canva-webhooks-events
Installation
SKILL.md
Canva Preview Webhook Intake
Overview
Authenticate every notification with Canva's rotating public JWK set, then apply separate tenant/resource authorization and idempotency. Webhooks are outgoing-only and do not replace the Comments API for replies.
Prerequisites
- Eligible integration and explicitly approved preview use
- Controlled HTTPS callback, required scopes, and notification allowlist
- Durable idempotency store, queue, retention, and incident owner
Instructions
Step 1: Confirm eligibility
Use Read and Grep to verify current preview status, public-review posture, required collaboration plus notification-specific scopes, and enabled notification types.