Manage Cross app access for Enterprise
Cross app access lets your organisation connect supported AI assistants to the Canva AI Connector using your existing SSO connection. Once enabled, people in your organisation can access the Canva AI Connector through supported AI assistants after signing in with SSO.
If you're looking to connect your own personal account instead, see Connect AI assistants to Canva with the AI Connector.
Before you begin
Make sure that:
- Your organisation is on the Canva Enterprise plan.
- You have administrator access to Canva, Identity Provider (IdP), and your AI assistant.
- You've set up Single Sign-On (SSO) for your Canva organisation. See Setting up Single Sign-On (SSO) for Enterprise.
- Your members already have Canva accounts in your Enterprise organisation.
At beta launch, Cross App Access currently supports Claude for Enterprise or Team for the AI assistant and Okta as the IdP.
If your organisation uses another identity provider, contact Canva support for further assistance.
Manage Cross app access
Step 1: Enable Cross App Access in Canva
- From the Canva homepage, open Settings.
- Under Security, select Cross app access.
- Turn on Enable Cross app access.
Step 2: Add your ID-JAG issuer URL (if needed)
Your ID-JAG issuer URL is the identifier your identity provider uses to authorise AI agents like Claude. Add your ID-JAG issuer URL only if it differs from your existing SAML issuer URL.
Tip: Compare your ID-JAG issuer URL with the Identity Provider Issuer value from Setting up Single Sign-On (SSO) for Enterprise. If they match, you don't need to add the URL issuer.
To add your ID-JAG issuer URL:
- Select Add ID-JAG Issuer.
- Enter your ID-JAG Issuer URL.
- Select Add Issuer.
The issuer appears in the ID-JAG Issuer list once saved.
Step 3: Configure your identity provider and AI assistant
To finish setting up, complete the configuration in your identity provider and AI assistant.
- Identity provider (Okta): Follow the Okta guide.
- AI assistant (Claude for Business): Follow Authorise MCP connectors for your entire organisation
Step 4: Verify the connection
To confirm Cross app access is active, check that:
- Open the Cross app access page and confirm that the Enable Cross app access toggle is turned on.
- Your ID-JAG issuer URL (if added) appears in the ID-JAG Issuer list.
- The Canva connector is visible and active in your AI assistant
After you enable Cross App Access:
- Users can access the Canva AI connector after signing in to Canva with SSO.
- Users can generate, edit, and search designs directly from their AI assistant.
- Users can access the Brand Kits, templates, and other content available to their assigned Enterprise team.
Note: If a user belongs to multiple Enterprise teams, Cross-app access connects them to their default Enterprise team. Support for connecting to other Enterprise teams isn't available yet.
Remove an Issuer URL
Removing an ID-JAG issuer URL prevents supported AI assistants that use that identity provider from accessing Canva.
To remove an issuer:
- From the Canva homepage, open Settings.
- Under Security, select Cross app access.
- Find the issuer you want to remove in the ID-JAG Issuer list.
- Select More next to the issuer, then select Delete.
- In the confirmation dialog, select Remove Issuer.
Disable Cross App Access
- From the Canva homepage, open Settings.
- Under Security, select Cross app access.
- Toggle off Enable Cross app access.
Troubleshooting
The Canva connector isn't available in Claude
What can cause this
The user hasn't been assigned access in Claude or hasn't signed in to Canva using SSO yet.
What to do
- Check that the user is included in the appropriate groups or roles in Claude.
- Ask the user to sign in to Canva using SSO at least once before accessing the connector.
- If you recently updated their access, ask the user to sign in to Claude again.
A user wants to remove access, but it keeps reconnecting
What can cause this
The Canva connector is managed by your organisation through Cross app access.
What to do
- To remove a user's access, update their groups or roles in Claude.
- If the user wants to disconnect a personal Canva connector instead, see Connect AI assistants to Canva with the AI Connector
I'm seeing an error during the setup
What can cause this
There may be an issue with your AI assistant's configuration, setup or connection.
What to do
If you experience issues setting up your AI assistant, contact your AI assistant provider for assistance.
At launch, Cross-app access supports Claude for Enterprise. Contact Claude support for assistance.
FAQs
Do I always need to add an ID-JAG issuer URL?
Only if your ID-JAG issuer URL differs from your existing SAML issuer URL. If they're the same, enabling the toggle is all you need to do.
Do users need to set up the Canva AI connector themselves?
No. After you enable Cross App Access, users can access the Canva AI Connector once they've signed in with SSO. If they want to set up their personal accounts, they can follow Connect AI assistants to Canva with the AI Connector.
Can users switch between Canva teams while using the connector?
No. Cross App Access uses the user's default Enterprise team. Users can access the Brand Kits, templates, and other content available to that team.
If a user belongs to multiple Enterprise teams, support for switching to another team isn't available yet.
How do Canva and Anthropic handle data?
Canva and Anthropic handle data according to their respective privacy policies and terms. For more information, see the Canva AI Terms, Privacy Policy and Anthropic's policies.
Was this helpful?
Helpful
Unhelpful