Agent skill

Canva Deploy Integration

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Deploy a Canva Connect backend with exact redirect URIs, runtime-only secrets, protected migrations, and verified rollback.

MITAuto-check passedDevOps & Cloud

Install Canva Deploy Integration

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-deploy-integration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace canva-deploy-integration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/canva-deploy-integration .claude/skills/canva-deploy-integration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
canva-deploy-integration
GitHub stars
2.8k
Token cost
~979 tokens
SKILL.md length
399 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Deploy a Canva Connect backend with exact redirect URIs, runtime-only secrets, protected migrations, and verified rollback.

  • Works in 6 steps: Compare configuration → Stage runtime secrets → Deploy traffic-disabled → …
  • Promoting to staging
  • SKILL.md covers Overview, Prerequisites, Instructions and Authentication, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Canva Deploy Integration is an agent skill from jeremylongshore/tons-of-skills-marketplace. Deploy a Canva Connect backend with exact redirect URIs, runtime-only secrets, protected migrations, and verified rollback. Use when promoting to staging or production. Trigger with: "deploy Canva integration", "configure Canva callback", "release Canva backend".

Its SKILL.md is about 980 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Requires control of the HTTPS callback domain, approved environment credentials, and a tested rollback artifact.

It sits in DevOps & Cloud, covering Deployment. It works with Canva. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Promoting to staging
  • With: deploy Canva integration
  • Configure Canva callback
  • Release Canva backend

Example prompts

  • “deploy Canva integration”
  • “configure Canva callback”
  • “release Canva backend”
  • “/canva-deploy-integration”

Requirements

  • Compatibility (from SKILL.md): Requires control of the HTTPS callback domain, approved environment credentials, and a tested rollback artifact.
  • Pre-approved tools (allowed-tools): Read, Grep, Write, Edit

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Compare configuration
  2. Stage runtime secrets
  3. Deploy traffic-disabled
  4. Verify callback safety
  5. Run bounded readiness
  6. Promote or roll back

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • canva.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires control of the HTTPS callback domain, approved environment credentials, and a tested rollback artifact.

    From compatibility in the SKILL.md frontmatter.

Context cost

Canva Deploy Integration loads about 979 tokens when it runs, and up to ~1.1k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 399 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~979
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 399 words, ~979 tokens.

Download SKILL.mdSave it as .claude/skills/canva-deploy-integration/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
canva-deploy-integration
description
Deploy a Canva Connect backend with exact redirect URIs, runtime-only secrets, protected migrations, and verified rollback. Use when promoting to staging or production. Trigger with: "deploy Canva integration", "configure Canva callback", "release Canva backend".
allowed-tools
Read, Grep, Write, Edit
compatibility
Requires control of the HTTPS callback domain, approved environment credentials, and a tested rollback artifact.
version
2.0.0
argument-hint
[target-environment-and-release-id]
model
inherit
effort
high
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, canva, deployment, operations

Canva Deployment and Callback Gate

Overview

Promote one immutable application artifact while keeping OAuth configuration and credentials environment-specific. Validate callbacks and a non-mutating Canva read before enabling user traffic.

Prerequisites

  • Reviewed artifact digest and target environment
  • Exact registered redirect URI and controlled HTTPS domain
  • Secret backend, migration plan, health contract, and rollback version

Instructions

Step 1: Compare configuration

Use Read and Grep to diff redirect URI, scopes, preview features, callback/webhook routes, secret references, and data stores against the approved release.

Step 2: Stage runtime secrets

Inject environment-specific credentials from the approved backend. Never bake secrets or refresh tokens into images, frontend bundles, logs, or deployment output.

Step 3: Deploy traffic-disabled

Use Write or Edit for reviewed platform configuration, deploy the immutable artifact, run migrations with a rollback plan, and keep external traffic disabled.

Step 4: Verify callback safety

Confirm exact redirect matching, state validation, PKCE verifier handling, backend-only token exchange, cookie/session controls, and rejection of unexpected hosts.

Step 5: Run bounded readiness

Use a dedicated test user for a non-mutating identity/metadata read and verify redaction, dependency health, and version. Do not create content in a generic health endpoint.

Step 6: Promote or roll back

Enable traffic gradually under local SLOs. Restore the prior artifact/config and pause OAuth entry if authorization, data, or readiness evidence diverges.

