|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request SP to configure |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
ー |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
ー |
Android - TrustLogin Mobile App In-App Browser |
|
|
〇 |
Android - Native App |
|
Prerequisites
If you want to assign the "Brand Designer" role when creating a user via SAML JIT, you need to configure a custom attribute in TrustLogin member information beforehand to link the Canva role. If you do not assign a role, this preparation is not required.
Note: Only if you want to assign the "Brand Designer" role, configure a custom attribute with the attribute value set to "Admin". If you do not configure a custom attribute, users will be added as "Member".
Note: The attribute name can be anything you choose.
[TrustLogin Custom Attribute Configuration Example]
Please refer to the following pages for instructions on how to configure custom attributes.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
- Register the "Application Name" and "Icon" (optional).
- Make a note of the "Identity Provider URL" and "Issuer/Entity ID" values in "Identity Provider Information", and download the certificate using the "Get Certificate" button.
Now, switch to configuring Canva.
Do not click the "Register" button yet — open Canva in a separate window.
Canva Settings
-
Log in to Canva and select "Account Settings" from the profile icon.
- Open "SSO & Provisioning" and click "Add Domain" under "1. Verify the domain you want to use SSO with".
- Enter the domain you want to add and click "Submit Domain".
- Copy the displayed TXT record token and configure your domain's DNS records.
Note: For instructions on configuring your domain's DNS records, please refer to your domain registrar's help documentation.
- Once the DNS record takes effect and domain verification is complete, the status will change to "Verified".
- Configure the "3. Get information from your identity provider" section as follows.
SAML 2.0 Endpoint (HTTP) The "Identity Provider URL" obtained from TrustLogin Identity Provider Issuer The "Issuer/Entity ID" obtained from TrustLogin x.509 Certificate The contents of the "certificate" obtained from TrustLogin
- In "4. Select the users who need to use SSO", select according to your company's policy, and click "Save Changes".
Note: When configuring SAML, please select "Everyone with an email address containing '[Your Domain]' can use SSO"
.
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Sign SAML Response Check the box Value for Name ID [Member]-[email] Entity ID https://www.canva.com Name ID Format unspecified ACS URL to Service https://www.canva.com/login/saml
-
In "SAML Attribute Settings", add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
Note: Only add the Role row if you are assigning a role. It is not required if you are not assigning a role.
Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value NameID Unspecified NameID Member Member - Email Address FirstName Unspecified FirstName Member Member - First Name LastName Unspecified LastName Member Member - Last Name Role Unspecified Role Custom attribute Attribute name is up to you
(e.g., CanvaAdmin)
- Click the "Register" button to save.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
- Click the app from "My Page" or the "Browser Extension" and check whether login succeeds.
②When an administrator adds members
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Note: Only for your first login, log out of Canva once, and on the Canva login page, select [Continue with email], then select [Continue with Single Sign-On (SSO)], and try logging in to confirm it succeeds.
SSO Authentication Method for the Native App
If you are using the native app, you can use it with the following method.
- Download the Canva native app.
- Open the Canva app and select "Continue with email".
- Enter your email address.
- Select "Log in with SSO".
- You will be redirected to the TrustLogin login screen. Log in to TrustLogin and use the app. (Note: If TrustLogin is already open, you will not be redirected to the login screen.)