{
  "data": {
    "a": {
      "slug": "canva",
      "name": "Canva REST APIs + MCP",
      "vendor": "Canva",
      "vendorUrl": "https://www.canva.dev",
      "kind": "http-api",
      "category": "design-assets",
      "summary": "Canva's REST APIs and hosted MCP server connect applications and agents to its design platform.",
      "url": "https://www.anchorterminal.com/tools/canva",
      "markdownUrl": "https://www.anchorterminal.com/tools/canva.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/canva.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/canva.json",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.canva.com/rest/v1",
      "packages": [],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 authorisation code flow with PKCE (S256) against https://www.canva.com/api/oauth/authorize, with scopes such as design:content, asset:read and brandtemplate:meta chosen per app in the Developer Portal. Every call runs as one Canva user, so there's no server-to-server key. The MCP server at mcp.canva.com also uses per-user OAuth. Integrators register a client in the Developer Portal or, for CIMD clients, through a waitlist.",
      "pricing": "byo-plan",
      "pricingNotes": "No separate API fee. What the API and MCP can do follows the user's Canva plan. Free covers design generation, editing, search, export, comments and asset upload. Pro, Business and Enterprise add autofill, brand templates, brand kits, resize and pro-quality export. Canva says usage limits for autofill will come later. Private apps need Enterprise (https://www.canva.com/pricing/).",
      "priceSummary": "Your plan",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "Per-user OAuth on Canva plans. No x402 in the docs or OpenAPI description (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 33,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.canva.dev/docs/apps/rest-apis/",
      "llmsTxt": "https://www.canva.dev/llms.txt",
      "openapi": "https://www.canva.dev/sources/connect/api/latest/api.yml",
      "registryName": "com.canva.mcp/mcp",
      "capabilities": [
        "design.templates",
        "design.render",
        "design.brand",
        "video.render"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "llms-txt",
        "openapi",
        "async-jobs",
        "webhooks"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.3,
        "grade": "B",
        "agentReady": false,
        "rank": 319,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 59,
          "maintenance": 85,
          "payments": 30,
          "reliability": 64,
          "schema": 95,
          "security": 63,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-09-18. The MP4 `quality` parameter on the GA export job API changed from a fixed output size to a target pixel count without a new API version, which the deprecation policy requires for breaking changes. Canva logged it the same day as a bug fix, so we deduct at the low end. https://www.canva.dev/docs/apps/rest-apis/changelog/"
        ],
        "verdict": "OpenAPI 3.0 with 59 described operations, per-user rate limits and a 78-value error code enum. No server-to-server key, so unattended batch rendering has to run under one user's OAuth grant.",
        "bestFor": "Agents working for people or teams who already use Canva and need editable, on-brand designs filled from data.",
        "strengths": [
          "OpenAPI 3.0 with 59 described operations, per-user rate limits and a 78-value error code enum",
          "OAuth with PKCE and 18 read and write scopes, every action attributable to one user",
          "Written deprecation policy with at least 6 months' notice and a dated changelog updated on 1 October 2026",
          "Bugcrowd bug bounty, disclosure policy, SOC 2 Type 2 and ISO 27001",
          "Exports to PNG, JPG, GIF, PDF, PPTX, MP4 and HTML, and the result stays editable in Canva"
        ],
        "weaknesses": [
          "No server-to-server key, so unattended batch rendering has to run under one user's OAuth grant",
          "25 of 59 operations are preview and can change without a new version",
          "MP4 export quality changed meaning on 18 September 2026 without a new API version",
          "Content is used to train Canva's models by default unless the user opts out in settings",
          "No official SDK, and MCP edits need a start, operate and commit sequence"
        ],
        "agentNotes": [
          "Call the user capabilities endpoint before autofill, brand templates or resize, which need Pro or above",
          "Poll export, upload and autofill jobs with exponential backoff and download results within 24 hours",
          "Commit an MCP editing transaction after perform-editing-operations, or the changes don't land",
          "Expect license_required on export when a design holds premium elements",
