Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Choose and implement Canva Connect API architecture blueprints for different scales. Use when designing new Canva integrations, choosing between monolith/service/microservice architectures, or planning migration paths. Trigger with phrases like "canva architecture", "canva blueprint", "how to structure canva", "canva project layout", "canva microservice".
.claude/skills/jeremylongshore-canva-architecture-variants/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 35% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 28% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 52% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 17% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 50% | 0% |
Select the smallest topology that preserves backend OAuth, per-user token isolation, asynchronous job reconciliation, and policy-controlled data handling. Treat scale thresholds as measured local evidence, not Canva product limits.
Identify browser, backend, token store, job ledger, worker, data store, and Canva API boundaries. Mark every place customer content or credentials could cross.
Use a backend monolith for one bounded service, a service plus worker when asynchronous jobs must outlive requests, or isolated services only when ownership and failure domains justify them.
Serialize refresh per Canva user, atomically replace the single-use refresh token, and separate access-token and refresh-token storage.
Persist opaque job identity before dispatch, poll with bounded backoff, and reconcile terminal state before repeating a mutating operation.
Resolve tenant, resource, explicit scope, capability, preview status, and data policy before dispatch rather than inside a generic HTTP client.
Use Write or Edit to capture selected shape, rejected alternatives, assumptions, failure modes, rollback, and validation evidence.
Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.
Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.
A service exports designs asynchronously for multiple tenants. A backend owns OAuth and policy, a durable ledger owns job identity, and workers are partitioned by tenant without embedding user IDs in metrics.
| Failure | Response | | --- | --- | | Browser-only design proposed | Reject it because client secrets and token exchange require a backend | | Workers can double-submit | Add durable identity and reconciliation before scaling | | Topology chosen by guessed volume | Measure queue and failure behavior first | | Preview dependency blocks review | Separate or disable that feature for the public release |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-04 | pass→pass | 11,371 | 8,682 | -24% | 1 | 1 | 0% | 2,338 | 3,258 | +39% | 0 | 0 | — |
case-05 | pass→pass | 14,534 | 14,309 | -2% | 1 | 1 | 0% | 2,851 | 4,197 | +47% | 0 | 0 | — |
case-01 | fail→pass | 15,209 | 11,412 | -25% | 1 | 1 | 0% | 2,908 | 3,919 | +35% | 0 | 0 | — |
case-02 | fail→pass | 21,769 | 18,101 | -17% | 1 | 1 | 0% | 4,155 | 5,331 | +28% | 0 | 0 | — |
case-03 | fail→pass | 30,287 | 22,923 | -24% | 1 | 1 | 0% | 4,023 | 6,134 | +52% | 0 | 0 | — |
case-06 | pass→pass | 10,069 | 9,559 | -5% | 1 | 1 | 0% | 1,873 | 3,511 | +87% | 0 | 0 | — |
case-07 | fail→pass | 20,701 | 12,152 | -41% | 1 | 1 | 0% | 3,408 | 3,987 | +17% | 0 | 0 | — |
case-08 | fail→pass | 17,049 | 12,600 | -26% | 1 | 1 | 0% | 2,586 | 3,887 | +50% | 0 | 0 | — |
case-09 | fail→pass | 11,001 | 5,084 | -54% | 1 | 1 | 0% | 1,738 | 2,469 | +42% | 0 | 0 | — |
case-10 | fail→pass | 14,655 | 15,792 | +8% | 1 | 1 | 0% | 2,308 | 4,318 | +87% | 0 | 0 | — |
case-11 | pass→pass | 16,973 | 16,667 | -2% | 1 | 1 | 0% | 2,860 | 4,446 | +55% | 0 | 0 | — |
case-12 | pass→pass | 7,792 | 4,312 | -45% | 1 | 1 | 0% | 1,538 | 2,547 | +66% | 0 | 0 | — |
case-13 | pass→pass | 28,585 | 10,407 | -64% | 1 | 1 | 0% | 2,596 | 3,466 | +34% | 0 | 0 | — |
case-14 | fail→fail | 11,871 | 9,805 | -17% | 1 | 1 | 0% | 2,059 | 3,370 | +64% | 0 | 0 | — |
case-15 | pass→pass | 11,825 | 7,603 | -36% | 1 | 1 | 0% | 1,782 | 3,080 | +73% | 0 | 0 | — |
case-16 | pass→pass | 12,864 | 8,855 | -31% | 1 | 1 | 0% | 2,255 | 3,321 | +47% | 0 | 0 | — |
case-17 | pass→pass | 14,257 | 11,962 | -16% | 1 | 1 | 0% | 2,190 | 3,799 | +73% | 0 | 0 | — |
case-18 | pass→pass | 8,134 | 2,093 | -74% | 1 | 1 | 0% | 1,269 | 1,945 | +53% | 0 | 0 | — |
case-19 | pass→pass | 7,108 | 2,410 | -66% | 1 | 1 | 0% | 933 | 2,038 | +118% | 0 | 0 | — |
case-20 | pass→pass | 15,374 | 11,240 | -27% | 1 | 1 | 0% | 2,389 | 3,585 | +50% | 0 | 0 | — |
case-21 | pass→pass | 2,837 | 2,380 | -16% | 1 | 1 | 0% | 397 | 1,996 | +403% | 0 | 0 | — |
case-22 | fail→pass | 24,113 | 14,213 | -41% | 1 | 1 | 0% | 2,693 | 4,061 | +51% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +36 percentage points is the difference between those two pass rates over the 22 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.