Canva home
Help

SCIM user provisioning and de-provisioning


If you’re a team admin or owner, easily provision and manage people in your team or district using the SCIM (System for Cross-domain Identity Management) standard.

Who can use this feature?

SCIM is only available to Canva Enterprise and Canva for Districts, and it isn’t available for new Canva Teams subscribers.

Limitations: For teams within an organization's structure (both single-team or multi-team), user provisioning and deprovisioning are supported. However, all other functionalities, such as provisioning users directly into specific teams or creating groups, aren’t currently supported.

When SCIM is configured with your Identity Provider, people in your team will automatically get a Canva account provisioned. It will also keep your team members in sync by adding new accounts to your Canva Enterprise team and removing people that have left your organisation.

SCIM provisioning

Step 1: Generate an API token in Canva

  1. Log in to your Canva account.
  2. On the homepage, select your account profile to open menu.
  3. Choose
    Settings.
  4. From the side menu, select the
    SSO and provisioning tab.
  5. Under Single Single Sign-On (SSO) section, click Manage.
  6. Choose Configure Provisioning.
  7. Under Provision Accounts for your team, select Add provisioning method.
  8. Choose SCIM, then turn on Enable SCIM user provisioning.
  9. Copy the access token. You’ll need this when configuring your identity provider.

Note: A new access token is generated every time the slider is toggled.

Step 2: Set up SCIM with your identity provider

Configure your identity provider using the guide below.

For other identity providers, please refer to their respective documentation on how to complete this step.

What’s next?

Once SCIM is set up, your configured identity provider will start provisioning your team members to your Canva Enterprise team.

What if someone from my organisation already has a Canva account?

If we find existing Canva accounts with the email addresses of people to provision, we will send them an email to join your team instead.

If they’re logging in using Single Sign-On (SSO) for the first time, they may be asked to connect their Canva account with your SSO provider. Learn more about SSO Linking.


SCIM de-provisioning

When a person gets removed from your organisation, your identity provider sends this information to Canva. Once this happens, they’re instantly removed from your Canva Enterprise team, and their account will be locked.

Before removing someone from your team, you can ask them to transfer ownership of their designs to someone else in the team. Learn more on Transferring design ownership.

Once a team member is removed, all their designs that were not transferred will remain in your team but will be ownerless. When the team member is added back to the team, we will assign them the designs they used to own that are currently ownerless.

For advanced users, please see our developer documentation on the SCIM endpoint for more information.

Was this helpful?

Helpful

Unhelpful

People also viewed