          "Read `page_number`, not the deprecated `index`, from Get design pages"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.3
          }
        ],
        "editorialScores": {
          "ergonomics": 59,
          "maintenance": 85,
          "payments": 30,
          "reliability": 64,
          "schema": 95,
          "security": 63,
          "transparency": 71
        },
        "provenanceScore": 95
      },
      "connect": {
        "http": "curl https://api.canva.com/rest/v1/users/me -H \"Authorization: Bearer $CANVA_ACCESS_TOKEN\"",
        "claudeCode": "claude mcp add --transport http canva https://mcp.canva.com/mcp"
      },
      "letme": {
        "capability": "https://letme.dev/design.templates",
        "tool": "https://letme.dev/canva"
      },
      "area": "design-diagrams",
      "provenance": {
        "legalEntity": "Canva Pty Ltd",
        "domain": "canva.com",
        "domainRegistered": "2001-05-05",
        "endpointOnVendorDomain": true,
        "terms": "https://www.canva.com/policies/terms-of-use/",
        "privacy": "https://www.canva.com/policies/privacy-policy/",
        "statusPage": "https://www.canvastatus.com",
        "changelog": "https://www.canva.dev/docs/apps/rest-apis/changelog/",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "notes": [
          "Developer docs live on canva.dev. The API is served from api.canva.com",
          "security.txt lists a bug bounty, disclosure policy and trust centre but has no Expires field"
        ],
        "score": 95
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/canva.json",
      "live": {
        "slug": "canva",
        "probe": {
          "target": "https://api.canva.com/rest/v1",
          "method": "get",
          "lastAt": "2026-10-09T09:26:46.116394378Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 192,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 128,
          "p95ms24h": 169,
          "samples24h": 261,
          "samples30d": 2287,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 101,
              "ok": 101
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.canvastatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T09:24:55.457525338Z"
        },
        "versions": [
          {
            "registry": "mcp-registry",
            "name": "com.canva.mcp/mcp",
            "version": "1.0.0",
            "seenAt": "2026-10-09T02:57:46.004536428Z"
          }
        ],
        "securityTxt": {
          "url": "https://canva.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-08T15:38:34.274236163Z"
        },
        "llmsTxt": {
          "url": "https://www.canva.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:10.237346609Z"
        },
        "domain": {
          "domain": "canva.com",
          "registered": "2001-05-05",
          "source": "https://rdap.verisign.com/com/v1/domain/canva.com",
          "checkedAt": "2026-10-04T13:10:37.911167719Z"
        },
        "pages": [
          {
            "url": "https://www.canva.dev/docs/apps/rest-apis/changelog/",
            "kind": "changelog",
            "status": 304,
            "checkedAt": "2026-10-08T18:26:52.259715541Z",
            "changedAt": "2026-10-06T16:14:20.206147434Z",
            "fingerprint": "e15bd0d4a37e"
          },
          {
            "url": "https://www.canva.dev/docs/apps/llms.txt",
            "kind": "deprecations",
            "status": 0,
            "checkedAt": "2026-10-08T18:26:52.127865741Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          },
          {
            "url": "https://www.canva.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:55.766891355Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9fd21481e687"
          },
          {
            "url": "https://www.canva.com/policies/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:51.204569556Z",
            "changedAt": "2026-10-06T16:14:18.034522395Z",
            "fingerprint": "e90a5d594598"
          },
          {
            "url": "https://www.canva.com/policies/terms-of-use/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:53.798853094Z",
            "changedAt": "2026-10-06T16:14:20.799802666Z",
            "fingerprint": "8422ab742c4e"
          }
        ],
        "updatedAt": "2026-10-09T09:26:46.116394378Z"
      }
    },
    "answer": "Shotstack scores 65.3 (B) on agent readiness against Canva REST APIs + MCP's 64.3 (B), and leads in 3 of 7 scored categories. Canva REST APIs + MCP leads on schema \u0026 documentation, security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust.",
    "b": {
      "slug": "shotstack",
      "name": "Shotstack",
      "vendor": "ShotStack Pty Ltd",
      "vendorUrl": "https://shotstack.io",
      "kind": "http-api",
      "category": "design-assets",
