Skip to main content

Add Google Cloud as an identity provider to an Aiven Runtime application

Let users access an Aiven Runtime application through the Google Cloud identity provider (IdP).

Required roles or permissions:role:project:admin, role:project:manager, or project:services:write

Step 1: Add Google Cloud to a Runtime application​

  1. In the Aiven Console, go to your Aiven Runtime application and click Authentication.

  2. Click Add authentication method.

  3. Select OpenID Connect (OIDC) and click Next.

  4. Copy the Redirect URL.

Step 2: Create the client ID in Google Cloud​

Open the Google Auth Platform in a new tab:

  1. Configure a consent screen.
    • To give access only to users in your Google Workspace domain, set the audience to Internal.
    • Add the openid, profile, and email scopes.
  2. Create an OAuth 2.0 client ID.
    • Select Web application as the Application type.
    • In Authorized redirect URIs, add the Redirect URL from the Aiven Console.
  3. Copy the Client ID and Client secret.

Step 3: Complete the setup in Aiven​

Return to the Aiven Console tab:

  1. Enter a name for the identity provider.

  2. In the Issuer/Provider URL, enter https://accounts.google.com.
  3. Enter the Client ID and Client Secret you copied.
  4. Click Add.