Verify a Canva Connect integration with a minimal read-only identity request and a redacted receipt.

MITAuto-check passedBackend & APIs

Install Canva Hello World

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-hello-world -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace canva-hello-world --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/canva-hello-world .claude/skills/canva-hello-world && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
canva-hello-world
GitHub stars
2.8k
Token cost
~913 tokens
SKILL.md length
391 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Verify a Canva Connect integration with a minimal read-only identity request and a redacted receipt.

  • Works in 6 steps: Confirm backend boundary → Select the read → Send one request → …
  • Endpoint reachability
  • SKILL.md covers Overview, Prerequisites, Instructions and Authentication, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Canva Hello World is an agent skill from jeremylongshore/tons-of-skills-marketplace. Verify a Canva Connect integration with a minimal read-only identity request and a redacted receipt. Use when proving OAuth, endpoint reachability, and response shape before any design or asset mutation. Trigger with: "test Canva connection", "Canva hello world", "verify Canva auth".

Its SKILL.md is about 910 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Requires a backend-held access token for a dedicated authorized test user.

It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with Canva. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Endpoint reachability
  • Response shape before any design
  • With: test Canva connection
  • Canva hello world

Example prompts

  • “test Canva connection”
  • “Canva hello world”
  • “verify Canva auth”
  • “/canva-hello-world”

Requirements

  • Compatibility (from SKILL.md): Requires a backend-held access token for a dedicated authorized test user.
  • Pre-approved tools (allowed-tools): Read, Grep, Write, Edit

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Confirm backend boundary
  2. Select the read
  3. Send one request
  4. Validate shape
  5. Classify failure
  6. Record success

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • canva.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires a backend-held access token for a dedicated authorized test user.

    From compatibility in the SKILL.md frontmatter.

Context cost

Canva Hello World loads about 913 tokens when it runs, and up to ~1k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 391 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~913
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 391 words, ~913 tokens.

Download SKILL.mdSave it as .claude/skills/canva-hello-world/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
canva-hello-world
description
Verify a Canva Connect integration with a minimal read-only identity request and a redacted receipt. Use when proving OAuth, endpoint reachability, and response shape before any design or asset mutation. Trigger with: "test Canva connection", "Canva hello world", "verify Canva auth".
allowed-tools
Read, Grep, Write, Edit
compatibility
Requires a backend-held access token for a dedicated authorized test user.
version
2.0.0
argument-hint
[approved-test-user]
model
inherit
effort
high
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, canva, quickstart, operations

Canva Read-Only Connection Proof

Overview

Prove the smallest safe path first. A successful identity or profile read confirms connectivity and authorization shape but does not authorize design creation, export, assets, or other scopes.

Prerequisites

  • Configured Canva integration and exact redirect URI
  • Approved test user with the minimum identity/profile scope
  • Backend secret storage and redacted evidence destination

Instructions

Step 1: Confirm backend boundary

Use Read and Grep to verify token exchange and storage stay server-side, the target base URL is exact, and no credential appears in client code.

Step 2: Select the read

Choose the minimum users/me or profile request supported by the granted explicit scope. Do not add design-write scopes for this proof.

Step 3: Send one request

Use the existing reviewed HTTP adapter and a bounded timeout. Do not print the Authorization header, response body, email, profile, or token metadata.

Step 4: Validate shape

Check status, content type, required response envelope, and only the minimum opaque identity field needed for correlation.

Step 5: Classify failure

Separate transport, invalid token, missing explicit scope, revoked consent, malformed response, and provider error using the redacted envelope.

Step 6: Record success

Use Write or Edit to save integration/config version, endpoint pattern, status category, schema result, latency bucket, and redaction check.

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Show full SKILL.md (139 more words)Show less

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

A new staging integration performs one users/me request for its dedicated test user and records only HTTP success, schema version, and an opaque internal connection reference.

Error Handling

FailureResponse
Token is client-visibleStop and move the flow to a backend
Read returns forbiddenCompare the exact scope and consent; do not add broad scopes blindly
Response contains unexpected fieldsReject or ignore according to the pinned schema
Proof requires a writeRedesign it around a supported non-mutating request

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/canva-hello-world of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Canva Hello World next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Canva Hello World compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Canva Hello World this skilljeremylongshore/tons-of-skills-marketplace2.8k—~913Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
OmniRoute Provider Managementdiegosouzapw/OmniRoute75k—~2.4kAutomated safety check: PassMIT
Antipattern Preventiondoorkeeper-gem/doorkeeper5.5k—~1.1kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Notion Worker Third-Party Auth Guidemakenotion/workers-template4391 repos~3.5kAutomated safety check: NotesMIT

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    75k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Notion Worker Third-Party Auth Guide

    makenotion/workers-template

    Official

    Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.

    439 GitHub starsUsed in 1 repo~3.5k tokens
    Backend & APIsAuto-check: notes
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    173 GitHub starsUsed in 2 repos~925 tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Canva Hello World

What does Canva Hello World do?

Verify a Canva Connect integration with a minimal read-only identity request and a redacted receipt. Canva Hello World is an agent skill from jeremylongshore/tons-of-skills-marketplace. Verify a Canva Connect integration with a minimal read-only identity request and a redacted receipt.

When should I use Canva Hello World?

Canva Hello World fits situations like: endpoint reachability; response shape before any design; with: test Canva connection; canva hello world.

How do I install Canva Hello World in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-hello-world -a claude-code`. Or copy the skill folder (skills/.curated/canva-hello-world in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/canva-hello-world in your project. Claude Code loads it when a task matches its description.

How do I install Canva Hello World in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-hello-world -a codex`. Or copy the skill folder (skills/.curated/canva-hello-world in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/canva-hello-world in your project. Codex loads it when a task matches its description.

Can I use Canva Hello World in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-hello-world -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/canva-hello-world, .gemini/skills/canva-hello-world, .github/skills/canva-hello-world and .opencode/skills/canva-hello-world in your project.

What does Canva Hello World need to run?

SKILL.md names no scripts, command-line tools or credentials: Canva Hello World is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Write, Edit. Compatibility (from SKILL.md): Requires a backend-held access token for a dedicated authorized test user..

Does Canva Hello World access the network?

SKILL.md names 1 domain. As links in the text: canva.dev. This is read from the text; nothing was executed.

Is Canva Hello World safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Canva Hello World use?

Canva Hello World is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Canva Hello World use?

About 913 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 117 tokens, read only when the agent opens those files.

What are the alternatives to Canva Hello World?

Skills that share tags, products or a category with Canva Hello World: Fortify Development (coollabsio/coolify, 63k stars), OmniRoute Provider Management (diegosouzapw/OmniRoute, 75k stars), Antipattern Prevention (doorkeeper-gem/doorkeeper, 5.5k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Canva Hello World?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.