Sponsor Suno AI Music arrow_forward
Plugin

Canva Pack

30 governed Canva Connect operator workflows for OAuth, designs, asynchronous jobs, and secure integrations

Type
Plugin
GitHub stars
2.8k
License
MIT
Repo last updated
Sep 27, 2026
Version
2.0.0
Author
Jeremy Longshore

What Canva Pack is

Canva Pack is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”

A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.

Installing Canva Pack adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.

How to install Canva Pack

Claude Code

  1. Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
  2. Install the plugin: claude plugin install canva-pack@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
  3. Restart the session if the new skills or commands don't appear straight away.

Claude Cowork

  1. Open Customize → Plugins and choose Add marketplace.
  2. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
  3. Find Canva Pack in the list, click Install, then connect any connectors it needs from its Connectors tab.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/saas-packs/canva-pack/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.

Thirty governed workflows for building and operating a Canva Connect backend. The pack covers OAuth, explicit authorization, designs and asynchronous jobs, assets and autofill, environment isolation, observability, incident response, and safe release controls.

Installation

/plugin install canva-pack@claude-code-plugins-plus

Operating Boundary

  • Canva Connect uses OAuth 2.0 Authorization Code with SHA-256 PKCE.
  • The current REST operation base is https://api.canva.com/rest/v1/.
  • Token exchange stays on a backend; refresh tokens are single-use and rotate.
  • Scopes are explicit and non-implied.
  • Mutating and asynchronous operations require durable identity and reconciliation.
  • Webhooks and the public connect/keys endpoint are preview surfaces; Canva says public integrations using preview features cannot pass review.
  • Endpoint behavior and limits come from the current first-party OpenAPI and endpoint references, not hard-coded folklore.

Workflows

Build and Integrate

  • canva-install-auth — backend PKCE, callback state, token rotation, disconnect
  • canva-hello-world — minimal read-only connection proof
  • canva-local-dev-loop — mock-first local development
  • canva-sdk-patterns — typed application-owned REST adapter
  • canva-core-workflow-a — design creation and export reconciliation
  • canva-core-workflow-b — assets, datasets, autofill, and folders

Diagnose and Recover

  • canva-common-errors — status/provider-code classification
  • canva-debug-bundle — minimal redacted evidence
  • canva-rate-limits — endpoint- and user-scoped throttling
  • canva-advanced-troubleshooting — layered hard-failure isolation
  • canva-incident-runbook — containment, mitigation, and recovery
  • canva-reliability-patterns — operation identity, reconciliation, dead letters
  • canva-known-pitfalls — preventive integration review

Secure and Govern

  • canva-security-basics — OAuth, secrets, tenants, and webhook authenticity
  • canva-data-handling — collection-through-deletion lifecycle controls
  • canva-enterprise-rbac — capability-aware application authorization
  • canva-policy-guardrails — repository and runtime enforcement
  • canva-prod-checklist — evidence-backed production approval

Deploy and Scale

  • canva-ci-integration — fork-safe offline and protected-live CI
  • canva-deploy-integration — immutable release and callback gate
  • canva-multi-env-setup — environment and credential isolation
  • canva-observability — privacy-safe metrics, traces, logs, and alerts
  • canva-performance-tuning — measured cache, pagination, and polling changes
  • canva-load-scale — mock-first capacity testing
  • canva-cost-tuning — request and entitlement evidence

Architect and Migrate

  • canva-reference-architecture — production backend blueprint
  • canva-architecture-variants — topology decision from explicit constraints
  • canva-migration-deep-dive — staged provider/application migration
  • canva-upgrade-migration — pinned OpenAPI and changelog upgrade
  • canva-webhooks-events — preview webhook verification and routing

First-Party Sources

  • Canva Connect documentation
  • Authentication
  • Security recommendations
  • Latest OpenAPI contract
  • API versions

Every skill also includes a dated references/official-docs.md evidence file.

License

MIT

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Canva Pack?

Canva Pack is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. 30 governed Canva Connect operator workflows for OAuth, designs, asynchronous jobs, and secure integrations

How do I install Canva Pack in Claude Code?

Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install canva-pack@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.

Can I use Canva Pack in Claude Cowork?

Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Canva Pack in the list, click Install, then connect any connectors it needs from its Connectors tab.

Is Canva Pack safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.