Agent skill

Canva Reference Architecture

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Implement a Canva Connect backend reference architecture with policy, OAuth, job reconciliation, and privacy-safe operations.

MITAuto-check passedBackend & APIs

Install Canva Reference Architecture

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-reference-architecture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace canva-reference-architecture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/canva-reference-architecture .claude/skills/canva-reference-architecture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
canva-reference-architecture
GitHub stars
2.8k
Token cost
~1k tokens
SKILL.md length
408 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Implement a Canva Connect backend reference architecture with policy, OAuth, job reconciliation, and privacy-safe operations.

  • Works in 7 steps: Draw trust boundaries → Own authorization centrally → Own tokens separately → …
  • Establishing service boundaries
  • SKILL.md covers Overview, Prerequisites, Instructions and Authentication, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Canva Reference Architecture is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement a Canva Connect backend reference architecture with policy, OAuth, job reconciliation, and privacy-safe operations. Use when establishing service boundaries, ownership, storage, and recovery for production. Trigger with: "Canva reference architecture", "design Canva backend", "Canva service layout".

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Requires a backend web application, durable token/job storage, approved data policy, and service ownership.

It sits in Backend & APIs, covering Accounting and bookkeeping, OAuth and OpenID Connect and Microservices. It works with Canva. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Establishing service boundaries
  • Recovery for production
  • With: Canva reference architecture
  • Design Canva backend

Example prompts

  • “Canva reference architecture”
  • “design Canva backend”
  • “Canva service layout”
  • “/canva-reference-architecture”

Requirements

  • Compatibility (from SKILL.md): Requires a backend web application, durable token/job storage, approved data policy, and service ownership.
  • Pre-approved tools (allowed-tools): Read, Grep, Write, Edit

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Draw trust boundaries
  2. Own authorization centrally
  3. Own tokens separately
  4. Own mutation identity
  5. Own data lifecycle
  6. Own failure recovery
  7. Record the blueprint

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • canva.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires a backend web application, durable token/job storage, approved data policy, and service ownership.

    From compatibility in the SKILL.md frontmatter.

Context cost

Canva Reference Architecture loads about 1k tokens when it runs, and up to ~1.2k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 408 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 408 words, ~1,040 tokens.

Download SKILL.mdSave it as .claude/skills/canva-reference-architecture/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
canva-reference-architecture
description
Implement a Canva Connect backend reference architecture with policy, OAuth, job reconciliation, and privacy-safe operations. Use when establishing service boundaries, ownership, storage, and recovery for production. Trigger with: "Canva reference architecture", "design Canva backend", "Canva service layout".
allowed-tools
Read, Grep, Write, Edit
compatibility
Requires a backend web application, durable token/job storage, approved data policy, and service ownership.
version
2.0.0
argument-hint
[requirements-and-data-classification]
model
inherit
effort
high
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, canva, architecture, operations

Canva Production Reference Architecture

Overview

Separate browser experience, backend OAuth/policy, provider adapter, durable operation ledger, workers, and controlled data stores. The architecture must prevent cross-tenant access and duplicate mutation by construction.

Prerequisites

  • Operations, tenants, traffic, data classes, and recovery objectives
  • Scopes, capabilities, preview dependencies, and public-review posture
  • Secret/token store, operation ledger, queue, observability, and rollback platform

Instructions

Step 1: Draw trust boundaries

Map browser, callback, backend, policy service, token vault, Canva adapter, job ledger, worker queue, data store, telemetry, and provider edges.

Step 2: Own authorization centrally

Resolve authenticated tenant, application role, resource ownership, explicit scope, capability, feature status, and data purpose before the adapter.

Step 3: Own tokens separately

Keep client secret and tokens backend-only, encrypt access and refresh tokens separately, serialize per-user refresh, and atomically replace single-use refresh tokens.

Step 4: Own mutation identity

Create a durable operation record before provider dispatch, attach returned resource/job identity, and reconcile terminal state across retries and restarts.

Step 5: Own data lifecycle

Store minimum approved metadata/content, authorize every read, expire temporary references, implement consent/account deletion, and keep protected values out of telemetry.

Step 6: Own failure recovery

Use endpoint-scoped admission, bounded retries, dead letters with reconciliation state, feature flags, immutable deploys, and exercised rollback.

Step 7: Record the blueprint

Use Write or Edit to document responsibilities, interfaces, schemas, threat decisions, SLOs, failure modes, and verification evidence.

Show full SKILL.md (183 more words)Show less

Authentication

Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Examples

The browser never receives a client secret or refresh token. The backend policy service authorizes an export, the ledger preserves identity, a worker polls the same job, and the application mediates result delivery.

