Canva home
Help

PingOne SAML configuration


Once you have a PingOne account that allows you to add a new app, you may start setting up Single Sign-On (SSO) for your team.

Who can use this feature?

SCIM is only available to Canva Enterprise and Canva for Districts, and it isn’t available for new Canva Teams subscribers.

Limitations: For teams within an organization's structure (both single-team or multi-team), user provisioning and deprovisioning are supported. However, all other functionalities, such as provisioning users directly into specific teams or creating groups, aren’t currently supported.

Step 1: Install the Canva app on PingIdentity

  1. Under Connections, go to Application Catalog.
  2. Search for Canva and select it.
  3. Click Next.
  4. Check the Map Attributes section. If necessary, modify the attributes so that the state is as shown below. Then, click Next.
  5. Leave Groups empty and click Save.
  6. Go to Connections again and select Applications. Then, select Canva.
  7. Go to the Configuration tab.
  8. Click Download Metadata. Copy and take note of the Issuer ID, Single Signon Service, and certificate. We'll need this information later for setting up SAML SSO.
  9. Change policies or access as per your organization’s requirements.

Step 2: Verify your domain on Canva

  1. Log in to your Canva account.
  2. On the homepage, select your account profile to open menu.
  3. Choose
    Settings.
  4. From the side menu, select
    SSO and provisioning.
  5. Under Domain verification, click Add Domain to enter your team’s domain.
  6. Click Submit domain. You will then be provided with a DNS token.
  7. Create a TXT record of the DNS token using your domain host. Help from your IT team might be needed for this step.

Learn more about adding a TXT record in our Setting up Single Sign-on (SSO) article.

Step 3: Set up SAML SSO in Canva

  1. Log in to your Canva account.
  2. On the homepage, select your account profile to open menu.
  3. Choose
    Settings.
  4. From the side menu, select
    SSO and provisioning.
  5. Under Single Single Sign-On (SSO) section, select Set up SSO.
  6. Under Add your IdP’s metadata, enter the following details from Okta: 
    • In the SSO or login URL field, paste your Identity Provider Single Sign-on Service URL.
    • In the Entity ID or Issuer URL field, paste your Issuer ID.
    • In the X.509 Public Certificate field, paste all of the contents from your X.509 Certificate section on the downloaded metadata (sample certificate).
  7. Click Save changes.

Step 4: Test your SSO login experience

  1. On the homepage, select your account profile to open menu.
  2. Choose
    Settings.
  3. From the side menu, select
    SSO and provisioning.
  4. Under Single Single Sign-On (SSO) section, click Manage.
  5. Choose Configure SSO Settings.
  6. Under Configure your Settings, select optional for everyone.
  7. Log out of your Canva account.
  8. Log in again using SSO. On the login page, select Continue with email, then select the Continue with single sign-on (SSO) link.

If you were redirected to your team’s account, you have successfully configured SSO!

Step 5: Set up login and signup controls

Choose how you want people to log in to your SSO-managed teams.

  1. On the homepage, select your account profile to open menu.
  2. Choose
    Settings.
  3. From the side menu, select
    SSO and provisioning.
  4. Under Single Single Sign-On (SSO) section, click Manage.
  5. Choose Configure SSO Settings.
  6. Under Configure your Settings, select an option. Learn more about each option in Setting up login and signup controls.
  7. Click Save changes.

If you’re having trouble setting up SSO, check our Troubleshooting SSO errors article.

Was this helpful?

Helpful

Unhelpful

People also viewed