Configuring SAML-Based SSO with Canva

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Canva supports a SAML-Based single sign-on (SSO) service for its web-based design application that you can configure in your RapidIdentity portal. These configuration settings are an example and may vary for individual configurations.

Requirements
  • Canva administrator credentials
  • Access to your RapidIdentity administrator portal
  1. Navigate to your RapidIdentity administrator portal.
  2. From the module selector, choose Configuration.
  3. Select Security > Identity Providers > Federation Partners.
  4. Click Add Federation Partner > SAML 2.0.
  5. In the General section, set the following:
    1. Name: Canva
    2. (Optional) Description: SAML SSO Configuration for Canva
    3. Login Hint: Leave the default usernames value.
    4. Is InCommon: Deselected
    5. Metadata: Paste the Canva metadata from https://www.canva.com/_saml/metadata.xml.
  6. In the SSO Settings section, set the following:
    SettingValue
    Include SAML2 Attribute StatementSelected
    Sign SAML2 SSO ResponseNever
    Sign SAML2 SSO AssertionsAlways
    Encrypt SAML2 SSO AssertionsNever
    Encrypt SAML2 SSO Name IDsNever
    Note:

    Leave all other settings in this section at their default values.

  7. In the Attribute Mapping section, add the following attributes. For each attribute, click Add New Attribute +, set the values from the table below, then click Save.
    Attribute TypeLDAP AttributeSAML NameFriendly NameName Format Friendly NameName Format Value
    LDAPmailEmailEmailUnspecifiedurn:oasis:names:tc:SAML:2.0:attrname-format:unspecified
    LDAPgivenNameFirstNameFirstNameUnspecifiedurn:oasis:names:tc:SAML:2.0:attrname-format:unspecified
    LDAPsnLastNameLastNameUnspecifiedurn:oasis:names:tc:SAML:2.0:attrname-format:unspecified
    Name IDidautoPersonSAMAccountNameNot applicableNot applicableNot applicableurn:oasis:names:tc:SAML:2.0:nameid-format:persistent
    Note:

    The SAML Name, Friendly Name, and Name Format Friendly Name fields do not apply to the Name ID attribute type.

  8. For each attribute, select it from the Add Attribute Mapping pop-up menu, select Permit, and click Save.
  9. Click Save.

RapidIdentity is now configured as a SAML identity provider for Canva.

Configure RapidIdentity as the identity provider in Canva to complete the integration. For instructions, see Canva SAML configuration for RapidIdentity.