CINXE.COM
Bitwarden + Google SAML - Password Manager - Bitwarden Community Forums
<!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8"> <title>Bitwarden + Google SAML - Password Manager - Bitwarden Community Forums</title> <meta name="description" content="Hello! I am trying to set up SSO login via Google SAML. I followed these instructions: Now when I’m trying to log in using SSO, I am still prompted for a master password. When I’m trying to test SAML login in Google&hellip;"> <meta name="generator" content="Discourse 3.5.0.beta1-dev - https://github.com/discourse/discourse version a0e1a1216112161465f976cd1121a00f044612e3"> <link rel="icon" type="image/png" href="https://community.bitwarden.com/uploads/default/optimized/3X/7/a/7a270efc3aae0860aca62ffb8641044e2668ea37_2_32x32.png"> <link rel="apple-touch-icon" type="image/png" href="https://community.bitwarden.com/uploads/default/optimized/1X/a499e237d3b459cb4e0f722f024ad44b4a4755d6_2_180x180.png"> <meta name="theme-color" media="all" content="#175DDC"> <meta name="color-scheme" content="light"> <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, viewport-fit=cover"> <link rel="canonical" href="https://community.bitwarden.com/t/bitwarden-google-saml/28292" /> <link rel="search" type="application/opensearchdescription+xml" href="https://community.bitwarden.com/opensearch.xml" title="Bitwarden Community Forums Search"> <link href="/stylesheets/color_definitions_bitwarden-light_2_2_b2494187e1617e66c85bb9d55f8a1c7518d319b0.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" class="light-scheme"/> <link href="/stylesheets/desktop_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="desktop" /> <link href="/stylesheets/checklist_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="checklist" /> <link href="/stylesheets/discourse-details_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-details" /> <link href="/stylesheets/discourse-docs_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-docs" /> <link href="/stylesheets/discourse-lazy-videos_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-lazy-videos" /> <link href="/stylesheets/discourse-local-dates_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-local-dates" /> <link href="/stylesheets/discourse-narrative-bot_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-narrative-bot" /> <link href="/stylesheets/discourse-presence_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-presence" /> <link href="/stylesheets/discourse-reactions_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-reactions" /> <link href="/stylesheets/discourse-solved_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-solved" /> <link href="/stylesheets/discourse-topic-voting_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-topic-voting" /> <link href="/stylesheets/discourse-user-notes_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-user-notes" /> <link href="/stylesheets/docker_manager_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="docker_manager" /> <link href="/stylesheets/footnote_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="footnote" /> <link href="/stylesheets/poll_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="poll" /> <link href="/stylesheets/spoiler-alert_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="spoiler-alert" /> <link href="/stylesheets/discourse-reactions_desktop_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-reactions_desktop" /> <link href="/stylesheets/discourse-topic-voting_desktop_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="discourse-topic-voting_desktop" /> <link href="/stylesheets/poll_desktop_b53fd240117d170debdb06f3083d62b4b981c29d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="poll_desktop" /> <link href="/stylesheets/desktop_theme_8_943d7e52cbb2ebeadb1cf605247da70771555236.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="desktop_theme" data-theme-id="8" data-theme-name="custom header links"/> <link href="/stylesheets/desktop_theme_20_d9ebd59490c018d821b1668a920abf0368d1be8e.