PingOne SAML configuration
Once you have a PingOne account that allows you to add a new app, you may start setting up Single Sign-On (SSO) for your team.
Who can use this feature?
SCIM is only available to Canva Enterprise and Canva for Districts, and it isn’t available for new Canva Teams subscribers.
Limitations: For teams within an organization's structure (both single-team or multi-team), user provisioning and deprovisioning are supported. However, all other functionalities, such as provisioning users directly into specific teams or creating groups, aren’t currently supported.
Step 1: Install the Canva app on PingIdentity
- Under Connections, go to Application Catalog.
- Search for Canva and select it.
- Click Next.
- Check the Map Attributes section. If necessary, modify the attributes so that the state is as shown below. Then, click Next.
- Leave Groups empty and click Save.
- Go to Connections again and select Applications. Then, select Canva.
- Go to the Configuration tab.
- Click Download Metadata. Copy and take note of the Issuer ID, Single Signon Service, and certificate. We'll need this information later for setting up SAML SSO.
- Change policies or access as per your organisation’s requirements.
Step 2: Verify your domain on Canva
- Log in to your Canva account.
- On the homepage, select your account profile to open menu.
- Choose Settings
- From the side menu, select SSO and provisioning.
- Under Domain verification, click Add Domain to enter your team’s domain.
- Click Submit domain. You will then be provided with a DNS token.
- Create a TXT record of the DNS token using your domain host. Help from your IT team might be needed for this step.
Learn more about adding a TXT record in our Setting up Single Sign-on (SSO) article.
Step 3: Set up SAML SSO in Canva
- Log in to your Canva account.
- On the homepage, select your account profile to open menu.
- Choose Settings
- From the side menu, select SSO and provisioning.
- Under Single Single Sign-On (SSO) section, select Set up SSO.
- Under Add your IdP’s metadata, enter the following details from Okta:
- In the SSO or login URL field, paste your Identity Provider Single Sign-on Service URL.
- In the Entity ID or Issuer URL field, paste your Issuer ID.
- In the X.509 Public Certificate field, paste all of the contents from your X.509 Certificate section on the downloaded metadata (sample certificate).
- Click Save changes.
Step 4: Test your SSO login experience
- On the homepage, select your account profile to open menu.
- Choose Settings
- From the side menu, select SSO and provisioning.
- Under Single Single Sign-On (SSO) section, click Manage.
- Choose Configure SSO Settings.
- Under Configure your Settings, select optional for everyone.
- Log out of your Canva account.
- Log in again using SSO. On the login page, select Continue with email, then select the Continue with single sign-on (SSO) link.
If you were redirected to your team’s account, you have successfully configured SSO!
Step 5: Set up login and signup controls
Choose how you want people to log in to your SSO-managed teams.
- On the homepage, select your account profile to open menu.
- Choose Settings
- From the side menu, select SSO and provisioning.
- Under Single Single Sign-On (SSO) section, click Manage.
- Choose Configure SSO Settings.
- Under Configure your Settings, select an option. Learn more about each option in Setting up login and signup controls.
- Click Save changes.
If you’re having trouble setting up SSO, check our Troubleshooting SSO errors article.
Was this helpful?
Helpful
Unhelpful