Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Configure Canva Connect API across development, staging, and production environments. Use when setting up multi-environment deployments, managing OAuth credentials per environment, or implementing environment-specific Canva configurations. Trigger with phrases like "canva environments", "canva staging", "canva dev prod", "canva environment setup", "canva config by env".
.claude/skills/jeremylongshore-canva-multi-env-setup/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-19 | ✗→✓ | ▲ Improved | 25% | 0% |
| case-01 | ✗→✓ | ▲ Improved | 7% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 97% | 0% |
| case-05 | ✗→✓ | ▲ Improved | 58% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 25% | 0% |
Give each environment an independent Canva integration and trust boundary. Prevent a staging build, callback, credential, user, or token record from resolving to production.
Use Read and Grep to map environment to integration ID, exact redirect hosts, scopes, preview features, secret references, token/data namespace, and owners.
Create or verify distinct Canva integrations where isolation is required. Never distinguish environments only with a runtime variable while sharing credentials.
Use Write or Edit to validate environment identity, controlled host allowlists, exact callback routes, expected integration ID, and forbidden cross-environment values at startup.
Use separate secret paths, encryption keys where policy requires, access policies, token tables or namespaces, backup rules, and rotation owners.
Use synthetic development/staging users and assets. Prevent non-production workers, webhooks, or support tooling from reading production records.
Prove staging cannot use production client secrets, callbacks, tokens, queues, databases, or webhook routes; fail closed on mismatch.
Document which artifact is shared, which configuration must differ, rollback, environment cleanup, and evidence needed before production.
Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.
Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.
The same reviewed artifact runs in staging and production, but startup validation requires different integration IDs, callback hosts, vault paths, token namespaces, and test policies.
| Failure | Response | | --- | --- | | Two environments share a secret | Stop deployment and separate/rotate credentials | | Callback host is unexpected | Reject the request before token exchange | | Production token appears in staging | Contain, revoke, and audit the cross-boundary path | | Environment matrix is stale | Block promotion until owners reconfirm it |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-19 | fail→pass | 7,723 | 2,670 | -65% | 1 | 1 | 0% | 1,439 | 1,792 | +25% | 0 | 0 | — |
case-01 | fail→pass | 18,832 | 23,033 | +22% | 1 | 1 | 0% | 4,275 | 4,560 | +7% | 0 | 0 | — |
case-02 | fail→fail | 15,848 | 20,746 | +31% | 1 | 1 | 0% | 3,068 | 5,950 | +94% | 0 | 0 | — |
case-03 | fail→fail | 21,092 | 20,743 | -2% | 1 | 1 | 0% | 4,203 | 5,728 | +36% | 0 | 0 | — |
case-04 | fail→pass | 6,752 | 3,794 | -44% | 1 | 1 | 0% | 1,096 | 2,154 | +97% | 0 | 0 | — |
case-05 | fail→pass | 7,503 | 3,634 | -52% | 1 | 1 | 0% | 1,244 | 1,970 | +58% | 0 | 0 | — |
case-06 | pass→pass | 12,714 | 3,984 | -69% | 1 | 1 | 0% | 2,125 | 2,170 | +2% | 0 | 0 | — |
case-07 | fail→pass | 9,938 | 3,528 | -64% | 1 | 1 | 0% | 1,630 | 2,044 | +25% | 0 | 0 | — |
case-08 | fail→pass | 8,730 | 3,774 | -57% | 1 | 1 | 0% | 1,498 | 1,848 | +23% | 0 | 0 | — |
case-09 | pass→pass | 6,439 | 11,254 | +75% | 1 | 1 | 0% | 1,184 | 2,245 | +90% | 0 | 0 | — |
case-10 | pass→pass | 4,288 | 5,110 | +19% | 1 | 1 | 0% | 755 | 2,220 | +194% | 0 | 0 | — |
case-11 | fail→pass | 6,519 | 3,262 | -50% | 1 | 1 | 0% | 1,191 | 2,018 | +69% | 0 | 0 | — |
case-12 | fail→pass | 6,614 | 3,335 | -50% | 1 | 1 | 0% | 1,090 | 1,977 | +81% | 0 | 0 | — |
case-13 | pass→pass | 17,327 | 8,168 | -53% | 1 | 1 | 0% | 1,788 | 2,861 | +60% | 0 | 0 | — |
case-14 | fail→fail | 13,079 | 13,086 | +0% | 1 | 1 | 0% | 2,234 | 3,811 | +71% | 0 | 0 | — |
case-15 | pass→pass | 10,626 | 6,451 | -39% | 1 | 1 | 0% | 1,607 | 2,531 | +57% | 0 | 0 | — |
case-16 | pass→pass | 11,082 | 11,339 | +2% | 1 | 1 | 0% | 1,714 | 3,470 | +102% | 0 | 0 | — |
case-17 | pass→pass | 11,386 | 7,933 | -30% | 1 | 1 | 0% | 1,850 | 2,951 | +60% | 0 | 0 | — |
case-18 | pass→pass | 5,622 | 2,158 | -62% | 1 | 1 | 0% | 958 | 1,818 | +90% | 0 | 0 | — |
case-20 | fail→pass | 5,663 | 3,275 | -42% | 1 | 1 | 0% | 997 | 1,897 | +90% | 0 | 0 | — |
case-21 | pass→pass | 8,122 | 2,882 | -65% | 1 | 1 | 0% | 1,313 | 1,909 | +45% | 0 | 0 | — |
case-22 | pass→pass | 8,862 | 4,114 | -54% | 1 | 1 | 0% | 1,545 | 2,177 | +41% | 0 | 0 | — |
case-23 | pass→pass | 14,053 | 14,690 | +5% | 1 | 1 | 0% | 2,360 | 4,576 | +94% | 0 | 0 | — |
case-24 | pass→pass | 14,183 | 11,835 | -17% | 1 | 1 | 0% | 2,664 | 3,686 | +38% | 0 | 0 | — |
case-25 | fail→pass | 14,545 | 13,026 | -10% | 1 | 1 | 0% | 2,738 | 4,019 | +47% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 25 cases were attempted. The headline lift of +40 percentage points is the difference between those two pass rates over the 25 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.