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="desktop_theme" data-theme-id="20" data-theme-name="discourse docs card filter"/> <link href="/stylesheets/desktop_theme_19_7cd90e4037d16a8f8fc0cfcb65a0df7e7879b46a.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="desktop_theme" data-theme-id="19" data-theme-name="discourse-mermaid-theme-component"/> <link href="/stylesheets/desktop_theme_11_c839ac74efd7814290e983264998b437b4769c1d.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="desktop_theme" data-theme-id="11" data-theme-name="welcome link banner"/> <link href="/stylesheets/desktop_theme_2_58f4820990b68d7dc01dffdd2ad779a69c097e11.css?__ws=community.bitwarden.com" media="all" rel="stylesheet" data-target="desktop_theme" data-theme-id="2" data-theme-name="default"/> <link href="//fonts.googleapis.com/css?family=Open+Sans:300,400,600,700,300italic,400italic,600italic" rel="stylesheet" type="text/css"> <meta id="data-ga-universal-analytics" data-tracking-code="G-G8EL98JE92" data-json="{"cookieDomain":"auto"}" data-auto-link-domains=""> <script async src="https://www.googletagmanager.com/gtag/js?id=G-G8EL98JE92" nonce="INAbjWac0J8bneQIKRtvjKzdK"></script> <script defer src="/assets/google-universal-analytics-v4-9e072ae9f23d2cccab25fd7b2debde9018749ade5240fda6e25d27be6a95ed2e.js" data-discourse-entrypoint="google-universal-analytics-v4" nonce="INAbjWac0J8bneQIKRtvjKzdK"></script> <link rel="alternate nofollow" type="application/rss+xml" title="RSS feed of 'Bitwarden + Google SAML'" href="https://community.bitwarden.com/t/bitwarden-google-saml/28292.rss" /> <meta property="og:site_name" content="Bitwarden Community Forums" /> <meta property="og:type" content="website" /> <meta name="twitter:card" content="summary" /> <meta name="twitter:image" content="https://community.bitwarden.com/uploads/default/original/3X/7/f/7f03815c05cadc57a3915c4e7d01826f041b39ac.png" /> <meta property="og:image" content="https://community.bitwarden.com/uploads/default/original/3X/7/f/7f03815c05cadc57a3915c4e7d01826f041b39ac.png" /> <meta property="og:url" content="https://community.bitwarden.com/t/bitwarden-google-saml/28292" /> <meta name="twitter:url" content="https://community.bitwarden.com/t/bitwarden-google-saml/28292" /> <meta property="og:title" content="Bitwarden + Google SAML" /> <meta name="twitter:title" content="Bitwarden + Google SAML" /> <meta property="og:description" content="Hello! I am trying to set up SSO login via Google SAML. I followed these instructions: Now when I’m trying to log in using SSO, I am still prompted for a master password. When I’m trying to test SAML login in Google app’s settings, I receive the error: There was an unexpected error during single sign-on. Please close this page and try again. Unsolicited responses are not allowed for idp "https://accounts.google.com/o/saml2?idpid=***". If I activate the option “Allow Unsolicited Authentica..." /> <meta name="twitter:description" content="Hello! I am trying to set up SSO login via Google SAML. I followed these instructions: Now when I’m trying to log in using SSO, I am still prompted for a master password. When I’m trying to test SAML login in Google app’s settings, I receive the error: There was an unexpected error during single sign-on. Please close this page and try again. Unsolicited responses are not allowed for idp "https://accounts.google.com/o/saml2?idpid=***". If I activate the option “Allow Unsolicited Authentica..." /> <meta property="og:article:section" content="Ask the Community" /> <meta property="og:article:section:color" content="3AB54A" /> <meta property="og:article:section" content="Password Manager" /> <meta property="og:article:section:color" content="0088CC" /> <meta name="twitter:label1" value="Reading time" /> <meta name="twitter:data1" value="1 mins 🕑" /> <meta name="twitter:label2" value="Likes" /> <meta name="twitter:data2" value="1 ❤" /> <meta property="article:published_time" content="2021-04-01T13:32:03+00:00" /> <meta property="og:ignore_canonical" content="true" /> <script type="application/ld+json">{"@context":"http://schema.org","@type":"QAPage","name":"Bitwarden + Google SAML","mainEntity":{"@type":"Question","name":"Bitwarden + Google SAML","text":"Hello!