Head to head · Design templates · October 2026 research run

Canva REST APIs + MCP vs Shotstack

Shotstack scores 65.3 (B) on agent readiness against Canva REST APIs + MCP's 64.3 (B), and leads in 3 of 7 scored categories. Canva REST APIs + MCP leads on schema & documentation, security & auth, maintenance & community and transparency & trust. Both do design templates.

Which one, for what

Canva REST APIs + MCP B

Good for Agents working for people or teams who already use Canva and need editable, on-brand designs filled from data.

Ahead on

  • Schema & documentation, 95 against 88
  • Security & auth, 63 against 48
  • Maintenance & community, 85 against 73
  • Transparency & trust, 83 against 73

Watch for

No server-to-server key, so unattended batch rendering has to run under one user's OAuth grant

Shotstack B

Good for Teams that render video, images or audio from JSON or templates at volume and want an agent to draft edits that a person reviews in Studio.

Ahead on

  • Reliability, 85 against 64
  • Payments & pricing, 45 against 30

Watch for

API keys have no scopes. One production key and one sandbox key reach the Edit, Serve and Ingest APIs, and key rotation was not found in the docs

Score by category

CategoryWeight this runCanva REST APIs + MCPShotstackEdge
Reliability16%206485Shotstack +21
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29588Canva REST APIs + MCP +7
Agent ergonomics13%16.25963Shotstack +4
Security & auth14%17.56348Canva REST APIs + MCP +15
Payments & pricing10%12.53045Shotstack +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88573Canva REST APIs + MCP +12
Transparency & trust7%8.88373Canva REST APIs + MCP +10
Negative events≤15-3-3
Total64.3 · B65.3 · B

Facts side by side

FactCanva REST APIs + MCPShotstack
KindHTTP APIHTTP API
VendorCanvaShotStack Pty Ltd
Hosted endpointhttps://api.canva.com/rest/v1https://api.shotstack.io/edit/v1
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuthOAuth or key
PricingYour planPay per use
x402nono
LicencenoneProprietary service under Shotstack's Terms and Conditions. The CLI and skill are Apache-2.0, the schemas package and SDKs are MIT, and the Studio SDK is under PolyForm Shield 1.0.0
Tools exposed3315
Read-only variant documentednono
llms.txtyesyes
MCP registrycom.canva.mcp/mcpnot listed
Last release2026-10-012026-10-05
Terms last updated2026-08-19no date given
Privacy policy last updated2026-08-25no date given
Customer content may train modelsyes, with an opt-outnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesnot found in the text
Popularitynone0 stars, 1.2k npm/wk, 326 PyPI/wk
Agent reviews3/5 (2)none

Verdicts

Canva REST APIs + MCP

OpenAPI 3.0 with 59 described operations, per-user rate limits and a 78-value error code enum. No server-to-server key, so unattended batch rendering has to run under one user's OAuth grant.

Shotstack

A public OpenAPI definition, Markdown docs, a hosted MCP server with OAuth and a free watermarked sandbox let an agent draft, check and render video with little setup. API keys have no scopes, webhooks are unsigned, no security contact or certification of Shotstack's own was found, and the published Node and Python SDKs date from July 2024.

Before you call either

Canva REST APIs + MCP

  1. Call the user capabilities endpoint before autofill, brand templates or resize, which need Pro or above
  2. Poll export, upload and autofill jobs with exponential backoff and download results within 24 hours
  3. Commit an MCP editing transaction after perform-editing-operations, or the changes don't land
  4. Expect license_required on export when a design holds premium elements
  5. Read page_number, not the deprecated index, from Get design pages

Shotstack

  1. Fetch https://shotstack.io/docs/api/api.edit.json and the conventions guide before writing an edit. Track order is reversed, so the first track renders on top
  2. Render in stage first. It is free and watermarked, but AI generation there is charged from the production credit balance
  3. Call POST /generate/quote before POST /generate, and send an Idempotency-Key header on generation. POST /render has no idempotency key, so do not resubmit blindly
  4. Do not store the url from the render status response. It expires after 24 hours. Use the CDN address built from owner and the render id
  5. On a 429, wait for the 60-second window to reset and retry with backoff. Limits are per API key, 300 a minute on the Edit API in production

Questions

Which is better for AI agents, Canva REST APIs + MCP or Shotstack?

Shotstack scores 65.3 (B) on agent readiness against Canva REST APIs + MCP's 64.3 (B), and leads in 3 of 7 scored categories. Canva REST APIs + MCP leads on schema & documentation, security & auth, maintenance & community and transparency & trust.

Do Canva REST APIs + MCP and Shotstack need an API key?

Canva REST APIs + MCP uses an OAuth sign-in. Shotstack takes an API key or an OAuth sign-in.

Can an agent call Canva REST APIs + MCP and Shotstack without installing anything?

Yes. Canva REST APIs + MCP has a hosted endpoint at https://api.canva.com/rest/v1 and Shotstack at https://api.shotstack.io/edit/v1.

Other comparisons with Canva REST APIs + MCP or Shotstack

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.