      "summary": "Shotstack is a cloud video editor driven by JSON. It renders video, images and audio from edits and templates with merge fields. Agents reach it through the Edit API, a hosted MCP server or a CLI with an agent skill.",
      "url": "https://www.anchorterminal.com/tools/shotstack",
      "markdownUrl": "https://www.anchorterminal.com/tools/shotstack.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/shotstack.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/shotstack.json",
      "repo": "https://github.com/shotstack/shotstack-cli",
      "license": "Proprietary service under Shotstack's Terms and Conditions. The CLI and skill are Apache-2.0, the schemas package and SDKs are MIT, and the Studio SDK is under PolyForm Shield 1.0.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.shotstack.io/edit/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@shotstack/cli"
        },
        {
          "registry": "npm",
          "name": "@shotstack/schemas"
        },
        {
          "registry": "npm",
          "name": "shotstack-sdk"
        },
        {
          "registry": "pypi",
          "name": "shotstack-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "REST calls and the CLI send an API key in the `x-api-key` header. A browser signup at app.shotstack.io gives one sandbox key and one production key, self-serve, with no scopes found in the docs. The same keys reach the Edit, Serve and Ingest APIs. The MCP server uses OAuth (authorisation code with PKCE S256, dynamic client registration, one scope, `mcp:tools`) or the API key in an `x-api-key` header for headless use.",
      "pricing": "usage",
      "pricingNotes": "10 free credits on signup, valid 30 days, with no card. Pay as you go is $10 for 50 credits, 20 cents a minute of rendered video. Monthly plans run from $39 for 250 minutes to $499 for 10,000. The `stage` sandbox renders free with a watermark, so an agent can start without a contract. AI generation is charged per model in credits (checked 2026-10-08).",
      "priceSummary": "$0.20 / credit",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "Prepaid credits and monthly plans. No x402, MPP or L402 in the docs, llms.txt, OpenAPI definition or pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 15,
      "popularity": {
        "githubStars": 0,
        "npmWeekly": 1211,
        "pypiWeekly": 326,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://shotstack.io/docs/guide/",
      "llmsTxt": "https://shotstack.io/llms.txt",
      "openapi": "https://shotstack.io/docs/api/api.edit.json",
      "capabilities": [
        "design.templates",
        "design.render",
        "video.edit",
        "video.generate",
        "image.generate",
        "speech.tts",
        "audio.music"
      ],
      "tags": [
        "hosted",
        "closed-source",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "cli",
        "agent-skill",
        "async-jobs",
        "webhooks",
        "video",
        "images",
        "sandbox",
        "status-page",
        "sla"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 65.3,
        "grade": "B",
        "agentReady": false,
        "rank": 297,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 73,
          "payments": 45,
          "reliability": 85,
          "schema": 88,
          "security": 48,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "4 October 2026. Release 1.22.0 of the published API definition removed the `pricing` object from the `GET /models` response and replaced it with `POST /generate/quote`, in a minor release with no breaking-change mark and no notice found. We did not test whether the live response changed that day (https://github.com/shotstack/oas-api-definition/blob/main/CHANGELOG.md)"
        ],
        "verdict": "A public OpenAPI definition, Markdown docs, a hosted MCP server with OAuth and a free watermarked sandbox let an agent draft, check and render video with little setup. API keys have no scopes, webhooks are unsigned, no security contact or certification of Shotstack's own was found, and the published Node and Python SDKs date from July 2024.",
        "bestFor": "Teams that render video, images or audio from JSON or templates at volume and want an agent to draft edits that a person reviews in Studio.",
        "strengths": [
          "OpenAPI 3.0.1 definition at `https://shotstack.io/docs/api/api.edit.json` with 122 schemas, plus llms.txt, llms-full.txt and a Markdown twin of every guide page",
          "Hosted MCP server at `https://mcp.shotstack.io/` with 15 tools, OAuth authorisation code with PKCE S256 and dynamic client registration, or an `x-api-key` header",
          "`shotstack validate` checks an edit offline and `shotstack studio` opens a preview link, both with no API key and no credits",
          "The `stage` environment renders free with a watermark, and `POST /generate/quote` returns the credit cost of an AI generation without charging",
