Canva SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Canva is required.

  • Domain ownership and verification are required to apply SAML.
  • If you want to assign a role in Canva, only the "Brand Designer" role can be assigned. The "Admin" role cannot be assigned, so you will need to configure it manually in Canva.
  • Even if you change the name in TrustLogin, the information will not be updated in Canva. If you want to change the name, please update it manually in Canva.
  • This manual was created based on verification performed with Canva for Teams.
  • Please refer to the manual provided by Canva for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App


Prerequisites

If you want to assign the "Brand Designer" role when creating a user via SAML JIT, you need to configure a custom attribute in TrustLogin member information beforehand to link the Canva role. If you do not assign a role, this preparation is not required.

Note: Only if you want to assign the "Brand Designer" role, configure a custom attribute with the attribute value set to "Admin". If you do not configure a custom attribute, users will be added as "Member".

Note: The attribute name can be anything you choose.


[TrustLogin Custom Attribute Configuration Example]

Canva10.png

Please refer to the following pages for instructions on how to configure custom attributes.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    001.png


  2. Register the "Application Name" and "Icon" (optional).
    Canva01.png

  3. Make a note of the "Identity Provider URL" and "Issuer/Entity ID" values in "Identity Provider Information", and download the certificate using the "Get Certificate" button.03

Now, switch to configuring Canva.
Do not click the "Register" button yet — open Canva in a separate window.

Canva Settings

  1. Log in to Canva and select "Account Settings" from the profile icon.
    Canva02.png

  2. Open "SSO & Provisioning" and click "Add Domain" under "1. Verify the domain you want to use SSO with".
    Canva03.png

  3. Enter the domain you want to add and click "Submit Domain".
    Canva04.png

  4. Copy the displayed TXT record token and configure your domain's DNS records.
    Note: For instructions on configuring your domain's DNS records, please refer to your domain registrar's help documentation.
    Canva05.png


  5. Once the DNS record takes effect and domain verification is complete, the status will change to "Verified".
    Canva08.png

  6. Configure the "3. Get information from your identity provider" section as follows.
    SAML 2.0 Endpoint (HTTP) The "Identity Provider URL" obtained from TrustLogin
    Identity Provider Issuer The "Issuer/Entity ID" obtained from TrustLogin
    x.509 Certificate The contents of the "certificate" obtained from TrustLogin

    Canva06.png

  7. In "4. Select the users who need to use SSO", select according to your company's policy, and click "Save Changes".
    Note: When configuring SAML, please select "Everyone with an email address containing '[Your Domain]' can use SSO"   
    .
    Canva09.png

    Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Sign SAML Response Check the box
    Value for Name ID [Member]-[email]
    Entity ID https://www.canva.com
    Name ID Format unspecified
    ACS URL to Service https://www.canva.com/login/saml

    Canva07.png

  2. In "SAML Attribute Settings", add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
    Note: Only add the Role row if you are assigning a role. It is not required if you are not assigning a role.

    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    NameID Unspecified NameID Member Member - Email Address
    FirstName Unspecified FirstName Member Member - First Name
    LastName Unspecified LastName Member Member - Last Name
    Role Unspecified Role Custom attribute Attribute name is up to you
    (e.g., CanvaAdmin)

    Canva11.png

  3. Click the "Register" button to save.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.
  4. Click the app from "My Page" or the "Browser Extension" and check whether login succeeds.

②When an administrator adds members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Note: Only for your first login, log out of Canva once, and on the Canva login page, select [Continue with email], then select [Continue with Single Sign-On (SSO)], and try logging in to confirm it succeeds.

SSO Authentication Method for the Native App
If you are using the native app, you can use it with the following method.

  1. Download the Canva native app.
  2. Open the Canva app and select "Continue with email".
    Canva12.png

  3. Enter your email address.
    Canva13.png

  4. Select "Log in with SSO".
    Canva14.png

  5. You will be redirected to the TrustLogin login screen. Log in to TrustLogin and use the app. (Note: If TrustLogin is already open, you will not be redirected to the login screen.)




