This document shows you how to configure Workforce Identity Federation with PingOne Advanced Identity Cloud (AIC) as an identity provider (IdP) and manage access to Google Cloud. After you configure the PingOne AIC IdP, federated users can access Google Cloud services that support Workforce Identity Federation by using the SAML 2.0 protocol.
Install the Google Cloud CLI. After installation, initialize the Google Cloud CLI by running the following command:
gcloud initIf you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
Enter an Entity ID. Record this value for later use.
This section describes how to use attributes from the SAML assertion.
In the following examples, attributes in the SAML assertion are mapped to local attributes:
| SAML attribute | Local attribute |
|---|---|
IDPEmail |
mail |
FirstName |
givenName |
groups |
groups |
Set up the required attributes in the attribute mapping section. You will map these attributes when you create the workforce identity pool provider later in this guide.
You can access the SAML 2.0 metadata for your hosted provider in one of the following ways:
Over REST
Run the following command:
curl --output METADATA_XML \
"https://TENANT_ENV_FQDN/am/ExportSamlMetadata?entityid=ENTITY_ID&realm=/REALM"
In a browser
Open your tenant environment's metadata URL in a browser to download the XML file:
https://TENANT_ENV_FQDN/am/ExportSamlMetadata?entityid=ENTITY_ID&realm=/REALM
Prepare the Google Cloud SP metadata XML. Use the following template, replacing the placeholder values:
<?xml version="1.0" encoding="UTF-8"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://iam.googleapis.com/locations/global/workforcePools/WORKFORCE_POOL_ID/providers/WORKFORCE_PROVIDER_ID">
<md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat>
<md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://auth.cloud.google/signin-callback/locations/global/workforcePools/WORKFORCE_POOL_ID/providers/WORKFORCE_PROVIDER_ID" index="0" isDefault="true"/>
</md:SPSSODescriptor>
</md:EntityDescriptor>
Import the metadata in one of the following ways:
In the console
Over REST
Run the following command:
curl --request POST \
--header 'authorization: Bearer ACCESS_TOKEN' \
--header 'Content-Type: application/json' \
--header 'Accept-API-Version: resource=1.0' \
--data-raw '{"standardMetadata": "BASE64URL_ENCODED_METADATA"}' \
'https://TENANT_ENV_FQDN/am/json/realms/root/realms/alpha/realm-config/saml2/remote?_action=importEntity'
This section describes how to create a workforce identity pool provider to enable your IdP users to access Google Cloud. You can configure the provider to use the SAML protocol.
To create a SAML workforce identity pool provider, you want to ensure that your identity provider metadata includes at least the SAML entity ID, the single sign-on URL, and one signing public key. To do this, follow these steps:
Save the SAML metadata from your PingOne AIC app.
To create the SAML workforce identity pool provider, run the following command:
gcloud iam workforce-pools providers create-saml WORKFORCE_PROVIDER_ID \
--workforce-pool="WORKFORCE_POOL_ID" \
--display-name="DISPLAY_NAME" \
--description="DESCRIPTION" \
--idp-metadata-path="XML_METADATA_PATH" \
--attribute-mapping="ATTRIBUTE_MAPPING" \
--attribute-condition="ATTRIBUTE_CONDITION" \
--location=global
Replace the following:
WORKFORCE_PROVIDER_ID: a provider ID.WORKFORCE_POOL_ID: the workforce identity pool ID.DISPLAY_NAME: a display name.DESCRIPTION: a description.XML_METADATA_PATH: the path to the XML-formatted metadata file you exported from PingOne AIC.ATTRIBUTE_MAPPING: the attribute mapping; for example, google.subject=assertion.subject,google.groups=assertion.attributes.groups,attribute.department=assertion.attributes.department[0].ATTRIBUTE_CONDITION: an optional attribute condition; for example, to limit the ipaddr attribute to a certain IP range you can set the condition assertion.ipaddr.startsWith('98.11.12.').For more information, see Attribute mapping.
This command assigns the subject, groups, and department in the SAML assertion to google.subject, google.groups, and attribute.department attributes, respectively. The attribute condition also ensures that only users within a certain IP range can sign in using this workforce provider.