          "Rate limits are published per API (Edit 300 requests per 60 seconds in production), and the terms carry a 99.9 per cent uptime SLA with a 10 per cent credit"
        ],
        "weaknesses": [
          "API keys have no scopes. One production key and one sandbox key reach the Edit, Serve and Ingest APIs, and key rotation was not found in the docs",
          "Webhook callbacks are not signed, per the webhooks guide, which tells receivers to confirm a render by calling the API",
          "No security.txt, disclosure policy or certification of Shotstack's own was found. The DPA relies on AWS's SOC 2 and ISO 27001 reports",
          "The published API definition dropped the `pricing` object from `GET /models` in release 1.22.0 on 4 October 2026, a minor release with no breaking-change mark",
          "The npm `shotstack-sdk` (0.2.9) and PyPI `shotstack-sdk` (0.2.8) packages were last published in July 2024"
        ],
        "agentNotes": [
          "Fetch `https://shotstack.io/docs/api/api.edit.json` and the conventions guide before writing an edit. Track order is reversed, so the first track renders on top",
          "Render in `stage` first. It is free and watermarked, but AI generation there is charged from the production credit balance",
          "Call `POST /generate/quote` before `POST /generate`, and send an `Idempotency-Key` header on generation. `POST /render` has no idempotency key, so do not resubmit blindly",
          "Do not store the `url` from the render status response. It expires after 24 hours. Use the CDN address built from `owner` and the render id",
          "On a 429, wait for the 60-second window to reset and retry with backoff. Limits are per API key, 300 a minute on the Edit API in production"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 65.3
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 73,
          "payments": 45,
          "reliability": 85,
          "schema": 88,
          "security": 48,
          "transparency": 61
        },
        "provenanceScore": 84
      },
      "connect": {
        "install": "npm install -g @shotstack/cli",
        "http": "curl -X POST https://api.shotstack.io/edit/stage/render -H \"Content-Type: application/json\" -H \"x-api-key: $SHOTSTACK_API_KEY\" -d @edit.json",
        "claudeCode": "claude mcp add --transport http shotstack https://mcp.shotstack.io",
        "config": {
          "mcpServers": {
            "shotstack": {
              "url": "https://mcp.shotstack.io/"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/design.templates",
        "tool": "https://letme.dev/shotstack"
      },
      "area": "design-diagrams",
      "unitPrices": [
        {
          "item": "Pay as you go credit",
          "unit": "credit",
          "usd": 0.2,
          "note": "$10 for 50 credits, one credit renders one minute of video, valid 12 months"
        },
        {
          "item": "Starter",
          "unit": "month",
          "usd": 39,
          "note": "250 minutes a month"
        },
        {
          "item": "Pro",
          "unit": "month",
          "usd": 99,
          "note": "750 minutes a month"
        },
        {
          "item": "Scale",
          "unit": "month",
          "usd": 199,
          "note": "2,000 minutes a month"
        },
        {
          "item": "Volume",
          "unit": "month",
          "usd": 499,
          "note": "10,000 minutes a month"
        }
      ],
      "provenance": {
        "legalEntity": "ShotStack Pty Ltd",
        "domain": "shotstack.io",
        "domainRegistered": "2017-06-30",
        "endpointOnVendorDomain": true,
        "terms": "https://shotstack.io/terms/",
        "privacy": "https://shotstack.io/privacy/",
        "statusPage": "https://status.shotstack.io",
        "changelog": "https://github.com/shotstack/oas-api-definition/blob/main/CHANGELOG.md",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms name ShotStack Pty Ltd, ACN 632 863 024, and the privacy policy gives an address in Maroubra, New South Wales.",
          "The terms were last updated on 6 October 2026. They cover the APIs, Studio and AI generation, and include plans and an SLA as schedules.",
          "The privacy policy was last updated on 21 December 2021. A DPA and a sub-processor list, both updated 6 October 2026, are at shotstack.io/dpa/ and shotstack.io/sub-processors/.",
          "The API answers at api.shotstack.io, the MCP server at mcp.shotstack.io and hosted files at cdn.shotstack.io.",
          "shotstack.io/.well-known/security.txt returns 404.",
          "The status page runs on Kener and links an RSS feed of incidents and maintenance.",
          "The changelog is the CHANGELOG.md of the API definition repository. No changelog page was found on shotstack.io.",
          "RDAP for shotstack.io gives a registration date of 2017-06-30 and Gandi SAS as registrar."