\n\nI am trying to set up SSO login via Google SAML. I followed these instructions:\n\n[image]\n\n<a href=\"https://bitwarden.com/help/configure-sso-saml/\" target=\"_blank\" rel=\"noopener nofollow ugc\">SAML 2.0 Configuration | Bitwarden Help Center<\/a>\n\nWith a Bitwarden enterprise plan, you can enable Login with SSO for SAML 2.0 authentication.\n\n[image]\n\n<a href=\"https://bitwarden.com/help/saml-google/\" target=\"_blank\" rel=\"noopener nofollow ugc\">Google …<\/a>","upvoteCount":0,"answerCount":0,"datePublished":"2021-04-01T13:32:03.203Z","author":{"@type":"Person","name":"Not_Honest","url":"https://community.bitwarden.com/u/Not_Honest"}}}</script> </head> <body class="crawler browser-update"> <header> <a href="/"> Bitwarden Community Forums </a> </header> <div id="main-outlet" class="wrap" role="main"> <div id="topic-title"> <h1> <a href="/t/bitwarden-google-saml/28292">Bitwarden + Google SAML</a> </h1> <div class="topic-category" itemscope itemtype="http://schema.org/BreadcrumbList"> <span itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem"> <a href="/c/support/pm-ask-the-community/62" class="badge-wrapper bullet" itemprop="item"> <span class='badge-category-bg' style='background-color: #3AB54A'></span> <span class='badge-category clear-badge'> <span class='category-name' itemprop='name'>Ask the Community</span> </span> </a> <meta itemprop="position" content="1" /> </span> <span itemprop="itemListElement" itemscope itemtype="http://schema.org/ListItem"> <a href="/c/support/pm-ask-the-community/62" class="badge-wrapper bullet" itemprop="item"> <span class='badge-category-bg' style='background-color: #0088CC'></span> <span class='badge-category clear-badge'> <span class='category-name' itemprop='name'>Password Manager</span> </span> </a> <meta itemprop="position" content="2" /> </span> </div> </div> <div itemscope itemtype='http://schema.org/DiscussionForumPosting'> <meta itemprop='headline' content='Bitwarden + Google SAML'> <link itemprop='url' href='https://community.bitwarden.com/t/bitwarden-google-saml/28292'> <meta itemprop='datePublished' content='2021-04-01T13:32:03Z'> <meta itemprop='articleSection' content='Password Manager'> <meta itemprop='keywords' content=''> <div itemprop='publisher' itemscope itemtype="http://schema.org/Organization"> <meta itemprop='name' content='Bitwarden, Inc.'> <div itemprop='logo' itemscope itemtype="http://schema.org/ImageObject"> <meta itemprop='url' content='https://community.bitwarden.com/uploads/default/original/3X/a/5/a57ca8519c76bc49e16df5fc9921ea603273ffa6.png'> </div> </div> <div id='post_1' class='topic-body crawler-post'> <div class='crawler-post-meta'> <span class="creator" itemprop="author" itemscope itemtype="http://schema.org/Person"> <a itemprop="url" rel='nofollow' href='https://community.bitwarden.com/u/Not_Honest'><span itemprop='name'>Not_Honest</span></a> (Pavel Lubyanskiy) </span> <link itemprop="mainEntityOfPage" href="https://community.bitwarden.com/t/bitwarden-google-saml/28292"> <span class="crawler-post-infos"> <time datetime='2021-04-01T13:32:03Z' class='post-time'> April 1, 2021, 1:32pm </time> <meta itemprop='dateModified' content='2023-03-22T03:19:46Z'> <span itemprop='position'>1</span> </span> </div> <div class='post' itemprop='text'> <p>Hello!<br> I am trying to set up SSO login via Google SAML. I followed these instructions:</p><aside class="onebox allowlistedgeneric" data-onebox-src="https://bitwarden.com/help/configure-sso-saml/"> <header class="source"> <img src="https://bitwarden.com/favicon-32x32.png?v=1abf57d1154002a9fac426a2c5c04d85" class="site-icon" width="32" height="32"> <a href="https://bitwarden.com/help/configure-sso-saml/" target="_blank" rel="noopener nofollow ugc">Bitwarden</a> </header> <article class="onebox-body"> <div class="aspect-image" style="--aspect-ratio:690/362;"><img