Canva home
Help

Set up Single Sign-On (SSO) for Canva websites


Enable Single Sign-On (SSO) protection for websites published to domains owned or connected via Canva. This ensures that only authorized users from your Identity Provider (IdP) can access your published Canva sites, providing a secure, seamless browsing experience.

This guide is for Canva Enterprise and Canva Education Organization administrators responsible for managing their team’s SSO settings.

Before you begin

  • Websites published before the SSO for websites setup must be re-published to activate protection.
  • All new websites published to the protected domain will be SSO-protected automatically.

Step 1: Start the setup in Canva

We're rolling out navigation changes gradually, so some steps in this Help article may not accurately reflect what you see in the app. If you can't find Canva AI, your profile photo, or your Print cart on the homepage, go to

More.

  1. On the homepage, select your profile icon to open the menu.
  2. Select
    Settings.
  3. Under Organization settings, select SSO for websites, then Create new connection.
  4. Under Select a website domain to protect with SSO, choose a Canva domain.

Note:

  • Domains already configured with SSO won't be selectable.
  • External domains may take time to prepare before they can be selected.

5. Select Next to proceed.

Step 2: Name your SSO connection

Step 2: Name your SSO connection

Create a Connection name to easily identify which domain is protected.

  1. Under Name this connection, type in a Connection name. We highly recommend something like:
    • IdP for [yourdomain.com]
    • Protected Websites for [yourdomain.com] Note: You can also use this name when creating the connection in your Identity Provider (IdP).
  2. Select Next.

 Step 3: Set up a new SAML 2.0 app in your IdP (outside of Canva)

Configure a new SAML 2.0 application in your Identity Provider (IdP), such as  Okta, Azure AD, Google Workspace, Ping Identity, JumpCloud, OneLogin, or Auth0.

  1. Sign in to your IdP.
  2. Follow your IdP’s steps to create a new SAML 2.0 app integration. Note: This is a separate app to Canva’s SSO Login app, which is named “Canva” in some IdP app galleries, or app catalogs.
  3. When prompted to configure the SAML Settings, use the following information:
    • Single sign-on URL / ACS URL / Reply URL / SSO Service URL / Recipient: https://[yourdomain.com]/_api/saml
    • Audience URI / Entity ID / Identifier / Party Identifier: Copy this from Canva, it'll look something like "https://www.canva.com/website/_saml/1fe3f205-077b-4739-359f-e9357eb77d0d."
    • NameID Format (recommended): Persistent
      • Note: We recommend choosing a NameId format that doesn't change, if your IdP supports this.
    • Important: Make sure your SAML response includes a signature. You may need to turn on a setting like "Signed response." This may be in the advanced settings, and most IdPs have this set by default.
    • If asked for an ACS URL Validator, use: ^https://[yourdomain.com]/_api/saml$
      • Note: That is the same ACS URL with the symbols “^” and “$” to indicate  the start and end of the URL.
  4. Assign the app to the appropriate Users/Groups/Assignments. These are the people who'll have access to your IdP. 
    • You can grant access to users without existing Canva accounts, since this SSO setup functions separately from Canva's standard login.
  5. Once you complete the app setup in your IdP, it will provide the “IdP metadata,” which needs to be copied into Canva in the next step.
  6. Back in Canva, select Next to proceed to the next steps.

Step 4: Add your IdP’s metadata in Canva

To complete the SSO setup in Canva, you can choose one of two methods for adding your Identity Provider’s (IdP) metadata:

Option 1: Upload the Metadata file

  1. From your Identity Provider, download the XML metadata file.
  2. In Canva, go to Upload metadata file section.
  3. Upload or drag the XML file into the field provided.
  4. Canva will automatically extract and populate all the required fields.
  5. Once done, click or tap Finish set up.

Option 2: Manually add metadata

  1. Under SAML 2.0 Endpoint (HTTP) or SSO URL, copy-paste the Sign on URL metadata. You can find this in your IdP application’s  Authentication page. It may also be called the Login URL or SAML 2.0/W-Federation URL. 
  2. Under Entity ID or Issuer URL, copy-paste your IdP’s Issuer metadata. It may also be called Identity Provider Issuer, or IdP Identifier.
  3. Finally, under x.509 Public Certificate, copy-paste your IdP’s Signing Certificate. You may have to download the certificate from your IdP and copy-paste its contents.
  4. Select Finish setup to complete the configuration.

Check if your website is SSO-protected

To verify that SSO is working:

  1. Publish a test website to a domain that's SSO-enabled.
  2. Visit the website URL in a private/incognito window.
  3. If you're redirected to your Identity Provider (IdP) login page, the SSO protection is working as expected. Anyone who's assigned the application in your IdP should be able to log in successfully and view the website. 

Update the SSO settings in Canva

To update the SAML metadata for your SSO connection:

  1. From the homepage, go to Organization settings. 
  2. Select SSO for websites, then click or tap the Pencil icon next to the connection you’d like to edit.
  3. Edit the metadata using the same steps as you did during setup.

FAQs

I have already set up SSO for Canva. How is this different?

If you’ve set up SSO in the SSO & provisioning tab in your Settings, that’s great! This allows your team to sign in to Canva via SSO.

This article is for “SSO for websites,” an entirely separate feature, where the setup is quite similar. This setup allows your team to sign in to view a Canva website on the internet. It requires a new app in your identity provider, and gives you more freedom as to who you allow to view your websites.

Do I need to repeat this process for each domain?

Yes. This means you can assign different sets of people to different domains.

Can I give access to my Canva websites to people who don’t have Canva?

Yes! The people who have access are managed entirely in your identity provider (IdP).

Do I need to re-publish existing sites?

Yes. Sites published before SSO setup must be re-published for protection to take effect.

Can I use external domains?

Yes, as long as they're verified and connected in Canva. Setup may take longer.

Can I change the SSO-protected domain later?

No. To protect a different domain, create a new connection.

Is this available to all Canva accounts?

This feature is available to Canva Enterprise Organization administrators.

How do I troubleshoot SSO for websites?

If you're running into issues after setup, here are some of the common issues and how to fix them.

Was this helpful?

Helpful

Unhelpful

People also viewed