        ],
        "score": 84
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/shotstack.json",
      "live": {
        "slug": "shotstack",
        "probe": {
          "target": "https://api.shotstack.io/edit/v1",
          "method": "get",
          "lastAt": "2026-10-09T09:27:04.664482457Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 882,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 858,
          "p95ms24h": 890,
          "samples24h": 20,
          "samples30d": 20,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.shotstack.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:32.082902585Z"
        },
        "updatedAt": "2026-10-09T09:27:04.664482457Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Canva",
        "b": "ShotStack Pty Ltd",
        "name": "Vendor"
      },
      {
        "a": "https://api.canva.com/rest/v1",
        "b": "https://api.shotstack.io/edit/v1",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP, Streamable HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Your plan",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "none",
        "b": "Proprietary service under Shotstack's Terms and Conditions. The CLI and skill are Apache-2.0, the schemas package and SDKs are MIT, and the Studio SDK is under PolyForm Shield 1.0.0",
        "name": "Licence"
      },
      {
        "a": "33",
        "b": "15",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "com.canva.mcp/mcp",
        "b": "not listed",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-01",
        "b": "2026-10-05",
        "name": "Last release"
      },
      {
        "a": "2026-08-19",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-08-25",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes, with an opt-out",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "none",
        "b": "0 stars, 1.2k npm/wk, 326 PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Shotstack scores 65.3 (B) on agent readiness against Canva REST APIs + MCP's 64.3 (B), and leads in 3 of 7 scored categories. Canva REST APIs + MCP leads on schema \u0026 documentation, security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Canva REST APIs + MCP or Shotstack?"
      },
      {
        "answer": "Canva REST APIs + MCP uses an OAuth sign-in. Shotstack takes an API key or an OAuth sign-in.",
        "question": "Do Canva REST APIs + MCP and Shotstack need an API key?"
      },
      {
        "answer": "Yes. Canva REST APIs + MCP has a hosted endpoint at https://api.canva.com/rest/v1 and Shotstack at https://api.shotstack.io/edit/v1.",
        "question": "Can an agent call Canva REST APIs + MCP and Shotstack without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 95 against 88",
          "Security \u0026 auth, 63 against 48",
          "Maintenance \u0026 community, 85 against 73",
          "Transparency \u0026 trust, 83 against 73"
        ],
        "also": null,
        "goodFor": "Agents working for people or teams who already use Canva and need editable, on-brand designs filled from data.",
        "slug": "canva",
        "watchFor": "No server-to-server key, so unattended batch rendering has to run under one user's OAuth grant"
      },
      {
        "aheadOn": [
          "Reliability, 85 against 64",
          "Payments \u0026 pricing, 45 against 30"
        ],
        "also": null,
        "goodFor": "Teams that render video, images or audio from JSON or templates at volume and want an agent to draft edits that a person reviews in Studio.",
        "slug": "shotstack",
        "watchFor": "API keys have no scopes. One production key and one sandbox key reach the Edit, Serve and Ingest APIs, and key rotation was not found in the docs"
      }
    ],
    "job": {
      "capability": "design.templates",
      "name": "Design templates"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/adobe-photoshop-api-vs-canva.json",
        "title": "Adobe Photoshop API vs Canva REST APIs + MCP",
        "url": "https://www.anchorterminal.com/compare/adobe-photoshop-api-vs-canva"
      },
      {
        "json": "https://www.anchorterminal.com/compare/adobe-photoshop-api-vs-shotstack.json",
        "title": "Adobe Photoshop API vs Shotstack",
        "url": "https://www.anchorterminal.com/compare/adobe-photoshop-api-vs-shotstack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bannerbear-vs-canva.json",
