- SAML Metadata XML
- Email domains governed by organization SSO (e.g. @camo.ag)
<custom-code>” would be replaced by your white-label sub-domain (e.g. acme.camo.ag would use acme).
CamoAg
- Entity ID: https://app.camo.ag/sp
- ACS URL:
https://app.camo.ag/api/auth/saml/acs/<custom-code>
- Entity ID: https://app.camo.ag/sp
- ACS URL: https://app.camo.ag/api/auth/saml/acs/acme
- First Name - Required (“first_name”, “first name”, “givenName”)
- Last Name - Required (“last_name”, “last name”, “surname”)
- Department - Optional (“department”)
- If provided, used for SSO read-only user groups for engagement analytics segmentation, and permission granularity for features and reporting
- Supervisor - Optional (“supervisor”)
- Title - Optional (“title”, “jobTitle”)
Troubleshooting
Google returns a 403 SAML error
If your organization uses Google as its identity provider, users may see a Google-branded error page instead of CamoAg’s after clicking Sign in with SSO:1
Sign in to the browser with the work Google account
Go to accounts.google.com, sign out of every account, then sign back in with the work email on your organization’s domain. If the browser has a profile picker, switch to the profile tied to the work account.
2
Return to CamoAg and sign in again
Open your organization’s CamoAg URL and click Sign in with SSO. Google should now hand you off to CamoAg without an error.
app_not_configured_for_user still appears, the Google Workspace admin hasn’t granted that account access to the CamoAg SAML app. Contact your IT or Workspace administrator and ask them to enable CamoAg for the user.
