How to Set Up WestFax Single Sign-On with Google Workspace
Add WestFax as a custom SAML app in Google Admin so your team signs in to the fax console with the Google credentials they already use.
WestFax supports SAML 2.0 single sign-on with Google Workspace, so your team reaches the WestFax fax console with the Google credentials they already sign in with every morning — no separate WestFax password to issue or reset. Setup is a three-step round trip: turn SSO on with your WestFax account manager and copy three endpoints off the SSO tab, add WestFax as a custom SAML app in the Google Admin console and copy three values back, then paste those into the WestFax admin panel and save. From then on, access is controlled entirely from Google Admin.
What you’ll need
- A Google Workspace account with at least one user, and super-admin access to admin.google.com
- A WestFax Enterprise account with SSO enabled — see step 1 if it isn’t on yet
What you get once it’s running: control from Google Admin over who can reach WestFax fax numbers, automatic sign-in for your users, and one central place to manage the accounts.
Step 1: Turn on SSO and copy your WestFax endpoints
SSO is not on by default. Before any of the identity-provider work below will do anything, your WestFax account has to be provisioned for it — contact your account manager and ask them to activate SSO. There may be a setup fee, and they will walk you through provisioning.
Once SSO is active on the account, sign in to the WestFax admin tool and open the SSO tab. You should see a screen like this:

The SSO tab shows three values generated for your account. Copy all three somewhere safe — every one of them gets pasted into your identity provider in the next step. YourProviderId is unique to your WestFax account; the tab shows the real value.
- Consume Endpoint —
https://home.westfax.com/login/Consume/YourProviderId. This is the SAML assertion consumer service (ACS) URL, where your identity provider posts the signed assertion. - Redirect Endpoint —
https://home.westfax.com/login/sso/YourProviderId. This is the link your users click to sign in, and the start URL for service-provider-initiated login. - Metadata Endpoint —
https://home.westfax.com/login/metadata/YourProviderId. This is the SAML entity ID that identifies WestFax as the service provider.
Copy these straight off the SSO tab rather than typing them by hand. A single wrong character in the Consume Endpoint is the most common reason a first SSO attempt fails.
Step 2: Add WestFax as a custom SAML app in Google Admin
Sign in to admin.google.com with your administrator account and create the SAML app that represents WestFax.
- Go to Apps → Web and mobile apps.
- Click Add app → Add custom SAML app.

- Name the app.
WestFax SSOworks; the name has no effect on the integration. Click Continue.
- Copy Google’s identity provider details. On the next screen, copy the
SSO URLandEntity ID, and download theCertificateas a.pemfile to a secure location. You also need the Client ID: it is the value that appears afteridpid=in the Entity ID. Save all of it — step 3 needs it.
- Enter the WestFax values in Service provider details. This is where the endpoints from step 1 go.

- ACS URL:
https://home.westfax.com/login/Consume/YourProviderId - Entity ID:
https://home.westfax.com/login/metadata/YourProviderId - Start URL:
https://home.westfax.com/login/sso/YourProviderId - Name ID format:
EMAIL - Name ID:
Basic Information > Primary email

- ACS URL:
- Click Continue, then Finish. Skip the attribute mapping page — WestFax matches on the Name ID, so no extra attributes are needed.
Before you test: turn the app on for your users. A new custom SAML app is off for everyone by default, and users who aren’t granted access get a 403 instead of a login screen. Open the app in Google Admin, click User access, and turn it on for the organizational units or groups that should reach WestFax.
Step 3: Finish the setup in the WestFax admin panel
Go back to the WestFax admin panel and open the SSO section again. This is where the three values from Google get entered.

A — Login Endpoint— theSSO URLfrom Google.B — Client Id (App Id)— the value afteridpid=in Google’s Entity ID.C — Certificate x.509— the.pemcertificate you downloaded from Google. Click upload and select the file.
Click Save Settings. That completes the configuration.
Sign in with SSO
Your team signs in through the Redirect Endpoint from step 1 — https://home.westfax.com/login/sso/YourProviderId — rather than the standard WestFax login page. Copy the exact link off the SSO tab and distribute it, bookmark it, or let users launch WestFax from their Google apps list.
Troubleshooting
- Users see a 403 error. They haven’t been granted access to the app in Google Admin. Open the WestFax SAML app, click User access, and turn it on for their organizational unit or group.
- Sign-in fails right after the Google prompt. Check the ACS URL and Entity ID against the SSO tab character for character, including
YourProviderId. - Users authenticate but WestFax rejects them. Confirm the Name ID format is
EMAILand the Name ID is mapped toBasic Information > Primary email. WestFax matches users on email address. - Sign-in worked and then stopped. Google signing certificates expire. Download the current certificate and re-upload it in the WestFax SSO panel.
Still stuck? Call us at 303-299-9329, contact our team, or reach out to your account manager.
