Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Deploy Canva Connect API integrations to Vercel, Fly.io, and Cloud Run. Use when deploying Canva-powered applications to production, configuring platform-specific secrets, or setting up deployment pipelines. Trigger with phrases like "deploy canva", "canva Vercel", "canva production deploy", "canva Cloud Run", "canva Fly.io".
.claude/skills/jeremylongshore-canva-deploy-integration/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-05 | ✗→✓ | ▲ Improved | 24% | 0% |
| case-01 | ✗→✓ | ▲ Improved | 27% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 23% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 28% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 16% | 0% |
Promote one immutable application artifact while keeping OAuth configuration and credentials environment-specific. Validate callbacks and a non-mutating Canva read before enabling user traffic.
Use Read and Grep to diff redirect URI, scopes, preview features, callback/webhook routes, secret references, and data stores against the approved release.
Inject environment-specific credentials from the approved backend. Never bake secrets or refresh tokens into images, frontend bundles, logs, or deployment output.
Use Write or Edit for reviewed platform configuration, deploy the immutable artifact, run migrations with a rollback plan, and keep external traffic disabled.
Confirm exact redirect matching, state validation, PKCE verifier handling, backend-only token exchange, cookie/session controls, and rejection of unexpected hosts.
Use a dedicated test user for a non-mutating identity/metadata read and verify redaction, dependency health, and version. Do not create content in a generic health endpoint.
Enable traffic gradually under local SLOs. Restore the prior artifact/config and pause OAuth entry if authorization, data, or readiness evidence diverges.
Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.
Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.
The same artifact moves from staging to production while each environment retains separate Canva credentials and redirect URIs. Traffic is enabled only after callback and read-only test evidence passes.
| Failure | Response | | --- | --- | | Redirect URI mismatch | Keep traffic disabled and correct the registered/configured value | | Secret appears in build output | Contain and rotate it before redeployment | | Migration is not reversible | Stop promotion until recovery is proven | | Readiness check mutates Canva | Replace it with a safe identity or metadata read |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-05 | fail→pass | 8,794 | 3,261 | -63% | 1 | 1 | 0% | 1,593 | 1,975 | +24% | 0 | 0 | — |
case-01 | fail→pass | 15,067 | 12,543 | -17% | 1 | 1 | 0% | 3,191 | 4,044 | +27% | 0 | 0 | — |
case-02 | fail→pass | 12,686 | 6,945 | -45% | 1 | 1 | 0% | 2,250 | 2,759 | +23% | 0 | 0 | — |
case-03 | fail→pass | 14,403 | 10,726 | -26% | 1 | 1 | 0% | 3,026 | 3,861 | +28% | 0 | 0 | — |
case-04 | pass→pass | 5,831 | 5,404 | -7% | 1 | 1 | 0% | 1,183 | 2,297 | +94% | 0 | 0 | — |
case-06 | fail→pass | 16,260 | 14,404 | -11% | 1 | 1 | 0% | 3,659 | 4,249 | +16% | 0 | 0 | — |
case-07 | fail→pass | 15,761 | 10,860 | -31% | 1 | 1 | 0% | 3,141 | 3,414 | +9% | 0 | 0 | — |
case-08 | pass→pass | 7,772 | 3,011 | -61% | 1 | 1 | 0% | 1,278 | 1,933 | +51% | 0 | 0 | — |
case-09 | pass→pass | 7,545 | 3,423 | -55% | 1 | 1 | 0% | 1,273 | 1,874 | +47% | 0 | 0 | — |
case-10 | fail→pass | 10,944 | 4,414 | -60% | 1 | 1 | 0% | 1,657 | 2,181 | +32% | 0 | 0 | — |
case-11 | fail→pass | 6,058 | 2,357 | -61% | 1 | 1 | 0% | 1,061 | 1,690 | +59% | 0 | 0 | — |
case-12 | pass→pass | 12,456 | 3,999 | -68% | 1 | 1 | 0% | 2,195 | 2,217 | +1% | 0 | 0 | — |
case-13 | pass→pass | 12,829 | 9,845 | -23% | 1 | 1 | 0% | 1,977 | 3,156 | +60% | 0 | 0 | — |
case-14 | pass→pass | 13,667 | 7,294 | -47% | 1 | 1 | 0% | 2,300 | 2,654 | +15% | 0 | 0 | — |
case-15 | pass→pass | 10,903 | 9,458 | -13% | 1 | 1 | 0% | 2,024 | 3,263 | +61% | 0 | 0 | — |
case-16 | pass→pass | 7,500 | 2,891 | -61% | 1 | 1 | 0% | 1,345 | 1,879 | +40% | 0 | 0 | — |
case-17 | pass→pass | 4,366 | 3,536 | -19% | 1 | 1 | 0% | 689 | 2,057 | +199% | 0 | 0 | — |
case-18 | fail→pass | 8,835 | 3,020 | -66% | 1 | 1 | 0% | 1,553 | 1,789 | +15% | 0 | 0 | — |
case-19 | pass→pass | 24,321 | 9,590 | -61% | 1 | 1 | 0% | 2,347 | 3,036 | +29% | 0 | 0 | — |
case-20 | pass→pass | 3,179 | 3,139 | -1% | 1 | 1 | 0% | 436 | 1,940 | +345% | 0 | 0 | — |
case-21 | pass→pass | 14,571 | 14,488 | -1% | 1 | 1 | 0% | 2,900 | 4,141 | +43% | 0 | 0 | — |
case-22 | pass→pass | 17,063 | 15,985 | -6% | 1 | 1 | 0% | 3,501 | 4,674 | +34% | 0 | 0 | — |
case-23 | pass→pass | 20,450 | 12,414 | -39% | 1 | 1 | 0% | 2,578 | 3,790 | +47% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +39 percentage points is the difference between those two pass rates over the 23 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.