src="https://bitwarden.com/_gatsby/file/6dfccd2753e195e6b181af4c5ed96055/help-configure-sso-saml-og.png?eu=d78e55b5b1cbf486066bf58b6f71353bb33c05abad5730816931b6ad1caf978477f21004289073e02f6e5ddfd6e810bc63c32e341cbcd4dc95bc1ea5b837fc5a5a865fbd31e77603522ec6f7b7fd06446cc51b50f083995af06d2380b1e0b3741a034d2cae29ee83eba93d65e5802632bcb0ac762186eb3bea0d410d964926a927a5c39a654fad8de55bacf8b0fc4dd29ba573540681f2632a2a0b1847e870c2a1c7672b302912265288ec5dce69c5e07e64683c5c5652f0616b8352f3653492b6faf259de7e7fe7afcc63778491ad85bf18ad2c69bf9a7be99f6825505bf544e8fe2eea91275913c27ba7c951ed541b751ed5" class="thumbnail" width="690" height="362"></div> <h3><a href="https://bitwarden.com/help/configure-sso-saml/" target="_blank" rel="noopener nofollow ugc">SAML 2.0 Configuration | Bitwarden Help Center</a></h3> <p>With a Bitwarden enterprise plan, you can enable Login with SSO for SAML 2.0 authentication.</p> </article> <div class="onebox-metadata"> </div> <div style="clear: both"></div> </aside> <aside class="onebox allowlistedgeneric" data-onebox-src="https://bitwarden.com/help/saml-google/"> <header class="source"> <img src="https://bitwarden.com/favicon-32x32.png?v=1abf57d1154002a9fac426a2c5c04d85" class="site-icon" width="32" height="32"> <a href="https://bitwarden.com/help/saml-google/" target="_blank" rel="noopener nofollow ugc">Bitwarden</a> </header> <article class="onebox-body"> <div class="aspect-image" style="--aspect-ratio:690/362;"><img src="https://bitwarden.com/_gatsby/file/9bae6e4dd6639b37168984abbed83636/help-saml-google-og.png?eu=8bd858e0e09ba88e066ba8846924673be63657faaa5836843462b6ab1da9998027a54a00239029b32d680bde82e117b26f972e631be9d2ddc9bb1afde33dad5b54865ee931e7720f537a92adb9a302476dc71a5ff7d59e5aa76f7ad1ece7b0761f561c29ab7fee83b8af3030e1d52b3ab9e2ac762186eb3bea0d410d964926a927a5c39a654fad8de55bacf8b0fc4dd29ba573540681f2632a2a0b1847e855ecc5ba56755d4e1f3a679adb5eb137d1c5607a7e76585705f2633a8207f23e3992b0fbf75d8b7878e4aec9392282c5fd88ed4ef9352eb29367b4c16a275210fb4cf2eb27a2cf3b5110c174ad" class="thumbnail" width="690" height="362"></div> <h3><a href="https://bitwarden.com/help/saml-google/" target="_blank" rel="noopener nofollow ugc">Google SAML Implementation | Bitwarden Help Center</a></h3> <p>This article contains instructions for configuring Bitwarden Login with SSO for Google Workspace SAML 2.0 implementations.</p> </article> <div class="onebox-metadata"> </div> <div style="clear: both"></div> </aside> <p>Now when I’m trying to log in using SSO, I am still prompted for a master password.<br> When I’m trying to test SAML login in Google app’s settings, I receive the error:<br> <code>There was an unexpected error during single sign-on. Please close this page and try again. Unsolicited responses are not allowed for idp "https://accounts.google.com/o/saml2?idpid=***".</code></p> <p>If I activate the option “Allow Unsolicited Authentication Response” in Bitwarden’s Single Sign-On settings, the error looks like this:<br> <code>There was an unexpected error during single sign-on. Please close this page and try again. Unsolicited SAML response received, but no ReturnUrl is configured. When receiving unsolicited SAML responses (i.e. IDP initiated login), Saml2 will redirect the client to the configured ReturnUrl after successful authentication, but it is not configured. In code-based config, add a ReturnUrl by setting the options.SpOptions.ReturnUrl property. In the config file, set the returnUrl attribute of the <sustainsys.saml2> element.</code></p> <p>What am I doing wrong? Where can I customize ReturnUrl, if it’s necessary?</p> </div> <div itemprop="interactionStatistic" itemscope itemtype="http://schema.org/InteractionCounter"> <meta itemprop="interactionType" content="http://schema.org/LikeAction"/> <meta itemprop="userInteractionCount" content="0" /> <span class='post-likes'></span> </div> </div> <div id='post_2' itemprop='comment' itemscope itemtype='http://schema.org/Comment' class='topic-body crawler-post'> <div class='crawler-post-meta'> <span class="creator" itemprop="author" itemscope itemtype="http://schema.org/Person"> <a itemprop="url" rel='nofollow' href='https://community.bitwarden.com/u/tgreer'><span itemprop='name'>tgreer</span></a> (Trey Greer) </span> <span class="crawler-post-infos"> <time itemprop='datePublished' datetime='2021-04-01T17:38:28Z' class='post-time'> April 1, 2021, 5:38pm </time> <meta itemprop='dateModified' content='2021-04-01T17:38:28Z'> <span itemprop='position'>2</span> </span> </div> <div class='post' itemprop='text'> <p>Welcome, <a class="mention" href="/u/not_honest">@Not_Honest</a>!