Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Execute Canva Connect API production deployment checklist and go-live procedures. Use when deploying Canva integrations to production, preparing for launch, or validating production readiness. Trigger with phrases like "canva production", "deploy canva", "canva go-live", "canva launch checklist".
.claude/skills/jeremylongshore-canva-prod-checklist/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 102% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 53% | 0% |
| case-15 | ✗→✓ | ▲ Improved | 3% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 11% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 1% | 0% |
Make go-live an evidence decision tied to an immutable artifact. Preview features, broad scopes, unsafe callback hosts, ambiguous jobs, or unverifiable rollback keep the release closed.
Use Read and Grep to confirm exact artifact, environment, integration ID, callback hosts, backend-only secrets, CI event boundaries, and operator ownership.
Review minimum explicit scopes, tenant/resource checks, capabilities, consent changes, disconnect cleanup, and token-refresh serialization.
Pin current OpenAPI/changelog, identify deprecated and preview APIs, and confirm public-review eligibility. Canva states public integrations using preview features cannot pass review.
Prove operation identity, bounded retry, endpoint/user queueing, async job reconciliation, webhook idempotency if used, and partial-failure cleanup.
Prove content/credential classification, retention/deletion, URL handling, log redaction, low-cardinality metrics, alert ownership, and debug-bundle expiry.
Use Write or Edit to record mocked failures, protected read-only integration proof, migration recovery, rollback command/path, and post-rollback reconciliation.
Record exact evidence, approver, residual risks, and activation steps. Refuse if any required fact is inferred rather than proven.
Canva Connect calls use Bearer access tokens obtained by a backend through OAuth 2.0 Authorization Code with SHA-256 PKCE. Request explicit least-privilege scopes, keep client secrets and tokens out of browser-visible state, and serialize refresh so the replacement single-use refresh token is stored atomically.
Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Canva-side change.
A public release using a preview webhook path is refused. The team ships the non-preview core after exact-head tests and keeps the preview feature in a separate non-public experiment.
| Failure | Response | | --- | --- | | Preview status is unclear | Treat the feature as ineligible until confirmed | | Rollback was not exercised | Do not approve production | | Scope set exceeds features | Reduce scopes and obtain new consent where required | | Health proof mutates content | Replace it with a protected non-mutating read |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 16,073 | 21,763 | +35% | 1 | 1 | 0% | 2,780 | 5,609 | +102% | 0 | 0 | — |
case-02 | pass→pass | 21,048 | 13,983 | -34% | 1 | 1 | 0% | 4,432 | 4,498 | +1% | 0 | 0 | — |
case-03 | fail→pass | 18,757 | 19,232 | +3% | 1 | 1 | 0% | 3,266 | 4,985 | +53% | 0 | 0 | — |
case-04 | pass→pass | 10,157 | 6,664 | -34% | 1 | 1 | 0% | 1,692 | 2,683 | +59% | 0 | 0 | — |
case-05 | pass→pass | 9,687 | 6,391 | -34% | 1 | 1 | 0% | 1,579 | 2,552 | +62% | 0 | 0 | — |
case-06 | pass→pass | 14,303 | 13,600 | -5% | 1 | 1 | 0% | 2,607 | 4,064 | +56% | 0 | 0 | — |
case-07 | pass→pass | 12,263 | 12,558 | +2% | 1 | 1 | 0% | 2,053 | 3,739 | +82% | 0 | 0 | — |
case-08 | pass→pass | 9,037 | 5,814 | -36% | 1 | 1 | 0% | 1,467 | 2,364 | +61% | 0 | 0 | — |
case-09 | pass→pass | 11,957 | 13,964 | +17% | 1 | 1 | 0% | 1,984 | 4,081 | +106% | 0 | 0 | — |
case-10 | pass→pass | 12,957 | 12,605 | -3% | 1 | 1 | 0% | 2,063 | 3,844 | +86% | 0 | 0 | — |
case-11 | pass→pass | 33,808 | 15,825 | -53% | 1 | 1 | 0% | 2,722 | 4,362 | +60% | 0 | 0 | — |
case-12 | pass→pass | 11,035 | 8,796 | -20% | 1 | 1 | 0% | 1,809 | 2,923 | +62% | 0 | 0 | — |
case-13 | pass→pass | 15,827 | 12,441 | -21% | 1 | 1 | 0% | 2,747 | 3,667 | +33% | 0 | 0 | — |
case-14 | fail→fail | 12,587 | 8,613 | -32% | 1 | 1 | 0% | 2,164 | 3,025 | +40% | 0 | 0 | — |
case-15 | fail→pass | 11,018 | 1,959 | -82% | 1 | 1 | 0% | 1,713 | 1,771 | +3% | 0 | 0 | — |
case-16 | fail→pass | 13,156 | 4,391 | -67% | 1 | 1 | 0% | 1,958 | 2,170 | +11% | 0 | 0 | — |
case-17 | pass→pass | 16,710 | 14,717 | -12% | 1 | 1 | 0% | 2,790 | 4,069 | +46% | 0 | 0 | — |
case-18 | pass→pass | 14,307 | 6,877 | -52% | 1 | 1 | 0% | 2,358 | 2,674 | +13% | 0 | 0 | — |
case-19 | pass→pass | 15,006 | 9,354 | -38% | 1 | 1 | 0% | 2,288 | 3,028 | +32% | 0 | 0 | — |
case-20 | pass→pass | 17,675 | 16,584 | -6% | 1 | 1 | 0% | 2,969 | 4,254 | +43% | 0 | 0 | — |
case-21 | pass→pass | 10,588 | 9,017 | -15% | 1 | 1 | 0% | 2,003 | 3,336 | +67% | 0 | 0 | — |
case-22 | pass→pass | 10,375 | 8,207 | -21% | 1 | 1 | 0% | 2,073 | 3,187 | +54% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +18 percentage points is the difference between those two pass rates over the 22 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.