canva-security-basics

v2026.09.24

Implement the Canva Connect security baseline for backend OAuth, least privilege, tenant isolation, logging, revocation, and preview webhook verification. Use when threat-modeling, reviewing, or hardening an integration. Trigger with: "secure Canva integration", "Canva token security", "verify Canva webhook".

GitHub
Install command
npx skhub add jeremylongshore/canva-security-basics
Markdown
SKILL.md

Canva Integration Security Baseline

Overview

Protect client secrets and user tokens as separate high-impact credentials. Enforce authorization before provider access and treat preview webhook verification as an additional boundary, not proof of business authorization.

Prerequisites

  • Integration ID, environments, operations, tenants, and threat scope
  • Current scopes, redirect URIs, token stores, and data flows
  • Webhook/preview use, incident response, secret scanning, and audit controls

Instructions

Step 1: Inventory secrets and flows

Use Read and Grep to locate client secrets, access/refresh tokens, PKCE verifier, OAuth state, callbacks, browser bundles, logs, backups, jobs, and external processors.

Step 2: Harden OAuth

Require controlled redirect hosts, one-time state/verifier, backend token exchange, encrypted and separated tokens, per-user refresh serialization, revocation, and disconnect cleanup.

Step 3: Minimize authorization

Request explicit minimum scopes and enforce tenant, resource, role, capability, purpose, and preview status server-side before every action.

Step 4: Harden data and logs

Use Write or Edit to prevent tokens, bodies, signed URLs, personal data, and resource identifiers from routine logs; protect stored content and deletion workflows.

Step 5: Verify webhooks

For authorized preview use, validate the signed token/claims against cached Canva JWKs, select by case-sensitive key ID, refetch only for unknown keys, enforce replay/idempotency controls, and authorize resulting actions separately.

Step 6: Harden dependencies and deployment

Pin provider/client inputs, scan secrets, isolate environments, protect CI from forks, deploy immutably, and maintain tested rollback and credential rotation.

Step 7: Prove controls

Test state mismatch, token leak prevention, cross-tenant denial, refresh races, scope denial, unknown webhook key, replay, revoked consent, and account deletion.

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

A valid Canva webhook signature is accepted only as authenticity evidence. The router still checks preview authorization, tenant/resource policy, idempotency, and allowed action before processing.

Error Handling

FailureResponse
Secret reaches public repositoryAssume compromise, rotate, and investigate
Cross-tenant access succeedsDisable the path and treat as a security incident
Webhook key is unknownRefetch the public JWK set once and fail closed if still unknown
Consent is revokedDelete tokens and deny queued work

Resources

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/.curated/canva-security-basics

Default branch

main

Latest commit

e5a6c3b

Tree SHA

c2dc8e8