canva-deploy-integration

v2026.09.24

Deploy a Canva Connect backend with exact redirect URIs, runtime-only secrets, protected migrations, and verified rollback. Use when promoting to staging or production. Trigger with: "deploy Canva integration", "configure Canva callback", "release Canva backend".

GitHub
Install command
npx skhub add jeremylongshore/canva-deploy-integration
Markdown
SKILL.md

Canva Deployment and Callback Gate

Overview

Promote one immutable application artifact while keeping OAuth configuration and credentials environment-specific. Validate callbacks and a non-mutating Canva read before enabling user traffic.

Prerequisites

  • Reviewed artifact digest and target environment
  • Exact registered redirect URI and controlled HTTPS domain
  • Secret backend, migration plan, health contract, and rollback version

Instructions

Step 1: Compare configuration

Use Read and Grep to diff redirect URI, scopes, preview features, callback/webhook routes, secret references, and data stores against the approved release.

Step 2: Stage runtime secrets

Inject environment-specific credentials from the approved backend. Never bake secrets or refresh tokens into images, frontend bundles, logs, or deployment output.

Step 3: Deploy traffic-disabled

Use Write or Edit for reviewed platform configuration, deploy the immutable artifact, run migrations with a rollback plan, and keep external traffic disabled.

Step 4: Verify callback safety

Confirm exact redirect matching, state validation, PKCE verifier handling, backend-only token exchange, cookie/session controls, and rejection of unexpected hosts.

Step 5: Run bounded readiness

Use a dedicated test user for a non-mutating identity/metadata read and verify redaction, dependency health, and version. Do not create content in a generic health endpoint.

Step 6: Promote or roll back

Enable traffic gradually under local SLOs. Restore the prior artifact/config and pause OAuth entry if authorization, data, or readiness evidence diverges.

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

The same artifact moves from staging to production while each environment retains separate Canva credentials and redirect URIs. Traffic is enabled only after callback and read-only test evidence passes.

Error Handling

FailureResponse
Redirect URI mismatchKeep traffic disabled and correct the registered/configured value
Secret appears in build outputContain and rotate it before redeployment
Migration is not reversibleStop promotion until recovery is proven
Readiness check mutates CanvaReplace it with a safe identity or metadata read

Resources

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/.curated/canva-deploy-integration

Default branch

main

Latest commit

e5a6c3b

Tree SHA

c2dc8e8