Canva

Canva

Canva belongs in Atlas because its remote MCP can assemble, edit, locate, export, and comment on designs while preserving each user's Canva permissions.

Content, CMS, creative & DAMSystem of productionBYO-UI-ready platform
An illustration of access surfaces surrounding a governed system.
System roleSystem of production
Access maturityBYO-UI-ready platform
MCP supportOfficial MCP server
Reference updatedNot stated by publisher
BYO-UI reviewedJul 22, 2026

Concrete capability record

Data, retrieval, actions, identity, and operating limits

A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.

01 · Records and state owned

Designs, pages, folders, uploaded assets, brand kits, brand templates, comments, exports, and resize operations, with some brand and resize capabilities gated by plan.

02 · Data you can retrieve

Search designs, pages, and folders, then access eligible brand kits, templates, and existing design context through the individually authenticated user's Canva account.

03 · Actions and write paths

Generate or edit designs, upload assets, add comments, export files, and resize eligible designs; Enterprise users can autofill brand templates through documented tools.

04 · Authentication and permissions

Each user authenticates individually. Tool authorization follows that user's Canva access; supported clients use CIMD, with deprecated DCR or manual registration available as legacy fallbacks.

05 · Monitoring, approval, and recovery

Canva keeps designs, assets, and permissions under individual users rather than an organization-wide MCP identity, so shared workflows must preserve per-user ownership and access across teams.

06 · Limits and caveats

Resize requires Pro or higher, brand kits and autofill require Enterprise, and unlisted partner clients may need redirect-URI registration through Canva's review process before connecting.

First-party MCP tool catalog

33 named MCP tools · Canva remote design server

All tool names on Canva's first-party MCP tools-and-rate-limits page for the hosted server at mcp.canva.com/mcp. Plan-specific tools remain included but are labeled in the catalog notes and cited source. Reviewed Jul 10, 2026. Each user authenticates individually and operations inherit that user's design and asset permissions. Resize requires Pro or above; brand kits, brand templates, and autofill require Enterprise. New client redirect URIs are subject to Canva's access review.

First-party exact listPublisher-described complete catalogCanva MCP server
33 shown
Assets, imports, exports, and shortlinks5
upload-asset-from-urlwriteget-assetsreadimport-design-from-urlwriteresolve-shortlinkreadexport-designread
Brand templates and autofill5
autofill-designwriteget-brand-template-datasetreadsearch-brand-templatesreadlist-brand-kitsreadcreate-design-from-brand-templatewrite
Comments and replies4
comment-on-designwritereply-to-commentwritelist-commentsreadlist-repliesread
Design discovery and generation9
search-designsreadget-designreadget-design-pagesreadget-design-contentreadget-presenter-notesreadget-export-formatsreadgenerate-designdraftcreate-design-from-candidatewritecopy-designwrite
Folders and organization4
create-folderwritelist-folder-itemsreadsearch-foldersreadmove-item-to-folderwrite
Resize and editing transactions6
resize-designwritestart-editing-transactiondraftperform-editing-operationsdraftcommit-editing-transactionwritecancel-editing-transactiondraftget-design-thumbnailread

Agent access

MCP support

Official MCP serverCanva-hosted remote design MCP plus separate developer MCPCurrent service; partner client registration may require review

Support: Official MCP server

Read scope: Search user-accessible designs, pages, and folders, and retrieve eligible brand kits, templates, and design context for agent-assisted creative and collaboration workflows.

Write scope: 16 of 33 reviewed named tools have a write, draft, or mixed action label, including upload-asset-from-url, import-design-from-url, autofill-design, create-design-from-brand-template, comment-on-design, and others. Read each catalog boundary before enabling them.

Authentication: The hosted server authenticates every user separately through Canva. Supported clients use CIMD; deprecated DCR and manually registered redirect URIs remain documented paths for compatibility.

Approval boundary: Confirm before export, comment, asset upload, or design mutation when the result enters a shared campaign workflow; Canva itself enforces the authenticated user's edit rights.

Protocol does not erase product boundaries.

Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.

Editorial assessment

Access-maturity dimensions

A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.

Data access4
Action access4
Event access4
Identity4
Governance4
Agent access4
UI extensibility4
Portability4
Observability3
Documentation5

Proposed customer-shaped experiences

What customers could create on top.

The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Canva ships them.

Single-platform patterns

  • On-brand campaign asset assembly room
  • Campaign asset assembly room
  • Brief-to-experience studio
  • Content approval queue
Use in the brief builder →

Multi-platform compositions

  • Canva + CRM or campaign platform: campaign asset assembly room
  • Canva + work-management system + analytics or distribution platform: cross-system decision workspace
Explore composition recipes →

Evidence and dates

First-party references, with publisher and review dates separated

“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.

6 recorded sources
MCPRepresentative source
https://www.canva.dev/docs/mcp/ ↗

Hosted design MCP tools, individual authentication, user permissions, plan eligibility, and partner client registration

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 22, 2026

Canva production MCP scope and access controls reviewed 2026-07-22

APISource inventory
https://www.canva.dev/docs/connect/ ↗

First-party API reference or API overview recorded for this platform.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 12, 2026

Full-profile first-party re-verification on 2026-07-12; see the private audit ledger.

Developer docsSource inventory
https://www.canva.dev/ ↗

First-party developer documentation or platform overview.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

HomepageSource inventory
https://www.canva.com/ ↗

First-party product homepage used to confirm product identity and current positioning.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Webhooks / extensionsSource inventory
https://www.canva.dev/docs/apps/ ↗

First-party webhook, event, SDK, embedded-app, or extension documentation.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

MCP tool catalogTargeted review
Canva MCP tools and rate limits ↗

Named catalog evidence used on this profile.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Targeted first-party catalog review

Verified fact

Tied to cited first-party evidence reviewed for this profile.

Source inventory

Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.

Editorial assessment

System role, maturity interpretation, and architectural boundary.

Proposed design

Interface patterns and compositions—not vendor product claims.