Error Handling

FailureResponse
Business roles leak into generic clientMove authorization before the adapter
Refresh can run concurrentlyAdd a per-user lock and atomic replacement
Queue lacks operation identityStop writes until the ledger exists
Telemetry contains resource identifiersRedesign dimensions and redact

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/canva-reference-architecture of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Canva Reference Architecture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Canva Reference Architecture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Canva Reference Architecture this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMIT
XeroCraftOS-dev/CraftBot392—~2kAutomated safety check: PassMIT
QuickBooks Online Integrationhewi333/Mom-n-Pop-Skills122—~1.9kAutomated safety check: PassMIT
Java ArchitectJeffallan/claude-skills12k—~1.5kAutomated safety check: PassMIT
API GatewayCraftOS-dev/CraftBot3923 repos~7.1kAutomated safety check: PassMIT
Microsoft TeamsCraftOS-dev/CraftBot3921 repos~4.4kAutomated safety check: PassMIT

Similar skills

  • Xero

    CraftOS-dev/CraftBot

    Xero API integration with managed OAuth. An agent skill from CraftOS-dev/CraftBot.

    392 GitHub stars~2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • QuickBooks Online Integration

    hewi333/Mom-n-Pop-Skills

    Connects a small business to QuickBooks Online for customers, estimates, invoices and payments, using Intuit OAuth 2.0 with token refresh and sandbox or production setups.

    122 GitHub stars~1.9k tokensUpdated 29 days ago
    Backend & APIsAuto-check passed
  • Java Architect

    Jeffallan/claude-skills

    Builds Spring Boot 3.x services on Java 21 with domain-driven design, WebFlux, JPA tuning and Spring Security using OAuth2 and JWT, verified by Maven or Gradle builds.

    12k GitHub stars~1.5k tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • API Gateway

    CraftOS-dev/CraftBot

    Connect to 100+ APIs (Google Workspace, Microsoft 365, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth.

    392 GitHub starsUsed in 3 repos~7.1k tokens
    Backend & APIsAuto-check passed
  • Microsoft Teams

    CraftOS-dev/CraftBot

    Microsoft Teams API integration with managed OAuth. An agent skill from CraftOS-dev/CraftBot.

    392 GitHub starsUsed in 1 repo~4.4k tokens
    Backend & APIsAuto-check passed
  • Stripe

    CraftOS-dev/CraftBot

    Stripe API integration with managed OAuth. An agent skill from CraftOS-dev/CraftBot.

    392 GitHub starsUsed in 1 repo~4.1k tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Canva Reference Architecture

What does Canva Reference Architecture do?

Implement a Canva Connect backend reference architecture with policy, OAuth, job reconciliation, and privacy-safe operations. Canva Reference Architecture is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement a Canva Connect backend reference architecture with policy, OAuth, job reconciliation, and privacy-safe operations.

When should I use Canva Reference Architecture?

Canva Reference Architecture fits situations like: establishing service boundaries; recovery for production; with: Canva reference architecture; design Canva backend.

How do I install Canva Reference Architecture in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-reference-architecture -a claude-code`. Or copy the skill folder (skills/.curated/canva-reference-architecture in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/canva-reference-architecture in your project. Claude Code loads it when a task matches its description.

How do I install Canva Reference Architecture in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-reference-architecture -a codex`. Or copy the skill folder (skills/.curated/canva-reference-architecture in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/canva-reference-architecture in your project. Codex loads it when a task matches its description.

Can I use Canva Reference Architecture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill canva-reference-architecture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/canva-reference-architecture, .gemini/skills/canva-reference-architecture, .github/skills/canva-reference-architecture and .opencode/skills/canva-reference-architecture in your project.

What does Canva Reference Architecture need to run?

SKILL.md names no scripts, command-line tools or credentials: Canva Reference Architecture is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Write, Edit. Compatibility (from SKILL.md): Requires a backend web application, durable token/job storage, approved data policy, and service ownership..

Does Canva Reference Architecture access the network?

SKILL.md names 1 domain. As links in the text: canva.dev. This is read from the text; nothing was executed.

Is Canva Reference Architecture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Canva Reference Architecture use?

Canva Reference Architecture is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Canva Reference Architecture use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 132 tokens, read only when the agent opens those files.

What are the alternatives to Canva Reference Architecture?

Skills that share tags, products or a category with Canva Reference Architecture: Xero (CraftOS-dev/CraftBot, 392 stars), QuickBooks Online Integration (hewi333/Mom-n-Pop-Skills, 122 stars), Java Architect (Jeffallan/claude-skills, 12k stars) and API Gateway (CraftOS-dev/CraftBot, 392 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Canva Reference Architecture?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.