Connect
Optimize
Secure
Announcing StackOne Defender: leading open-source prompt injection guard for your agent • Read More →
Production-ready Canva MCP server with 21 extensible actions — plus built-in authentication, security, and optimized execution.
Coverage
Create, read, update, and delete across Canva — and extend your agent's capabilities with custom actions.
Authentication
Per-user OAuth in one call. Your Canva MCP server gets session-scoped tokens with zero credentials stored on your infra.
Agent Auth →Security
Every Canva tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.
Prompt Injection Defense →Performance
Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Canva call.
Tools Discovery →A Canva MCP server lets AI agents read and write Canva data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Canva MCP server ships with 21 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, and optimized agent context. Connect it from MCP clients like Claude Desktop, Cursor, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.
Every action from Canva's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.
Create a new Canva design
List designs owned by the authenticated user
Retrieve a design by its ID
List pages in a design
List items in a folder
Move an item to a different folder
Create a new folder
Retrieve a folder by its ID
Update a folder's name
Delete a folder
Retrieve an asset by its ID
Update an asset's metadata
Delete an asset
Start a design export job
Get the status and result of an export job
Create a new comment thread on a design
Retrieve a comment thread from a design
Add a reply to a comment thread
List replies in a comment thread
Retrieve the authenticated user's information
Retrieve the authenticated user's profile
One endpoint. Any framework. Your agent is talking to Canva in under 10 lines of code.
MCP Clients
Agent Frameworks
{
"mcpServers": {
"stackone": {
"command": "npx",
"args": [
"-y",
"mcp-remote@latest",
"https://api.stackone.com/mcp?x-account-id=<account_id>",
"--header",
"Authorization: Basic <YOUR_BASE64_TOKEN>"
]
}
}
}Anthropic's code_execution processes data already in context. Custom MCP code mode keeps raw tool responses in a sandbox. 14K tokens vs 500.
11 min
Benchmarking BM25, TF-IDF, and hybrid search for MCP tool discovery across 916 tools. The 80/20 TF-IDF/BM25 hybrid hits 21% Top-1 accuracy in under 1ms.
10 min
MCP tools that read emails, CRM records, and tickets are indirect prompt injection vectors. Here's how we built a two-tier defense that scans tool results in ~11ms.
12 min
origin_owner_id.All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.