generated: '2026-08-13' method: searched source: >- https://www.canva.com/.well-known/openid-configuration, https://www.canva.com/.well-known/oauth-authorization-server, https://www.canva.com/.well-known/security.txt, https://mcp.canva.com/.well-known/oauth-protected-resource, https://mcp.canva.com/.well-known/oauth-authorization-server, https://www.canva.dev/docs/scim/, https://www.canva.dev/docs/connect/error-responses/, openapi/canva-connect-api-openapi.yml description: >- Cross-cutting standards conformance for Canva's developer surface, each entry backed by a document that was actually fetched or a spec property that was actually read. Absences are recorded as `conforms: false` with the evidence of absence, not omitted. standards: - id: oauth2 name: OAuth 2.0 (RFC 6749) authorization code conforms: true evidence: - >- openapi/canva-connect-api-openapi.yml securitySchemes.oauthAuthCode declares an authorizationCode flow with 18 scopes. - 'https://www.canva.com/.well-known/oauth-authorization-server (HTTP 200)' - 'Token/introspect/revoke operations exist: exchangeAccessToken, introspectToken, revokeTokens.' - id: oauth2-pkce name: PKCE (RFC 7636) conforms: true evidence: - >- The documented /authorize call requires code_challenge and code_challenge_method=s256 (https://www.canva.dev/docs/connect/api-requests-responses/). - >- mcp.canva.com advertises code_challenge_methods_supported [S256, plain]. - id: rfc8414 name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: - 'https://www.canva.com/.well-known/oauth-authorization-server -> HTTP 200, issuer https://www.canva.com' - 'https://mcp.canva.com/.well-known/oauth-authorization-server -> HTTP 200' - id: rfc9728 name: OAuth 2.0 Protected Resource Metadata conforms: true partial: true evidence: - >- https://mcp.canva.com/.well-known/oauth-protected-resource -> HTTP 200 with resource, authorization_servers, scopes_supported, bearer_methods_supported. - >- The 401 from https://mcp.canva.com/mcp carries a WWW-Authenticate header naming the resource_metadata URL — the full RFC 9728 discovery handshake. - >- PARTIAL: served by mcp.canva.com only. www.canva.com and api.canva.com both 404 on /.well-known/oauth-protected-resource. - id: rfc7591 name: OAuth 2.0 Dynamic Client Registration conforms: true partial: true evidence: - >- mcp.canva.com advertises registration_endpoint https://mcp.canva.com/register and client_id_metadata_document_supported: true. MCP surface only — Connect API integrations are still registered by hand in the Developer Portal. - id: oidc name: OpenID Connect Core / Discovery conforms: true evidence: - >- https://www.canva.com/.well-known/openid-configuration -> HTTP 200; issuer https://www.canva.com, userinfo https://api.canva.com/auth/v1/oidc/userinfo, jwks https://api.canva.com/auth/v1/oidc/jwks, RS256, pairwise subjects, scopes openid/email/profile. - 'Connect API exposes getOidcJwks and userInfo operations.' - id: scim name: SCIM 2.0 (RFC 7643 / RFC 7644) conforms: true evidence: - >- Canva publishes a SCIM v2 API at https://www.canva.com/_scim/v2 and states it implements the SCIM v2 specification (RFC 7644): https://www.canva.dev/docs/scim/ - 'Full Users and Groups CRUD incl. PATCH-style individual-attribute updates.' availability: >- Canva Enterprise single teams only. Not available to Canva for Teams organizations or multi-team organizations (existing Teams users are grandfathered). - id: rfc9116 name: security.txt conforms: true evidence: - >- https://www.canva.com/.well-known/security.txt -> HTTP 200 with Contact, Policy, Acknowledgments, Preferred-Languages, Hiring and Canonical fields. - id: rfc9457 name: 'Problem Details for HTTP APIs (application/problem+json)' conforms: false evidence: - >- Errors are application/json with a two-field {code, message} body. No `type` URI, no `title`, no `status` member, and the problem+json media type appears nowhere in the published OpenAPI (only application/json is used across all 59 operations). https://www.canva.dev/docs/connect/error-responses/ note: >- The error contract is nonetheless stable and machine-readable — a documented, fixed vocabulary of ~80 `code` values shared across every endpoint. - id: rfc8594 name: Sunset / Deprecation headers conforms: false evidence: - >- The versioning and deprecation documentation (https://www.canva.dev/docs/connect/versions/) describes a 6-month support window in prose but names no Sunset or Deprecation response header, and none appears in the OpenAPI. Deprecation is signalled by `deprecated: true` in the spec and by changelog entries only. - id: pagination name: Cursor pagination conforms: true evidence: - >- `continuation` query parameter + `continuation` response field on list endpoints; `limit` added per-endpoint through 2025-2026. Analytics preview endpoints use `offset` instead. openapi/canva-connect-api-openapi.yml - id: idempotency name: Idempotent writes (Idempotency-Key) conforms: false evidence: - >- No Idempotency-Key or equivalent header in any of the 59 operations, and no idempotency documentation. The async-job pattern partially mitigates lost responses. - id: openapi name: OpenAPI conforms: true version: 3.0.0 evidence: - >- Canva publishes and maintains an OpenAPI description at https://www.canva.dev/sources/connect/api/latest/api.yml and explicitly recommends openapi-generator for client generation. - id: asyncapi name: AsyncAPI conforms: false evidence: - >- No AsyncAPI document is published or referenced anywhere in Canva's own documentation index (https://www.canva.dev/docs/connect/llms.txt). The webhook catalog is prose plus NotificationContent schemas inside the REST OpenAPI. See asyncapi/canva-webhooks.yml. - id: mcp name: Model Context Protocol conforms: true evidence: - >- Hosted MCP server at https://mcp.canva.com/mcp (HTTP 401 with an RFC 9728 OAuth challenge) plus a local stdio server via `npx -y @canva/cli@latest mcp`. See mcp/canva-mcp.yml. - id: a2a name: A2A Agent Card conforms: false evidence: - >- /.well-known/agent-card.json and /.well-known/agent.json return HTTP 404 on www.canva.com, api.canva.com and www.canva.dev. No agent card is published. - id: llmstxt name: llms.txt conforms: true evidence: - >- https://www.canva.dev/docs/llms.txt (HTTP 200) is a real index, and each product area publishes its own — /docs/connect/llms.txt, /docs/apps/llms.txt, /docs/scim/llms.txt, /docs/print/llms.txt, /docs/audit-logs/llms.txt — plus a .md twin for every doc page. compliance_programs: source: https://trust.canva.com/ certifications: - SOC 2 - ISO 27001 - PCI DSS - GDPR detail: security/canva-trust-center.yml industry_regimes: - id: fhir conforms: false note: Not a healthcare provider; N/A. - id: psd2 conforms: false note: Not a financial provider; N/A. - id: fapi conforms: false note: Not a financial provider; N/A. - id: odata conforms: false - id: 'json:api' conforms: false