---
title: Setting up ZEN Master GCP SSO
slug: zen-master/setting-up-zen-master-gcp-sso
docTags: 
createdAt: 2024-12-11T17:11:37.926Z
---

This section includes instructions on how to register ZEN Master as an SSO app on GCP and configure the connection between ZEN Master and GCP. To complete this process, you need to log in as an Admin on both the GCP side and the ZEN Master side. It is, therefore, recommended to have both open in parallel.&#x20;

**To setup ZEN Master GCP SSO:**

:::::WorkflowBlock
:::WorkflowBlockItem
On the **GCP&#x20;**&#x68;ome page, click **APIs & Services > Credentials**.

![](https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/Tako_Frfd1TE72Eca79u1_image.png)
:::

:::WorkflowBlockItem
Click **+ Create Credentials**.

![](https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/o_4ULYy0JbDu03qjCDUSY_image.png)
:::

::::WorkflowBlockItem
From the options shown, click **OAuth client ID**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/91evs5hA7KWL-ctd4kkH__image.png" size="60" width="1570" height="876" position="center" showCaption="false"}

:::hint{type="info"}
If this is your first time creating an OAuth client ID, you will need to configure your OAuth consent screen. For more information, see [Setting up OAuth 2.0](https://support.google.com/cloud/answer/6158849?hl=en).
:::
::::

:::WorkflowBlockItem
In the **Application type** field, select **Web application**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/uxzUOa8jWhqcnAO9IPCi2_image.png" size="60" width="1384" height="1072" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
In the **Name&#x20;**&#x66;ield, enter a name for the SSO app. (This name is only used to identify the client in the console, and will not be shown to end users.) For example, "ZEN Master".

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/UOcFB2LKcOkRNM8PxG1yl_image.png" size="60" width="1429" height="1055" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
In the **ZEN Master UI**, go to **Account Management > Single Sign-On**.&#x20;
:::

:::WorkflowBlockItem
Click **+Add**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/uFymwFI0em_vNagK2PGh1_image.png" size="80" width="1920" height="565" position="center" showCaption="false"}

The **Create New Single Sign-On** screen opens.
:::

:::WorkflowBlockItem
Copy the **Callback URL** to your clipboard.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/26MUv6zbhUAm8fgmpwvXz_image.png" size="70" width="1701" height="1494" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
In **GCP**, in the **Authorized redirect URIs** section on the **Create OAuth client ID** screen, click **+ ADD URI**.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/xhyPARgNlX0vX5CFPK34M_image.png" size="70" width="1434" height="1734" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Paste the Callback URL in the field that is displayed.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/OjoiURKuMZTlk2moqxG-j_image.png" size="70" width="1291" height="1753" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Click **Create**.

The OAuth client is created, and a window with your client ID and client secret opens.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/L5eyuMKqProEjB6RWg5hF_image.png" size="70" width="1295" height="1133" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Click the **Your Client ID** copy button.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/XoXb4HE9P-wZvPTmdcjUQ_image.png" size="70" width="1295" height="1133" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
In **ZEN Master**, paste the Client ID in the **Client ID** field.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/oXtCJ_kWMSHP9bBnQRl-g_image.png" size="70" width="1701" height="1494" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Back in **GCP**, copy the **Client Secret**, and paste it in the **Client Secret** field in **ZEN Master**.
:::

:::WorkflowBlockItem
In **ZEN Master**, in the **Name** field, enter a name for this SSO connection, for example GCP SSO. This is the name that will be displayed on the GCP button in the ZEN Master **Sign In** portal.
:::

:::WorkflowBlockItem
In the **Authorization URL** field, enter the Authorization URL, for example: https\://accounts.google.com/o/oauth2/auth.
:::

:::WorkflowBlockItem
In the **Token URL** field, enter the Token URL, for example: https\://oauth2.googleapis.com/token
:::

:::WorkflowBlockItem
If you want to manually register GCP users to ZEN Master (see [Pre-registering Users in ZEN Master for GCP](docId:_SOv8QL6uA-qFpGNnBrmk)) before granting access, select the **Allow pre-registered users only** checkbox. The registration is simple and only involves entering the user's email.
:::

:::WorkflowBlockItem
In **ZEN Master**, click **Save**. GCP SSO is added to the list of SSO profiles. GCP users will be able to connect to ZEN Master by selecting the newly created SSO option under **Sign In With**. During the first connection you may be required to provide permission to connect through GCP to ZEN Master. As an administrator, you can select **Consent on behalf of your organization option**, which will not require additional consent by the other users.

::Image[]{src="https://api.archbee.com/api/optimize/mzxtTQEvCNIdUNgF2kuwJ/GLhHhulV-4xlTIvaaffIB_image.png" size="60" width="370" height="449" position="center" showCaption="false"}

However, if you have selected the **Allow pre-registered users only&#x20;**&#x6F;ption you will need to manually pre-register the users by following the instructions below.
:::
:::::