</p> <p>Just a quick note - even with SSO configured, users retain a Master Password such that they are in control of their Vault keys.</p> <p>I’m not sure offhand what the issue may be, but as an enterprise subscriber, you are entitled to priority support from our team: <a href="https://bitwarden.com/contact">https://bitwarden.com/contact</a></p> </div> <div itemprop="interactionStatistic" itemscope itemtype="http://schema.org/InteractionCounter"> <meta itemprop="interactionType" content="http://schema.org/LikeAction"/> <meta itemprop="userInteractionCount" content="0" /> <span class='post-likes'></span> </div> </div> <div id='post_3' itemprop='comment' itemscope itemtype='http://schema.org/Comment' class='topic-body crawler-post'> <div class='crawler-post-meta'> <span class="creator" itemprop="author" itemscope itemtype="http://schema.org/Person"> <a itemprop="url" rel='nofollow' href='https://community.bitwarden.com/u/hdub-tech'><span itemprop='name'>hdub-tech</span></a> (H Dub) </span> <span class="crawler-post-infos"> <time itemprop='datePublished' datetime='2024-11-25T15:33:31Z' class='post-time'> November 25, 2024, 3:33pm </time> <meta itemprop='dateModified' content='2024-11-25T15:33:31Z'> <span itemprop='position'>3</span> </span> </div> <div class='post' itemprop='text'> <p><em>(I know this is an old issue but I figured I would update it just for completeness, as I too stumbled across it looking for an answer, having missed the obvious the first time <img src="https://community.bitwarden.com/images/emoji/twitter/sweat_smile.png?v=12" title=":sweat_smile:" class="emoji" alt=":sweat_smile:" loading="lazy" width="20" height="20"> )</em></p> <p>The <code>Allow Unsolicited Authentication Response</code> option has since been removed and the second link in the original post has been updated to include:</p> <blockquote> <p>Note: Bitwarden does not support unsolicited responses, so initiating login from your IdP will result in an error. The SSO login flow must be initiated from Bitwarden.</p> </blockquote> </div> <div itemprop="interactionStatistic" itemscope itemtype="http://schema.org/InteractionCounter"> <meta itemprop="interactionType" content="http://schema.org/LikeAction"/> <meta itemprop="userInteractionCount" content="1" /> <span class='post-likes'>1 Like</span> </div> </div> </div> </div> <footer class="container wrap"> <nav class='crawler-nav'> <ul> <li itemscope itemtype='http://schema.org/SiteNavigationElement'> <span itemprop='name'> <a href='/' itemprop="url">Home </a> </span> </li> <li itemscope itemtype='http://schema.org/SiteNavigationElement'> <span itemprop='name'> <a href='/categories' itemprop="url">Categories </a> </span> </li> <li itemscope itemtype='http://schema.org/SiteNavigationElement'> <span itemprop='name'> <a href='/guidelines' itemprop="url">Guidelines </a> </span> </li> <li itemscope itemtype='http://schema.org/SiteNavigationElement'> <span itemprop='name'> <a href='https://bitwarden.com/terms/' itemprop="url">Terms of Service </a> </span> </li> <li itemscope itemtype='http://schema.org/SiteNavigationElement'> <span itemprop='name'> <a href='https://bitwarden.com/privacy/' itemprop="url">Privacy Policy </a> </span> </li> </ul> </nav> <p class='powered-by-link'>Powered by <a href="https://www.discourse.org">Discourse</a>, best viewed with JavaScript enabled</p> </footer> <div class="buorg"><div>Unfortunately, <a href="https://www.discourse.org/faq/#browser">your browser is unsupported</a>. Please <a href="https://browsehappy.com">switch to a supported browser</a> to view rich content, log in and reply.</div></div> </body> </html>