        "title": "Bannerbear API + MCP vs Canva REST APIs + MCP",
        "url": "https://www.anchorterminal.com/compare/bannerbear-vs-canva"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bannerbear-vs-shotstack.json",
        "title": "Bannerbear API + MCP vs Shotstack",
        "url": "https://www.anchorterminal.com/compare/bannerbear-vs-shotstack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/canva-vs-creatomate.json",
        "title": "Canva REST APIs + MCP vs Creatomate",
        "url": "https://www.anchorterminal.com/compare/canva-vs-creatomate"
      },
      {
        "json": "https://www.anchorterminal.com/compare/canva-vs-placid.json",
        "title": "Canva REST APIs + MCP vs Placid API + MCP",
        "url": "https://www.anchorterminal.com/compare/canva-vs-placid"
      },
      {
        "json": "https://www.anchorterminal.com/compare/canva-vs-templated.json",
        "title": "Canva REST APIs + MCP vs Templated API + MCP",
        "url": "https://www.anchorterminal.com/compare/canva-vs-templated"
      },
      {
        "json": "https://www.anchorterminal.com/compare/creatomate-vs-shotstack.json",
        "title": "Creatomate vs Shotstack",
        "url": "https://www.anchorterminal.com/compare/creatomate-vs-shotstack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/placid-vs-shotstack.json",
        "title": "Placid API + MCP vs Shotstack",
        "url": "https://www.anchorterminal.com/compare/placid-vs-shotstack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/shotstack-vs-templated.json",
        "title": "Shotstack vs Templated API + MCP",
        "url": "https://www.anchorterminal.com/compare/shotstack-vs-templated"
      },
      {
        "json": "https://www.anchorterminal.com/compare/canva-vs-osmo-cli.json",
        "title": "Canva REST APIs + MCP vs Osmo CLI",
        "url": "https://www.anchorterminal.com/compare/canva-vs-osmo-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/osmo-cli-vs-shotstack.json",
        "title": "Osmo CLI vs Shotstack",
        "url": "https://www.anchorterminal.com/compare/osmo-cli-vs-shotstack"
      }
    ],
    "scores": [
      {
        "by": 21,
        "canva": 64,
        "edge": "shotstack",
        "key": "reliability",
        "name": "Reliability",
        "shotstack": 85,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "canva": 95,
        "edge": "canva",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "shotstack": 88,
        "weight": 13
      },
      {
        "by": 4,
        "canva": 59,
        "edge": "shotstack",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "shotstack": 63,
        "weight": 13
      },
      {
        "by": 15,
        "canva": 63,
        "edge": "canva",
        "key": "security",
        "name": "Security \u0026 auth",
        "shotstack": 48,
        "weight": 14
      },
      {
        "by": 15,
        "canva": 30,
        "edge": "shotstack",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "shotstack": 45,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "canva": 85,
        "edge": "canva",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "shotstack": 73,
        "weight": 7
      },
      {
        "by": 10,
        "canva": 83,
        "edge": "canva",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "shotstack": 73,
        "weight": 7
      }
    ],
    "summary": "Shotstack scores 65.3 (B) on agent readiness against Canva REST APIs + MCP's 64.3 (B), and leads in 3 of 7 scored categories. Canva REST APIs + MCP leads on schema \u0026 documentation, security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust. Both do design templates.",
    "verdicts": {
      "canva": "OpenAPI 3.0 with 59 described operations, per-user rate limits and a 78-value error code enum. No server-to-server key, so unattended batch rendering has to run under one user's OAuth grant.",
      "shotstack": "A public OpenAPI definition, Markdown docs, a hosted MCP server with OAuth and a free watermarked sandbox let an agent draft, check and render video with little setup. API keys have no scopes, webhooks are unsigned, no security contact or certification of Shotstack's own was found, and the published Node and Python SDKs date from July 2024."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/canva-vs-shotstack",
    "json": "https://www.anchorterminal.com/compare/canva-vs-shotstack.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/canva-vs-shotstack.md",
