---
title: "canva"
description: "Search and work with designs in the connected user's global Canva account, using Canva's official remote MCP server. This package does not replace canva-cn."
canonical: https://agentpluginsdirectory.com/plugins/canva--xpert-ai
last-updated: 2026-10-10
---

# canva
Search and work with designs in the connected user's global Canva account, using Canva's official remote MCP server. This package does not replace canva-cn.
- Slug: canva--xpert-ai
- Publisher: Xpert AI
- Repository: https://github.com/xpert-ai/xpert-plugins
- Manifest: agent-plugins/canva/plugin.json
- Version: 1.0.0
- Category (editorial): other
- Skills: 1 (canva-workspace)
- MCP servers: 1 (canva-global)
- Stars: 8
- Repository created: 2025-09-19
- Repository last pushed: 2026-10-10
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/canva--xpert-ai
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What canva does, in the publisher's words

Search and work with designs in the global Canva account on the workspace's shared Connector.

Official endpoint: https://mcp.canva.com/mcp

Product docs: Canva MCP

- Unauthenticated initialize returned 401. WWW-Authenticate named protected-resource metadata https://mcp.canva.com/.well-known/oauth-protected-resource/mcp.
- That document's resource is https://mcp.canva.com/mcp, which matches the MCP URL. Its authorization server is https://mcp.canva.com.
- Minimum OAuth scope: profile:read, design:meta:read, design:content:write, design:content:read, folder:read, folder:write, brandtemplate:content:read, brandtemplate:meta:read, brandtemplate:content:write, comment:write, comment:read, asset:read, asset:write, brandkit:read, help:answers:read, and help:answers:write. Those are the scopes_supported values on the protected-resource metadata. The document does not name a smaller required subset. Do not add scopes outside that list.
- Authorization-server metadata at https://mcp.canva.com/.well-known/oauth-authorization-server names issuer https://mcp.canva.com, authorize https://mcp.canva.com/authorize, token https://mcp.canva.com/token, and registration https://mcp.canva.com/register. PKCE S256 is advertised. Token endpoint auth methods include none, client_secret_basic, and client_secret_post. Canva also documents Client ID Metadata Documents. The path /.well-known/oauth-authorization-server/mcp returned 404; use the issuer document above.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/xpert-ai/xpert-plugins/HEAD/agent-plugins/canva/README.md