To configure the SAML provider by using the Google Cloud console, do the following:
In the Configure provider section, do the following:
google.subject (for example, assertion.subject).Optional: To enter other mappings, click Add mapping and enter other mappings—for example:
google.subject=assertion.subject,
google.groups=assertion.attributes['https://example.com/aliases'],
attribute.costcenter=assertion.attributes.costcenter[0]
Optional: To add an attribute condition, click Add condition and enter a CEL expression representing an attribute condition. For example, to limit the ipaddr attribute to a certain IP range you can set the condition assertion.attributes.ipaddr.startsWith('98.11.12.'). This example condition ensures that only users with an IP address that starts with 98.11.12. can sign in using this workforce provider.
To turn on detailed audit logging, in Detailed logging, click the Enable attribute value audit logging toggle.
To create the provider, click Submit.
This section shows how to manage access to Google Cloud resources for PingOne AIC users.
The sample project used in this guide can be different from the project that you used to set up Workforce Identity Federation.
You can manage roles for single identities, a group of identities, or an entire pool. For more information, see Workforce principal identifiers for allow policies.
To grant the Storage Admin role (roles/storage.admin) to all identities within a specific department for the TEST_PROJECT_ID project, run the following command:
gcloud projects add-iam-policy-binding TEST_PROJECT_ID \
--role="roles/storage.admin" \
--member="principalSet://iam.googleapis.com/locations/global/workforcePools/WORKFORCE_POOL_ID/attribute.department/DEPARTMENT_VALUE"
Replace the following:
TEST_PROJECT_ID: the project ID.WORKFORCE_POOL_ID: the workforce identity pool ID.DEPARTMENT_VALUE: the mapped attribute.department value.To grant the Storage Admin role (roles/storage.admin) to all identities within the GROUP_ID group for the TEST_PROJECT_ID project, run the following command:
gcloud projects add-iam-policy-binding TEST_PROJECT_ID \
--role="roles/storage.admin" \
--member="principalSet://iam.googleapis.com/locations/global/workforcePools/WORKFORCE_POOL_ID/group/GROUP_ID"
Replace the following:
TEST_PROJECT_ID: the project ID.WORKFORCE_POOL_ID: the workforce identity pool ID.GROUP_ID: a group in the mapped google.groups claim.In this section, you sign in as a workforce identity pool user and test your access.
To sign in to the Google Cloud Workforce Identity Federation console, also known as the console (federated), do the following:
Go to the console (federated) sign-in page.
locations/global/workforcePools/WORKFORCE_POOL_ID/providers/WORKFORCE_PROVIDER_IDTo sign in to gcloud CLI using a browser-based sign-in flow:
Run the following command to create a login configuration file:
gcloud iam workforce-pools create-login-config \ locations/global/workforcePools/WORKFORCE_POOL_ID/providers/WORKFORCE_PROVIDER_ID \ --output-file=LOGIN_CONFIG_PATH
gcloud iam workforce-pools create-login-config ` locations/global/workforcePools/WORKFORCE_POOL_ID/providers/WORKFORCE_PROVIDER_ID ` --output-file=LOGIN_CONFIG_PATH
Replace the following:
WORKFORCE_POOL_ID: The Workforce Identity Federation pool ID.WORKFORCE_PROVIDER_ID: The Workforce Identity Federation provider ID.LOGIN_CONFIG_PATH: The path to write the login configuration file
to. For example, login-config.json.
The login configuration file contains the endpoints used by the gcloud CLI to enable the browser-based authentication flow and set the audience to the IdP that was configured in the workforce identity pool provider. The file doesn't contain confidential information.