    "slim": "https://www.anchorterminal.com/compare/canva-vs-shotstack.min.md"
  },
  "markdown": "Shotstack scores 65.3 (B) on agent readiness against Canva REST APIs + MCP's 64.3 (B), and leads in 3 of 7 scored categories. Canva REST APIs + MCP leads on schema \u0026 documentation, security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust. Both do design templates.\n\n- Canva REST APIs + MCP: grade B, 64.3/100, rank #319 of 842. Markdown https://www.anchorterminal.com/tools/canva.md · JSON https://www.anchorterminal.com/api/v1/tools/canva.json\n- Shotstack: grade B, 65.3/100, rank #297 of 842. Markdown https://www.anchorterminal.com/tools/shotstack.md · JSON https://www.anchorterminal.com/api/v1/tools/shotstack.json\n\n## Which one, for what\n\n### Canva REST APIs + MCP (B)\n\nGood for: Agents working for people or teams who already use Canva and need editable, on-brand designs filled from data.\n\nAhead on:\n- Schema \u0026 documentation, 95 against 88\n- Security \u0026 auth, 63 against 48\n- Maintenance \u0026 community, 85 against 73\n- Transparency \u0026 trust, 83 against 73\n\nWatch for: No server-to-server key, so unattended batch rendering has to run under one user's OAuth grant\n\n### Shotstack (B)\n\nGood for: Teams that render video, images or audio from JSON or templates at volume and want an agent to draft edits that a person reviews in Studio.\n\nAhead on:\n- Reliability, 85 against 64\n- Payments \u0026 pricing, 45 against 30\n\nWatch for: API keys have no scopes. One production key and one sandbox key reach the Edit, Serve and Ingest APIs, and key rotation was not found in the docs\n\n\n## Score by category\n\n| Category | Weight | Canva REST APIs + MCP | Shotstack | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 64 | 85 | Shotstack +21 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 95 | 88 | Canva REST APIs + MCP +7 |\n| Agent ergonomics | 13% (16.2 this run) | 59 | 63 | Shotstack +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 63 | 48 | Canva REST APIs + MCP +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 45 | Shotstack +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 73 | Canva REST APIs + MCP +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 83 | 73 | Canva REST APIs + MCP +10 |\n| Negative events | ≤15 | -3 | -3 | |\n| **Total** | | **64.3 · B** | **65.3 · B** | |\n\n## Facts side by side\n\n| Fact | Canva REST APIs + MCP | Shotstack |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Canva | ShotStack Pty Ltd |\n| Hosted endpoint | `https://api.canva.com/rest/v1` | `https://api.shotstack.io/edit/v1` |\n| Transports | HTTP, Streamable HTTP | HTTP, Streamable HTTP |\n| Auth | OAuth | OAuth or key |\n| Pricing | Your plan | Pay per use |\n| x402 | no | no |\n| Licence | none | Proprietary service under Shotstack's Terms and Conditions. The CLI and skill are Apache-2.0, the schemas package and SDKs are MIT, and the Studio SDK is under PolyForm Shield 1.0.0 |\n| Tools exposed | 33 | 15 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | `com.canva.mcp/mcp` | not listed |\n| Last release | 2026-10-01 | 2026-10-05 |\n| Terms last updated | 2026-08-19 | no date given |\n| Privacy policy last updated | 2026-08-25 | no date given |\n| Customer content may train models | yes, with an opt-out | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | none | 0 stars, 1.2k npm/wk, 326 PyPI/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Canva REST APIs + MCP.** OpenAPI 3.0 with 59 described operations, per-user rate limits and a 78-value error code enum. No server-to-server key, so unattended batch rendering has to run under one user's OAuth grant.\n\n**Shotstack.** A public OpenAPI definition, Markdown docs, a hosted MCP server with OAuth and a free watermarked sandbox let an agent draft, check and render video with little setup. API keys have no scopes, webhooks are unsigned, no security contact or certification of Shotstack's own was found, and the published Node and Python SDKs date from July 2024.