Fax Integration

How to Set Up WestFax Single Sign-On with Google Workspace

Add WestFax as a custom SAML app in Google Admin so your team signs in to the fax console with the Google credentials they already use.

WestFax supports SAML 2.0 single sign-on with Google Workspace, so your team reaches the WestFax fax console with the Google credentials they already sign in with every morning — no separate WestFax password to issue or reset. Setup is a three-step round trip: turn SSO on with your WestFax account manager and copy three endpoints off the SSO tab, add WestFax as a custom SAML app in the Google Admin console and copy three values back, then paste those into the WestFax admin panel and save. From then on, access is controlled entirely from Google Admin.

What you’ll need

  • A Google Workspace account with at least one user, and super-admin access to admin.google.com
  • A WestFax Enterprise account with SSO enabled — see step 1 if it isn’t on yet

What you get once it’s running: control from Google Admin over who can reach WestFax fax numbers, automatic sign-in for your users, and one central place to manage the accounts.

Step 1: Turn on SSO and copy your WestFax endpoints

SSO is not on by default. Before any of the identity-provider work below will do anything, your WestFax account has to be provisioned for it — contact your account manager and ask them to activate SSO. There may be a setup fee, and they will walk you through provisioning.

Once SSO is active on the account, sign in to the WestFax admin tool and open the SSO tab. You should see a screen like this:

The SSO tab in the WestFax admin panel showing the Consume, Redirect, and Metadata endpoints

The SSO tab shows three values generated for your account. Copy all three somewhere safe — every one of them gets pasted into your identity provider in the next step. YourProviderId is unique to your WestFax account; the tab shows the real value.

  • Consume Endpointhttps://home.westfax.com/login/Consume/YourProviderId. This is the SAML assertion consumer service (ACS) URL, where your identity provider posts the signed assertion.
  • Redirect Endpointhttps://home.westfax.com/login/sso/YourProviderId. This is the link your users click to sign in, and the start URL for service-provider-initiated login.
  • Metadata Endpointhttps://home.westfax.com/login/metadata/YourProviderId. This is the SAML entity ID that identifies WestFax as the service provider.

Copy these straight off the SSO tab rather than typing them by hand. A single wrong character in the Consume Endpoint is the most common reason a first SSO attempt fails.

Step 2: Add WestFax as a custom SAML app in Google Admin

Sign in to admin.google.com with your administrator account and create the SAML app that represents WestFax.

  1. Go to Apps → Web and mobile apps.
  2. Click Add app → Add custom SAML app.

    The Add app menu in Google Admin with Add custom SAML app highlighted

  3. Name the app. WestFax SSO works; the name has no effect on the integration. Click Continue.

    Naming the custom SAML app WestFax SSO in the Google Admin console

  4. Copy Google’s identity provider details. On the next screen, copy the SSO URL and Entity ID, and download the Certificate as a .pem file to a secure location. You also need the Client ID: it is the value that appears after idpid= in the Entity ID. Save all of it — step 3 needs it.

    Google identity provider details showing the SSO URL, Entity ID, and downloadable certificate

  5. Enter the WestFax values in Service provider details. This is where the endpoints from step 1 go.

    The Google service provider details form for the WestFax SAML app

    1. ACS URL: https://home.westfax.com/login/Consume/YourProviderId
    2. Entity ID: https://home.westfax.com/login/metadata/YourProviderId
    3. Start URL: https://home.westfax.com/login/sso/YourProviderId
    4. Name ID format: EMAIL
    5. Name ID: Basic Information > Primary email

    Name ID format set to EMAIL and Name ID set to Basic Information Primary email

  6. Click Continue, then Finish. Skip the attribute mapping page — WestFax matches on the Name ID, so no extra attributes are needed.

Before you test: turn the app on for your users. A new custom SAML app is off for everyone by default, and users who aren’t granted access get a 403 instead of a login screen. Open the app in Google Admin, click User access, and turn it on for the organizational units or groups that should reach WestFax.

Step 3: Finish the setup in the WestFax admin panel

Go back to the WestFax admin panel and open the SSO section again. This is where the three values from Google get entered.

The WestFax SSO settings form with fields for login endpoint, client ID, and x.509 certificate

  • A — Login Endpoint — the SSO URL from Google.
  • B — Client Id (App Id) — the value after idpid= in Google’s Entity ID.
  • C — Certificate x.509 — the .pem certificate you downloaded from Google. Click upload and select the file.

Click Save Settings. That completes the configuration.

Sign in with SSO

Your team signs in through the Redirect Endpoint from step 1 — https://home.westfax.com/login/sso/YourProviderId — rather than the standard WestFax login page. Copy the exact link off the SSO tab and distribute it, bookmark it, or let users launch WestFax from their Google apps list.

Troubleshooting

  • Users see a 403 error. They haven’t been granted access to the app in Google Admin. Open the WestFax SAML app, click User access, and turn it on for their organizational unit or group.
  • Sign-in fails right after the Google prompt. Check the ACS URL and Entity ID against the SSO tab character for character, including YourProviderId.
  • Users authenticate but WestFax rejects them. Confirm the Name ID format is EMAIL and the Name ID is mapped to Basic Information > Primary email. WestFax matches users on email address.
  • Sign-in worked and then stopped. Google signing certificates expire. Download the current certificate and re-upload it in the WestFax SSO panel.

Still stuck? Call us at 303-299-9329, contact our team, or reach out to your account manager.