Canva SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Canva is required.

  • Domain ownership and verification are required to apply SAML.
  • If you want to assign a role in Canva, only the "Brand Designer" role can be assigned. The "Admin" role cannot be assigned, so you will need to configure it manually in Canva.
  • Even if you change the name in TrustLogin, the information will not be updated in Canva. If you want to change the name, please update it manually in Canva.
  • This manual was created based on verification performed with Canva for Teams.
  • Please refer to the manual provided by Canva for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App


Prerequisites

If you want to assign the "Brand Designer" role when creating a user via SAML JIT, you need to configure a custom attribute in TrustLogin member information beforehand to link the Canva role. If you do not assign a role, this preparation is not required.

Note: Only if you want to assign the "Brand Designer" role, configure a custom attribute with the attribute value set to "Admin". If you do not configure a custom attribute, users will be added as "Member".

Note: The attribute name can be anything you choose.


[TrustLogin Custom Attribute Configuration Example]

Canva10.png

Please refer to the following pages for instructions on how to configure custom attributes.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    001.png


  2. Register the "Application Name" and "Icon" (optional).
    Canva01.png

  3. Make a note of the "Identity Provider URL" and "Issuer/Entity ID" values in "Identity Provider Information", and download the certificate using the "Get Certificate" button.03

Now, switch to configuring Canva.
Do not click the "Register" button yet — open Canva in a separate window.

Canva Settings

  1. Log in to Canva and select "Account Settings" from the profile icon.
    Canva02.png

  2. Open "SSO & Provisioning" and click "Add Domain" under "1. Verify the domain you want to use SSO with".
    Canva03.png

  3. Enter the domain you want to add and click "Submit Domain".
    Canva04.png

  4. Copy the displayed TXT record token and configure your domain's DNS records.
    Note: For instructions on configuring your domain's DNS records, please refer to your domain registrar's help documentation.
    Canva05.png


  5. Once the DNS record takes effect and domain verification is complete, the status will change to "Verified".
    Canva08.png

  6. Configure the "3. Get information from your identity provider" section as follows.
    SAML 2.0 Endpoint (HTTP) The "Identity Provider URL" obtained from TrustLogin
    Identity Provider Issuer The "Issuer/Entity ID" obtained from TrustLogin
    x.509 Certificate The contents of the "certificate" obtained from TrustLogin

    Canva06.png

  7. In "4. Select the users who need to use SSO", select according to your company's policy, and click "Save Changes".
    Note: When configuring SAML, please select "Everyone with an email address containing '[Your Domain]' can use SSO"   
    .
    Canva09.png

    Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Sign SAML Response Check the box
    Value for Name ID [Member]-[email]
    Entity ID https://www.canva.com
    Name ID Format unspecified
    ACS URL to Service https://www.canva.com/login/saml

    Canva07.png

  2. In "SAML Attribute Settings", add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
    Note: Only add the Role row if you are assigning a role. It is not required if you are not assigning a role.

    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    NameID Unspecified NameID Member Member - Email Address
    FirstName Unspecified FirstName Member Member - First Name
    LastName Unspecified LastName Member Member - Last Name
    Role Unspecified Role Custom attribute Attribute name is up to you
    (e.g., CanvaAdmin)

    Canva11.png

  3. Click the "Register" button to save.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.
  4. Click the app from "My Page" or the "Browser Extension" and check whether login succeeds.

②When an administrator adds members

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Note: Only for your first login, log out of Canva once, and on the Canva login page, select [Continue with email], then select [Continue with Single Sign-On (SSO)], and try logging in to confirm it succeeds.

SSO Authentication Method for the Native App
If you are using the native app, you can use it with the following method.

  1. Download the Canva native app.
  2. Open the Canva app and select "Continue with email".
    Canva12.png

  3. Enter your email address.
    Canva13.png

  4. Select "Log in with SSO".
    Canva14.png

  5. You will be redirected to the TrustLogin login screen. Log in to TrustLogin and use the app. (Note: If TrustLogin is already open, you will not be redirected to the login screen.)