Canva home
Help

Troubleshoot Single Sign-On (SSO) errors


If you’re seeing an error while setting up Single Sign-On (SSO), this guide can help you identify and resolve the issue.

Most SSO issues need to be resolved by your Organization Admin or IT team. If you’re an educator or team member, please contact them for help.

Azure AD errors

Error: The signed in user is not assigned to a role for the application

What happened: The user doesn’t have access to the Canva app in Azure AD.

How to fix it: Make sure the user is assigned to the Canva app in Azure

Error: Multi TeamId User not assigned to all teams

What happened: A user with multiple TeamIds isn’t being added to all the teams associated with the organization.

How to fix it: Use Group Claims to set up TeamId attributes. Custom claim attributes in Azure will only send one TeamId per user.

Canva errors

Error: Multiple OAuth accounts

What happened: The user is signed in with a different Google account.

How to fix it: Ask the user to reset their password. If the error continues, contact us to get help.

Error: No account with that email

What happened: The email domain isn’t registered with Canva.

How to fix it:

Error: Error processing SAML assertion attributes

What happened: There may be a problem with the public certificate.

How to fix it: Check that the latest version of the certificate is correctly pasted in Canva.

Error: SAML login configuration has not been completed

What happened: This may be due to an incomplete SAML setup in Canva or a mismatch between the email from your IdP and your verified domain.

How to fix it: Make sure you've completed all setup steps for your SSO provider and verified all email domains.

Error: We can’t log you in because you don’t belong to a school

What happened: A user with a Student role doesn’t have a TeamId attribute that matches an existing school.

How to fix it:

  • If the user isn't supposed to have the Student role, check the Role attribute in your SAML app.
  • If they're supposed to have the Student role, check that the TeamId attribute is being sent correctly.

Error: Unrecognized identity provider found in SAML assertion

What happened: The SAML 2.0 Endpoint (HTTP) or Identity Provider Issuer fields are incorrect in Canva.

How to fix it: Double-check both values in Canva and confirm they match your IdP.

Error: 404 Not found

How to fix it: Contact us to get help.

Error: Not found

What happened: The SAML 2.0 Endpoint (HTTP) value is incorrect.

How to fix it: Review your ClassLink setup and confirm the correct value.

Error: Cannot parse login request

What happened: The Web Address field in Launchpad is incorrect.

How to fix it: Use your IDP Initiate Login URL in the Web Address field. You’ll find this in your ClassLink SAML settings.

Google errors

Error: 403 app_not_enabled_for_user

What happened: The user doesn’t have access to Canva in Google Admin.

How to fix it:

  1. Sign in to your Admin console.
  2. Go to Apps, then select Web and mobile apps.
  3. Select Canva.
  4. Go to Settings > then select User access.
  5. Set it to On for everyone, then click Save.

Error: 403 app_not_configured_for_user or 403 not_a_saml_app

What happened: The ACS URL or Entity ID values are incorrect.

How to fix it:

  • Double-check both fields in the SAML Service Provider Details section. These values are case-sensitive.
  • If the error continues, wait 24–48 hours and try again — there may be a delay on Google’s end

Error: 400 malformed_certificate

What happened: The public certificate in Canva is incorrect.

How to fix it:

  • Copy the certificate from Google Admin and make sure it includes both Begin Certificate and End Certificate tags.
  • In Google Admin, make sure Signed Response is selected.

Error: null

What happened: The ACS URL or Entity ID values are incorrect.

How to fix it:

  • Review both values in the SAML Service Provider Details section and make sure Signed Response is ticked.
  • If the error continues, check Google’s SAML app error messages article for more help.

Other errors

Error: Teachers are assigned a student role

How to fix it: Review your SSO provider’s SAML attribute mapping and make sure you’ve followed all required steps.

Error: RapidIdentity – 404 Not Found

How to fix it: Review the RapidIdentity setup guide and confirm all steps have been completed.

Error: Teachers are assigned a student role

How to fix it: Review your SSO provider’s SAML attribute mapping and make sure you’ve followed all required steps.

Was this helpful?

Helpful

Unhelpful

People also viewed