Showing results for 
Search instead for 
Did you mean: 

Configuring ClassLink (SAML) and Canvas Authentication

Configuring ClassLink (SAML) and Canvas Authentication

    Official Canvas Document

Canvas + Logo transparent (WHITE)- 300px.png



Authentication Terminology

Term Definition

Identity Provider

The job of the IdP is to identify users based on credentials. The IdP typically provides the login screen interface and presents information about the authenticated user to service providers after successful authentication.

ClassLink is the Identity Provider.


Username in Canvas terminology.

When information about an authenticated user is returned to Canvas, a user with a login_id matching the incoming data is looked for.


Information about the SP or IdP.  This metadata is almost always provided in the form of XML.  The metadata about your Canvas instance is located at http://<yourcanvas> (replace <yourcanvas> with the first portion of your Canvas domain).


Security Assertion Markup Language

SIS Student Information System

Unique ID of a user in Canvas.

Used to link a user to an outside system, often a Student Information System (SIS).


Single Logout

When a user logs out of a service, some IdPs can subsequently log the user out of all other services the user has authenticated to. 


Service Provider

An SP is usually a website providing information, tools, reports, etc to the end user.  Canvas provides a learning environment to teachers, students, and admins and is, therefore, the Service Provider.

Note: An SP cannot authenticate against an IdP unless the IdP is known to the SP.  Likewise, an IdP will not send assertions to an SP that it does now know about.


Single Sign-On

This is what happens when a user isn't required to log in to a second service because information about the authenticated user is passed to the service.



  • Canvas does not automatically create user accounts from successful single-sign-ons. User accounts must either be created manually in the web interface or through the SIS import CSVs.
  • The login_id field in Canvas must match the selected field returned from ClassLink.
  • Your organization must have a ClassLink subscription.
  • You must be able to login to the admin console for your organization.

Login Release Valve

You may accidentally lock yourself out of Canvas while you are setting up authentication. If this happens, you can log in to Canvas using local authentication. Simply go to http://<yourcanvasname> (This forces Canvas to display the local login form rather than redirecting to the SAML login page).

Configure ClassLink SAML

Audience: ClassLink Administrator

Reference: Canvas SAML – ClassLink 


1. Launch the ClassLink IDP Console

After you log in to the IDP Console, click on COPY EXISTING from the top of the navigation menu. This will present a list of pre-configured SAML connections.


2. Copy the Canvas (RosterServer required) template from the library.


3. Enter Service Provider Entity ID

To do this, click Edit.

      Enter Canvas SP Entity ID: ex:

While editing the SAML app, locate the Login URL field then input your LaunchPad custom login URL.




Not sure what your custom login URL is? The login page URL is located in the ClassLink Management Console under Settings>Login Page. See below.



Once you've completed updating the SAML settings, scroll down to save.


4. Copy IDP Metadata

You will now see the Canvas SAML connector in your list of applications. Copy the IDP Metadata URL and enter this in Canvas (Configure Canvas Authentication).

Configure Canvas Authentication

The following steps take place in Canvas. 

1. In a new browser tab, log in to your Canvas instance as an administrator. From the Admin tile, click Authentication





2. Click on the Choose an Authentication drop-down, then select the SAML option


SAML Identity Provider



3. On the SAML configuration page, paste the Identity Provider metadata URL into the IdP Metadata URI field. Click Save




4.  The page will reload with the values for IdP Entity ID, Log On URL, Log Out URL and Certificate Fingerprint automatically filled


5. Test the configuration. Open a new incognito window, and go to



If successful, you’ll be prompted to enter your ClassLink credentials. You will then be logged in and redirected to your Canvas instance.



Note: Canvas does not automatically create user accounts from successful single-sign-ons. User accounts must either be created manually in the web interface or through the SIS import CSVs.


6. Return to the Authentication screen. To make SAML the primary method for authentication, navigate to the bottom of the SAML section, and change Position to 1. Click Save