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Show full SKILL.md (139 more words)Show less

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

The same artifact moves from staging to production while each environment retains separate Canva credentials and redirect URIs. Traffic is enabled only after callback and read-only test evidence passes.

Error Handling

FailureResponse
Redirect URI mismatchKeep traffic disabled and correct the registered/configured value
Secret appears in build outputContain and rotate it before redeployment
Migration is not reversibleStop promotion until recovery is proven
Readiness check mutates CanvaReplace it with a safe identity or metadata read

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/canva-deploy-integration of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Canva Deploy Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Canva Deploy Integration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Canva Deploy Integration this skilljeremylongshore/tons-of-skills-marketplace2.8k—~979Automated safety check: PassMIT
Os Usagegoinfinite/os361—~4.8kAutomated safety check: NotesGPL-2.0
Protocol Deploymentsablier-labs/evm-monorepo353—~3.8kAutomated safety check: NotesCustom licence
Release Allpaperboytm/spool592—~1.1kAutomated safety check: PassCustom licence
AI ServerOpentrons/opentrons523—~2.5kAutomated safety check: NotesApache-2.0
Monstermq Broker Configvogler75/monster-mq143—~2.2kAutomated safety check: PassGPL-3.0

Similar skills

  • Os Usage

    goinfinite/os

    A skill your agent uses when deploying or managing applications on an Infinite OS instance — maps the dashboard, CLI, and REST API, and gives the core deployment workflows.

    361 GitHub stars~4.8k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Protocol Deployment

    sablier-labs/evm-monorepo

    Deploy Sablier protocols to a new EVM chain. An agent skill from sablier-labs/evm-monorepo.

    353 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Release All

    paperboytm/spool

    Publish the complete Spool CLI release train: synchronized versions, npm packages, the GitHub release, and the matching production web deployment.

    592 GitHub stars~1.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • AI Server

    Opentrons/opentrons

    Conventions for the opentrons-ai-server FastAPI service — project structure, uv dependency management, settings, testing, Docker, and deployment.

    523 GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Monstermq Broker Config

    vogler75/monster-mq

    Guide for configuring, deploying, and operating the MonsterMQ broker.

    143 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Deploy

    clacky-ai/openclacky

    Deploy Rails applications to Railway. An agent skill from clacky-ai/openclacky.

    1.2k GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Canva Deploy Integration

What does Canva Deploy Integration do?

Deploy a Canva Connect backend with exact redirect URIs, runtime-only secrets, protected migrations, and verified rollback. Canva Deploy Integration is an agent skill from jeremylongshore/tons-of-skills-marketplace. Deploy a Canva Connect backend with exact redirect URIs, runtime-only secrets, protected migrations, and verified rollback.

When should I use Canva Deploy Integration?

Canva Deploy Integration fits situations like: promoting to staging; with: deploy Canva integration; configure Canva callback; release Canva backend.

How do I install Canva Deploy Integration in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-deploy-integration -a claude-code`. Or copy the skill folder (skills/.curated/canva-deploy-integration in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/canva-deploy-integration in your project. Claude Code loads it when a task matches its description.

How do I install Canva Deploy Integration in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-deploy-integration -a codex`. Or copy the skill folder (skills/.curated/canva-deploy-integration in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/canva-deploy-integration in your project. Codex loads it when a task matches its description.

Can I use Canva Deploy Integration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-deploy-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/canva-deploy-integration, .gemini/skills/canva-deploy-integration, .github/skills/canva-deploy-integration and .opencode/skills/canva-deploy-integration in your project.

What does Canva Deploy Integration need to run?

SKILL.md names no scripts, command-line tools or credentials: Canva Deploy Integration is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Write, Edit. Compatibility (from SKILL.md): Requires control of the HTTPS callback domain, approved environment credentials, and a tested rollback artifact..

Does Canva Deploy Integration access the network?

SKILL.md names 1 domain. As links in the text: canva.dev. This is read from the text; nothing was executed.

Is Canva Deploy Integration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Canva Deploy Integration use?

Canva Deploy Integration is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Canva Deploy Integration use?

About 979 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 131 tokens, read only when the agent opens those files.

What are the alternatives to Canva Deploy Integration?

Skills that share tags, products or a category with Canva Deploy Integration: Os Usage (goinfinite/os, 361 stars), Protocol Deployment (sablier-labs/evm-monorepo, 353 stars), Release All (paperboytm/spool, 592 stars) and AI Server (Opentrons/opentrons, 523 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Canva Deploy Integration?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.