into your IdP’s SAML application settings, replacing any previous values.
Save and re-run the test.
Certificate or metadata issuesAn expired or incorrect X.509 certificate prevents GC AI from validating the SAML response.How to fix:
Download a fresh copy of your IdP’s metadata XML or X.509 certificate.
Invalid Client ID or Client SecretIf the credentials entered during setup don’t match what your IdP issued, authentication fails.How to fix:
Open your IdP’s admin console and locate the GC AI OIDC application.
Copy the Client ID and Client Secret directly from your IdP.
Re-enter them in the GC AI SSO configuration.
Save and re-run the test.
Incorrect Discovery EndpointThe discovery endpoint URL must point to your IdP’s OpenID Connect discovery document (usually ending in /.well-known/openid-configuration).How to fix:
Verify the discovery endpoint URL in your IdP’s documentation.
Confirm it is accessible by opening it in a browser. You should see a JSON document.
Update the URL in the GC AI SSO configuration and re-run the test.