The login configuration file content looks similar to the following:
{ "universe_domain": "googleapis.com", "universe_cloud_web_domain": "cloud.google", "type": "external_account_authorized_user_login_config", "audience": "//iam.googleapis.com/locations/global/workforcePools/WORKFORCE_POOL_ID/providers/WORKFORCE_PROVIDER_ID", "auth_url": "https://auth.cloud.google/authorize", "token_url": "https://sts.googleapis.com/v1/oauthtoken", "token_info_url": "https://sts.googleapis.com/v1/introspect" }
Point to the login configuration file with an environment variable, a property in the active
gcloud CLI configuration, or use it directly with the gcloud auth login
command:
To use the login configuration file with an environment variable, complete the following instructions:
CLOUDSDK_AUTH_LOGIN_CONFIG_FILE environment variable to the path of
the login configuration file.
Run the following command:
gcloud auth login
To stop using the login configuration file for gcloud auth login commands, clear
the CLOUDSDK_AUTH_LOGIN_CONFIG_FILE environment variable.
To use the login configuration file with a gcloud CLI configuration property, complete the following instructions:
Set the active gcloud CLI configuration's auth/login_config_file property to
the login configuration file's path with the following command:
gcloud config set auth/login_config_file LOGIN_CONFIG_PATH
Run the following command:
gcloud auth login
To stop using the login configuration file for gcloud auth login commands, unset
the property with the following command:
gcloud config unset auth/login_config_file
To use the login configuration file directly with the gcloud auth login
command, complete the following instructions:
If you used the --activate flag when you created the login configuration
file, run the following command:
gcloud auth login
If you didn't use the --activate flag when you created the login
configuration file, run the following command:
gcloud auth login \ --login-config=LOGIN_CONFIG_PATH
gcloud auth login ` --login-config=LOGIN_CONFIG_PATH
Replace LOGIN_CONFIG_PATH with the path of your login configuration file.
The gcloud auth login command stores access credentials in your home directory. The authenticated principal becomes the active principal in your active gcloud CLI configuration. Unless overridden, the gcloud CLI uses these stored credentials to access Google Cloud.
To sign in to PingOne AIC with the gcloud CLI using the SAML protocol, do the following:
SAML_ASSERTION_PATH=/tmp/saml_assertion.xml.Generate a configuration file:
gcloud iam workforce-pools create-cred-config \
locations/global/workforcePools/WORKFORCE_POOL_ID/providers/WORKFORCE_PROVIDER_ID \
--subject-token-type=urn:ietf:params:oauth:token-type:saml2 \
--credential-source-file=SAML_ASSERTION_PATH \
--workforce-pool-user-project=PROJECT_ID \
--output-file=config.json
Replace the following:
SAML_ASSERTION_PATH: the path of the SAML assertion file.PROJECT_ID: the project ID.The configuration file that's generated looks similar to the following:
{
"type": "external_account",
"audience": "//iam.googleapis.com/locations/global/workforcePools/WORKFORCE_POOL_ID/providers/WORKFORCE_PROVIDER_ID",
"subject_token_type": "urn:ietf:params:oauth:token-type:saml2",
"token_url": "https://sts.googleapis.com/v1/token",
"credential_source": {
"file": "SAML_ASSERTION_PATH"
},
"workforce_pool_user_project": "PROJECT_ID"
}
To sign in to the gcloud CLI using token exchange, run the following command:
gcloud auth login --cred-file=config.json
gcloud then transparently exchanges your PingOne AIC credentials for temporary Google Cloud access tokens, allowing you to make other gcloud calls to Google Cloud. The output is similar to the following:
Authenticated with external account user credentials for: [principal://iam.googleapis.com/locations/global/workforcePools/WORKFORCE_POOL_ID/subject/USER_ID].
To list the credentialed accounts and the active account, run the following command:
gcloud auth list
You can access the Google Cloud services that support Workforce Identity Federation that you're granted access to. Earlier in this guide, you granted the Storage Admin role to all identities within a specific department or group for project TEST_PROJECT_ID. You can test that you have access by listing Cloud Storage buckets.
To verify your access in the console (federated), do the following:
TEST_PROJECT_ID.To list Cloud Storage buckets and objects for the project that you have access to, run the following command:
gcloud alpha storage ls --project="TEST_PROJECT_ID"
The principal must have the serviceusage.services.use permission on the project set in the gcloud CLI session: PROJECT_ID.
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-07-21 UTC.