Okta SAML configuration
Set up Single Sign-On (SSO) for your organization using Okta.
Who can use this feature?
SCIM is only available to Canva Enterprise and Canva for Districts, and it isn’t available for new Canva Teams subscribers.
Limitations: For teams within an organization's structure (both single-team or multi-team), user provisioning and deprovisioning are supported. However, all other functionalities, such as provisioning users directly into specific teams or creating groups, aren’t currently supported.
Step 1: Add Canva to Okta
- From your Okta Dashboard, go to Applications.
- Click Browse App Catalog.
- In the app catalog, search for Canva.
- Click Add Integration.
- On the Sign-On Options page, select SAML 2.0, then click on View Setup Instructions.
- On the Setup Instructions page, go to the SAML credentials section and copy the following details. You’ll need these to complete the setup in Canva.
- Identity Provider Single Sign-on URL
- Identity Provider Issuer
- X.509 Certificate (Click Download and copy the file contents)
Step 2: Verify your domain
Changing your SSO domain? To prevent duplicate user accounts, contact our Support team before the domain change.
- Log in to your Canva account.
- On the homepage, select your account profile to open menu.
- Choose gear icon Settings.
- From the side menu, click the SSO and provisioning tab.
- Under Domain verification, enter your team’s domain.
- Click Submit domain. You will then be provided with a DNS token.
- Create a TXT record of the DNS token using your domain host. Help from your IT team might be needed for this step.
Learn more about adding a TXT record in our Setting up Single Sign-on (SSO) article.
Step 3: Set up SAML SSO in Canva
- Log in to your Canva account.
- On the homepage, select your account profile to open menu.
- Choose Settings.
- From the side menu, click the SSO and provisioning tab.
- Click Single sign-on (SSO) > Manage > Edit IdP metadata.
- Enter your identity provider’s details in the three fields:
- SSO or login URL: Paste your Identity Provider Single Sign-on URL.
- Entity ID or Issuer URL: Paste your Identity Provider Issuer.
- X.509 Public Certificate: Paste all of the contents from your X.509 Certificate (sample certificate).
- Click Save and next.
Step 4: Configure TeamId in Canva (optional if you are not a multi-team organization)
The value for the ‘TeamId’ will need to be mapped to each team in Canva and should be a unique value. The ‘TeamId’ value can be added/edited by an Organization Administrator.
What is TeamId and why is it important?
TeamId is a custom SAML attribute for multi-team organizations, indicating team membership. Canva adds users to specified teams if they're not already members but doesn't remove users based on this attribute.
- Login as Organization admin.
- From the homepage, go to Settings.
- Under Organization settings, go to Teams.
- Click More next to the team you want to edit.
- Select Edit Team Id.
- Enter a unique value for the TeamId and save your changes.
Step 5: Configure TeamId in Okta
Before proceeding, ensure:
- The Canva Okta application is set up.
- Okta groups are assigned to the Canva application.
- SAML settings are configured in Canva.
Option 1: Use group naming conventions
- In Okta, navigate to Directory > Groups.
- Create groups following a consistent naming convention (e.g., all groups start with "Acme").
- Edit SAML settings by going to General > SAML settings > Edit and click Next until you reach the Configure SAML screen.
- Configure the Group Attribute:
- Name - teamId
- Name format (optional) - Unspecified
- Filter - Starts with
- Value: Your group naming convention (e.g., "Acme").
- Save the settings and check the changes by navigating to Applications > Canva.
Option 2: Map individual group IDs
- Ensure Okta group names match the TeamId for your Canva teams.
- Okta group interface
- Canva Teams with IDs
- Okta group interface
- Extract group IDs by navigating each group in Okta. Record the group ID from the URL (letters and numbers after the last /).
- In Okta, go to General > SAML Settings > Edit, then click Next.
- Add an attribute:
- Name: TeamId
- Value: Use the following format:
- Replace <group id> with the actual group IDs you extracted in Step 2.
- Click Next, then Finish.
Step 6: Test your SSO login experience
There are two easy ways to test your SSO setup:
Option 1: Use the Test SSO button
If you're still on the Set up SSO page, scroll to the Test your SSO connection section and click Test SSO. If you're starting from the Canva homepage instead:
- In the bottom-left corner, click your profile avatar, then select Settings.
- From the side menu, click the SSO and provisioning tab.
- Under Single sign-on (SSO) > Manage > Test SSO.
This lets you quickly check if everything’s working without logging out.
Option 2: Log out and back in using SSO
- Before logging out, go to the SSO and provisioning tab.
- Click Single sign-on (SSO) > Manage > Configure SSO settings.
- Set the login option to Optional for everyone.
- Log out of your Canva account.
- On the login page, click Continue with email, then select Log in with SSO.
If you’re taken to your team’s page after logging in, you successfully set up SSO! If you get an error, check our Troubleshooting SSO errors article for help.
Quick tip: Using both methods can give you extra peace of mind that everything’s set up right.
Step 7: Set up login and signup controls
Choose how you want people to log in to your SSO-managed teams.
- From the homepage, select your account profile to open menu.
- Go to Settings > SSO and provisioning.
- Click Single sign-on (SSO) > Manage > Configure SSO settings.
- Select one of the login options. Learn more about each option in Setting up login and signup controls.
- Click Save changes.
If you’re having trouble setting up SSO, check our Troubleshooting SSO errors article.
Was this helpful?
Helpful
Unhelpful