Setting up SCIM provisioning in PingIdentity
Configure SCIM (System for Cross-domain Identity Management) standard for your team or district using PingIdentity.
Who can use this feature?
SCIM is only available to Canva Enterprise and Canva for Districts, and it isn’t available for new Canva Teams subscribers.
Limitations: For teams within an organization's structure (both single-team or multi-team), user provisioning and deprovisioning are supported. However, all other functionalities, such as provisioning users directly into specific teams or creating groups, aren’t currently supported.
Supported provisions
- Create users - Users in Ping Identity assigned to the Canva App are added as members of the organization in Canva.
- Update user attributes - Updates made to the user's profile through PingIdentity will be pushed to Canva.
- Deactivate users - Deactivating the user through PingIdentity will lock the user in Canva.
Step 1: Configuring SCIM Provisioning in PingIdentity
- Under Connections, go to Provisioning.
- Click the plus icon.
- Select Identity Store.
- Enter SCIM in the search box and click Select.
- Enter a fitting name and description. Then, click Next.
- Enter the following information you obtain from Canva during Step 1 of SCIM provisioning.
- Users Resource: /Users
- Authentication method: OAuth 2 Bearer Token
- OAuth Access Token field: Paste the token copied from Canva.
- Click Test Connection.
- If everything is set up correctly, you should see a “Connection successful” message. Click Next.
- Under Remove Action, click on the dropdown menu and select Disable. This will lock a user on Canva. Deprovision on Rule Deletion is optional. You may click on the question mark icon next to it to understand the implications.
- Click Finish.
- Finally, Enable the SCIM connection by switching the toggle on.
Step 2: Attribute mapping between PingIdentity and Canva
Now that a SCIM connection has been established, we'll set up rules or attribute mapping.
- On PingIdentity, go to Provisioning.
- Click the plus button and select New Rule.
- Enter a fitting name and click Create Rule.
- Select the connection established earlier and click Save.
- Edit the user filters as per your organization’s requirements. As of writing, PingIdentity doesn't support wildcards for user filter. User filter decides which users will get access to the Canva app.
- Edit the attributes as shown below.
- Click Save.
- Enable the new rule by toggling the switch on.
Congratulations! You've now successfully enabled SCIM provisioning.
Troubleshooting
You may view the event logs at your PingIdentity account. Go to Environment and select Audit.
If you’re having trouble configuring your PingOne SCIM integration, contact our Support team for help.
For Canva Education, please reach out to your contact person at Canva for help.
For advanced users, please see our developer documentation on the SCIM endpoint for more information.
Was this helpful?
Helpful
Unhelpful