\n\n## Before you call either\n\n### Canva REST APIs + MCP\n\n1. Call the user capabilities endpoint before autofill, brand templates or resize, which need Pro or above\n2. Poll export, upload and autofill jobs with exponential backoff and download results within 24 hours\n3. Commit an MCP editing transaction after perform-editing-operations, or the changes don't land\n4. Expect license_required on export when a design holds premium elements\n5. Read `page_number`, not the deprecated `index`, from Get design pages\n\n### Shotstack\n\n1. Fetch `https://shotstack.io/docs/api/api.edit.json` and the conventions guide before writing an edit. Track order is reversed, so the first track renders on top\n2. Render in `stage` first. It is free and watermarked, but AI generation there is charged from the production credit balance\n3. Call `POST /generate/quote` before `POST /generate`, and send an `Idempotency-Key` header on generation. `POST /render` has no idempotency key, so do not resubmit blindly\n4. Do not store the `url` from the render status response. It expires after 24 hours. Use the CDN address built from `owner` and the render id\n5. On a 429, wait for the 60-second window to reset and retry with backoff. Limits are per API key, 300 a minute on the Edit API in production\n\n## Questions\n\n### Which is better for AI agents, Canva REST APIs + MCP or Shotstack?\n\nShotstack scores 65.3 (B) on agent readiness against Canva REST APIs + MCP's 64.3 (B), and leads in 3 of 7 scored categories. Canva REST APIs + MCP leads on schema \u0026 documentation, security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust.\n\n### Do Canva REST APIs + MCP and Shotstack need an API key?\n\nCanva REST APIs + MCP uses an OAuth sign-in. Shotstack takes an API key or an OAuth sign-in.\n\n### Can an agent call Canva REST APIs + MCP and Shotstack without installing anything?\n\nYes. Canva REST APIs + MCP has a hosted endpoint at https://api.canva.com/rest/v1 and Shotstack at https://api.shotstack.io/edit/v1.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/canva-vs-shotstack.json, and with the fewest tokens: https://www.anchorterminal.com/compare/canva-vs-shotstack.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"canva\", \"b\": \"shotstack\"}`. From a terminal: `anchor compare canva shotstack`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/canva.json and https://www.anchorterminal.com/api/v1/tools/shotstack.json\n\n## Other comparisons with Canva REST APIs + MCP or Shotstack\n\n- [Adobe Photoshop API vs Canva REST APIs + MCP](https://www.anchorterminal.com/compare/adobe-photoshop-api-vs-canva.md)\n- [Adobe Photoshop API vs Shotstack](https://www.anchorterminal.com/compare/adobe-photoshop-api-vs-shotstack.md)\n- [Bannerbear API + MCP vs Canva REST APIs + MCP](https://www.anchorterminal.com/compare/bannerbear-vs-canva.md)\n- [Bannerbear API + MCP vs Shotstack](https://www.anchorterminal.com/compare/bannerbear-vs-shotstack.md)\n- [Canva REST APIs + MCP vs Creatomate](https://www.anchorterminal.com/compare/canva-vs-creatomate.md)\n- [Canva REST APIs + MCP vs Placid API + MCP](https://www.anchorterminal.com/compare/canva-vs-placid.md)\n- [Canva REST APIs + MCP vs Templated API + MCP](https://www.anchorterminal.com/compare/canva-vs-templated.md)\n- [Creatomate vs Shotstack](https://www.anchorterminal.com/compare/creatomate-vs-shotstack.md)\n- [Placid API + MCP vs Shotstack](https://www.anchorterminal.com/compare/placid-vs-shotstack.md)\n- [Shotstack vs Templated API + MCP](https://www.anchorterminal.com/compare/shotstack-vs-templated.md)\n- [Canva REST APIs + MCP vs Osmo CLI](https://www.anchorterminal.com/compare/canva-vs-osmo-cli.md)\n- [Osmo CLI vs Shotstack](https://www.anchorterminal.com/compare/osmo-cli-vs-shotstack.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Canva REST APIs + MCP vs Shotstack",
        "url": ""
      }
    ],
    "description": "Shotstack scores 65.3 (B) on agent readiness against Canva REST APIs + MCP's 64.3 (B), and leads in 3 of 7 scored categories. Canva REST APIs + MCP leads on schema \u0026 documentation, security \u0026 auth, maintenance \u0026 community and transparency \u0026 trust. Both do design templates.…",
    "facts": [
      "Canva REST APIs + MCP B 64.3",
      "Shotstack B 65.3",
      "scores"
    ],
    "h1": "Canva REST APIs + MCP vs Shotstack",
    "image": "https://www.anchorterminal.com/assets/og/compare-canva-vs-shotstack.png",
    "path": "/compare/canva-vs-shotstack",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Canva REST APIs + MCP vs Shotstack for AI agents, B 64.3 vs B 65.3",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/canva-vs-shotstack"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 730
  },
  "version": 1
}
