OneRoster Provisioning
Configure OneRoster to send your roster data to Canva.
Step 1: Add the Canva app to the Roster Server
- Log in to the SIS (Student Information System).
- Select Roster Server > Manage > Applications.
- On the top corner, select the + Add button, then search for 'Canva Education'.
- Select the + Add button next to 'Canva Education'.
- Set up the data to be sent to Canva and enable the sync. We strongly recommend enabling a full permissions sync.
Step 2: Copy API credentials
- On the Roster Server Console, select Apps from the toolbar.
- Select the gear icon to show more actions for the Canva Education app.
- On the side menu, select API.
- Go to the API Credentials tab.
- Copy the following details. You’ll need these in the next step.
- Key
- Secret
- Webpage URL - You can get this by selecting Explore in API. Make sure to copy up to and include "/v1p1".
Step 3: Configure Roster Server in Canva
- Log in to your Canva account.
- On the homepage, select your account profile to open menu.
- Choose gear icon .
- From the side menu, select the SSO and provisioning tab.
- Under Single Single Sign-On (SSO) section, click Manage.
- Choose Configure Provisioning.
- Under Provision Accounts for your team, select Add provisioning method.
- Choose OneRoster.
- Go to the Sync Roster with OneRoster section, and fill out the details.
In the Endpoint URL field, paste your Webpage URL.
Refer to the screenshot below for the access token URL formats.
Provider | Standard Token URL format where [youridentifierhere] represents your domain or instance-specific identifier. Ask your One Roster provider if you're not sure |
|---|---|
Aeries | https://[youridentifierhere].aeries.net/aeries/token |
Classlink | Take your original URL from Classlink (including the "oneroster" or "rosterserver" part and then add "/token" to the end. For example, https://[youridentifierhere].oneroster.com/token |
Infinite Campus | See your Infinite Campus OneRoster Connection to Canva |
Skyward | ISCorp SMS 2.0: https://skyward.iscorp.com/[youridentifierhere]/token |
ISCorp Qmlativ: https://skyward.iscorp.com/[youridentifierhere]API/oauth/token | |
Self Hosted SMS 2.0: https://[skywarddomain.com]/[youridentifierhere]/token | |
Self Hosted Qmlativ: https://[skywarddomain].com/[youridentifierhere]API/oauth/token |
In the API Key field, paste your Key. In the API Secret field, paste your Secret.
Turn on Enable Daily Sync and Test settings to test your configuration settings. If you get an error, here are some things to check:
- If you correctly copied the credentials
- If the app (plugin in your OneRoster data provider) is enabled
- If the Token url is correct
- If the endpoint is correct (for example, there shouldn’t be text after “v1p1”)
If you’ve made sure all of the above and the error persists, it could be an allowlist issue. Contact our Support Team so we can check our allowlist.
If there are no errors, select Save changes and then Sync now.
Syncing may take a few hours to finish. To check if the users have been added, go to the People page in Settings.
How OneRoster sync updates users and access
Once OneRoster provisioning is enabled, Canva will continuously sync user and membership changes based on what your OneRoster source sends. This includes updates such as:
- Adding users to schools/teams/brands
- Moving users between classes/groups
- Removing users from schools/teams/brands when they’re no longer returned in the roster data or are marked as inactive/deleted in the rostering source
Users must remain in the school/district Brand to keep access. If a OneRoster sync removes a user from the Brand, the user may lose access, even if nothing else about their account changed.
Pause Purge windows (seasonal removal protection)
OneRoster syncing can trigger removals when users are no longer present (or no longer eligible) in the rostering source. To help prevent large-scale removals during long school breaks, Canva uses a pause purge window.
Default pause purge window (US summer)
Note: This default pause purge window applies to US schools and districts only.
- May 30 – September 1 (recurs yearly)
- Times are in UTC, starting at 00:00 on each date
- Window opens: May 30 00:00 UTC
- Window closes: September 1 00:00 UTC
Some schools use a custom pause purge window that differs from the default. If a custom window is set up for your school, it will be used instead of the default dates.
Assigning the correct roles for data syncing
Canva supports the following roles: team admin, Teacher, aide, and student. Users assigned with a role that’s unsupported will not get provisioned in the syncs.
However, while we recognise the team admin role, this role can’t be assigned to users and will be assigned as a Teacher by default.
If you don’t see the Roster Settings section in Canva, reach out to your contact person in Canva and let them know that you’re rostering.
Was this helpful?
Helpful
Unhelpful