CANVAS SCIM CONFIGURATION
Setting up SCIM with Canvas
Canvas supports SCIM (System for Cross-domain Identity Management), allowing your organisation to automatically provision and manage Canvas users and groups through your identity provider.
Using SCIM, changes made within your identity provider can be synchronised with Canvas, reducing the need to manually create and manage individual users.
Before you start
SCIM must first be enabled for a trusted Canvas user within your organisation.
Contact your Canvas Account Manager and let them know the email address of the Canvas user who will be responsible for configuring SCIM. This user must already have a Canvas account, or will need one to be created.
Once SCIM access has been enabled, the nominated user should log out of Canvas and log back in before continuing with the setup.
Configure your SCIM connection
Once SCIM access has been enabled:
Log in to the Canvas Design platform for your region.
Select Organisations from the left-hand navigation.
Select your organisation.
Hover over Details, then select SCIM.
Copy the Base SCIM URL. Add this to the Base URL or Tenant URL field within your identity provider.
In Canvas, select + in the top-right corner to create a new SCIM token.
Enter a name that will help you identify the token in future, then select Add.
Copy the generated secret value and add this to the Secret token or Bearer token field within your identity provider.
Save the configuration and use your identity provider's connection test to confirm the integration is working.
Important: Keep your SCIM secret secure. It provides authenticated access to your organisation's SCIM integration and should not be shared unnecessarily.
Managing group permissions
Groups provisioned through SCIM can be given permissions within Canvas.
Once your groups have been synchronised:
Navigate to your organisation in Canvas.
Hover over Details, then SCIM, and select Groups.
Select the group you want to manage.
Open the Permissions tab to view its existing permissions.
Select Add Permissions to grant additional Canvas permissions to the group.
This allows access to Canvas to continue to be managed through your identity provider, while Canvas-specific permissions can be assigned to the relevant groups.
User requirements
When provisioning users through SCIM, Canvas requires:
userName – must be provided and must be unique. Usernames are treated as case-insensitive.
Email address – a valid email address is required. Canvas will use the first available value in the following order:
The emails entry marked with primary: true
The first value provided in emails
userName
name.givenName and name.familyName – these fields are optional, but we recommend providing them to ensure users are displayed correctly throughout Canvas.
Need help?
If you would like to enable SCIM for your organisation, or need assistance with the initial configuration, please contact your Canvas Account Manager.