Canva supports a SAML-Based single sign-on (SSO) service for its web-based design
application that you can configure in your RapidIdentity portal. These configuration
settings are an example and may vary for individual configurations.
Requirements
- Canva administrator credentials
- Access to your RapidIdentity administrator portal
- Navigate to your RapidIdentity administrator portal.
- From the module selector, choose Configuration.
- Select .
- Click .
- In the General section, set the following:
- Name: Canva
- (Optional) Description: SAML SSO Configuration for Canva
- Login Hint: Leave the default
usernames value. - Is InCommon: Deselected
- Metadata: Paste the Canva metadata from
https://www.canva.com/_saml/metadata.xml.
- In the SSO Settings section, set the following:
| Setting | Value |
|---|
| Include SAML2 Attribute Statement | Selected |
| Sign SAML2 SSO Response | Never |
| Sign SAML2 SSO Assertions | Always |
| Encrypt SAML2 SSO Assertions | Never |
| Encrypt SAML2 SSO Name IDs | Never |
Note:
Leave all other settings in this section at their default values.
- In the Attribute Mapping section, add the following
attributes. For each attribute, click Add New Attribute +,
set the values from the table below, then click Save.
| Attribute Type | LDAP Attribute | SAML Name | Friendly Name | Name Format Friendly Name | Name Format Value |
|---|
| LDAP | mail | Email | Email | Unspecified | urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified |
| LDAP | givenName | FirstName | FirstName | Unspecified | urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified |
| LDAP | sn | LastName | LastName | Unspecified | urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified |
| Name ID | idautoPersonSAMAccountName | Not applicable | Not applicable | Not applicable | urn:oasis:names:tc:SAML:2.0:nameid-format:persistent |
Note:
The SAML Name, Friendly Name,
and Name Format Friendly Name fields do not apply
to the Name ID attribute type.
- For each attribute, select it from the Add Attribute
Mapping pop-up menu, select Permit, and
click Save.
- Click Save.
RapidIdentity is now configured as a SAML identity provider for Canva.
Configure RapidIdentity as the identity provider in Canva to complete the
integration. For instructions, see Canva SAML configuration for
RapidIdentity.