canva-deploy-integration

v2026.09.24

Deploy a Canva Connect backend with exact redirect URIs, runtime-only secrets, protected migrations, and verified rollback. Use when promoting to staging or production. Trigger with: "deploy Canva integration", "configure Canva callback", "release Canva backend".

GitHub
安装命令
npx skhub add jeremylongshore/canva-deploy-integration
Markdown
SKILL.md

Canva Deployment and Callback Gate

Overview

Promote one immutable application artifact while keeping OAuth configuration and credentials environment-specific. Validate callbacks and a non-mutating Canva read before enabling user traffic.

Prerequisites

  • Reviewed artifact digest and target environment
  • Exact registered redirect URI and controlled HTTPS domain
  • Secret backend, migration plan, health contract, and rollback version

Instructions

Step 1: Compare configuration

Use Read and Grep to diff redirect URI, scopes, preview features, callback/webhook routes, secret references, and data stores against the approved release.

Step 2: Stage runtime secrets

Inject environment-specific credentials from the approved backend. Never bake secrets or refresh tokens into images, frontend bundles, logs, or deployment output.

Step 3: Deploy traffic-disabled

Use Write or Edit for reviewed platform configuration, deploy the immutable artifact, run migrations with a rollback plan, and keep external traffic disabled.

Step 4: Verify callback safety

Confirm exact redirect matching, state validation, PKCE verifier handling, backend-only token exchange, cookie/session controls, and rejection of unexpected hosts.

Step 5: Run bounded readiness

Use a dedicated test user for a non-mutating identity/metadata read and verify redaction, dependency health, and version. Do not create content in a generic health endpoint.

Step 6: Promote or roll back

Enable traffic gradually under local SLOs. Restore the prior artifact/config and pause OAuth entry if authorization, data, or readiness evidence diverges.

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

The same artifact moves from staging to production while each environment retains separate Canva credentials and redirect URIs. Traffic is enabled only after callback and read-only test evidence passes.

Error Handling

FailureResponse
Redirect URI mismatchKeep traffic disabled and correct the registered/configured value
Secret appears in build outputContain and rotate it before redeployment
Migration is not reversibleStop promotion until recovery is proven
Readiness check mutates CanvaReplace it with a safe identity or metadata read

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/canva-deploy-integration

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8