canva-multi-env-setup

v2026.09.24

Configure isolated development, staging, and production Canva integrations. Use when separating redirect URIs, credentials, users, token stores, scopes, data, and audit evidence across environments. Trigger with: "Canva environments", "Canva staging setup", "separate Canva credentials".

GitHub
安装命令
npx skhub add jeremylongshore/canva-multi-env-setup
Markdown
SKILL.md

Canva Environment Isolation

Overview

Give each environment an independent Canva integration and trust boundary. Prevent a staging build, callback, credential, user, or token record from resolving to production.

Prerequisites

  • Named environments, owners, domains, and deployment identities
  • Separate Developer Portal integrations and redirect URIs
  • Secret backend, token namespace, test-user, data, and audit policy per environment

Instructions

Step 1: Build the matrix

Use Read and Grep to map environment to integration ID, exact redirect hosts, scopes, preview features, secret references, token/data namespace, and owners.

Step 2: Separate integrations

Create or verify distinct Canva integrations where isolation is required. Never distinguish environments only with a runtime variable while sharing credentials.

Step 3: Constrain configuration

Use Write or Edit to validate environment identity, controlled host allowlists, exact callback routes, expected integration ID, and forbidden cross-environment values at startup.

Step 4: Isolate secrets and tokens

Use separate secret paths, encryption keys where policy requires, access policies, token tables or namespaces, backup rules, and rotation owners.

Step 5: Isolate users and data

Use synthetic development/staging users and assets. Prevent non-production workers, webhooks, or support tooling from reading production records.

Step 6: Test negative boundaries

Prove staging cannot use production client secrets, callbacks, tokens, queues, databases, or webhook routes; fail closed on mismatch.

Step 7: Record promotion rules

Document which artifact is shared, which configuration must differ, rollback, environment cleanup, and evidence needed before production.

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

The same reviewed artifact runs in staging and production, but startup validation requires different integration IDs, callback hosts, vault paths, token namespaces, and test policies.

Error Handling

FailureResponse
Two environments share a secretStop deployment and separate/rotate credentials
Callback host is unexpectedReject the request before token exchange
Production token appears in stagingContain, revoke, and audit the cross-boundary path
Environment matrix is staleBlock promotion until owners reconfirm it

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/canva-multi-env-setup

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8