Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Diagnose and fix Canva Connect API errors and HTTP status codes. Use when encountering Canva errors, debugging failed requests, or troubleshooting integration issues. Trigger with phrases like "canva error", "fix canva", "canva not working", "debug canva", "canva 401", "canva 429".
.claude/skills/jeremylongshore-canva-common-errors/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 32% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 67% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 160% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 231% | 0% |
| case-14 | ✗→✓ | ▲ Improved | 70% | 0% |
Treat HTTP status alone as insufficient. Use the current endpoint reference and redacted provider error code to separate caller defects, authorization failures, throttling, preview drift, and provider incidents.
Record method, endpoint pattern, status, provider code, terminal job state, retry metadata if actually present, and deployment version. Exclude tokens, bodies, signed URLs, and customer identifiers.
For an invalid or expired access token, serialize the authorized refresh flow and atomically store the replacement refresh token. Reauthorize after revocation or unrecoverable refresh failure.
Compare the operation with explicit granted scopes, resource ownership, capabilities, tenant policy, and preview availability. Never assume a write scope grants its read counterpart.
Pause only the affected endpoint/user queue. Use documented endpoint metadata and response instructions; otherwise apply bounded exponential backoff with jitter rather than a guessed fixed delay.
Poll the existing job to a documented terminal state. Correct validation or entitlement errors before any new submission.
Correlate repeated server errors with Canva status/changelog and provide a redacted support receipt after bounded retry is exhausted.
Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.
Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.
An autofill returns HTTP 403. The operator checks explicit scopes, current capability and Enterprise availability, template ownership, preview status, and the provider error before deciding whether reauthorization is relevant.
| Failure | Response | | --- | --- | | Only HTTP status is available | Collect the redacted provider envelope before acting | | Refresh repeats 401 | Stop and require reauthorization instead of looping | | 429 has no retry metadata | Use the local bounded backoff policy and lower concurrency | | Job failed validation | Correct the request; do not retry unchanged input |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-09 | pass→pass | 12,539 | 11,455 | -9% | 1 | 1 | 0% | 1,887 | 3,768 | +100% | 0 | 0 | — |
case-01 | fail→pass | 15,670 | 10,943 | -30% | 1 | 1 | 0% | 2,991 | 3,935 | +32% | 0 | 0 | — |
case-02 | fail→pass | 14,102 | 12,122 | -14% | 1 | 1 | 0% | 2,312 | 3,862 | +67% | 0 | 0 | — |
case-03 | pass→pass | 9,380 | 8,765 | -7% | 1 | 1 | 0% | 1,794 | 3,248 | +81% | 0 | 0 | — |
case-04 | pass→pass | 11,143 | 9,062 | -19% | 1 | 1 | 0% | 1,828 | 3,090 | +69% | 0 | 0 | — |
case-05 | pass→pass | 9,015 | 4,506 | -50% | 1 | 1 | 0% | 1,579 | 2,307 | +46% | 0 | 0 | — |
case-06 | pass→pass | 10,272 | 6,607 | -36% | 1 | 1 | 0% | 1,798 | 2,752 | +53% | 0 | 0 | — |
case-07 | fail→pass | 10,883 | 2,498 | -77% | 1 | 1 | 0% | 770 | 2,004 | +160% | 0 | 0 | — |
case-08 | pass→pass | 9,631 | 2,957 | -69% | 1 | 1 | 0% | 1,584 | 2,085 | +32% | 0 | 0 | — |
case-10 | pass→pass | 9,128 | 7,147 | -22% | 1 | 1 | 0% | 1,771 | 2,986 | +69% | 0 | 0 | — |
case-11 | pass→pass | 12,372 | 10,970 | -11% | 1 | 1 | 0% | 2,229 | 3,389 | +52% | 0 | 0 | — |
case-12 | pass→pass | 8,640 | 5,730 | -34% | 1 | 1 | 0% | 1,711 | 2,769 | +62% | 0 | 0 | — |
case-13 | fail→pass | 3,468 | 2,725 | -21% | 1 | 1 | 0% | 627 | 2,075 | +231% | 0 | 0 | — |
case-14 | fail→pass | 9,578 | 6,990 | -27% | 1 | 1 | 0% | 1,764 | 2,998 | +70% | 0 | 0 | — |
case-15 | pass→pass | 10,899 | 7,402 | -32% | 1 | 1 | 0% | 1,991 | 2,991 | +50% | 0 | 0 | — |
case-16 | fail→pass | 15,489 | 11,451 | -26% | 1 | 1 | 0% | 2,664 | 3,591 | +35% | 0 | 0 | — |
case-17 | fail→pass | 15,797 | 14,432 | -9% | 1 | 1 | 0% | 2,676 | 4,121 | +54% | 0 | 0 | — |
case-18 | fail→pass | 9,808 | 5,180 | -47% | 1 | 1 | 0% | 1,616 | 2,543 | +57% | 0 | 0 | — |
case-19 | fail→pass | 6,369 | 2,046 | -68% | 1 | 1 | 0% | 1,081 | 1,932 | +79% | 0 | 0 | — |
case-20 | fail→pass | 6,365 | 2,397 | -62% | 1 | 1 | 0% | 1,011 | 1,977 | +96% | 0 | 0 | — |
case-21 | fail→pass | 12,006 | 7,696 | -36% | 1 | 1 | 0% | 2,286 | 3,104 | +36% | 0 | 0 | — |
case-22 | pass→pass | 8,865 | 5,309 | -40% | 1 | 1 | 0% | 1,670 | 2,765 | +66% | 0 | 0 | — |
case-23 | pass→pass | 11,235 | 10,108 | -10% | 1 | 1 | 0% | 2,171 | 3,561 | +64% | 0 | 0 | — |
case-24 | pass→pass | 11,976 | 15,360 | +28% | 1 | 1 | 0% | 2,164 | 4,378 | +102% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 24 cases were attempted, and 23 counted toward the lift figure. The other 1 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +46 percentage points is the difference between those two pass rates over the 23 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.