Canva's Connect API at https://api.canva.com/rest/v1 lets integrations read and create designs, upload assets, and export files on a user's behalf.
Canva uses OAuth 2.0 with PKCE: register an integration in the Developer Portal and complete the authorization flow to get a user access token. Send it as Authorization: Bearer <token>. In the examples it's written {{CANVA_TOKEN}}.
Full reference: https://www.canva.dev/docs/connect/
Returns the user_id and team_id.
curl https://api.canva.com/rest/v1/users/me \
-H "Authorization: Bearer {{CANVA_TOKEN}}"
curl "https://api.canva.com/rest/v1/designs?limit=10" \
-H "Authorization: Bearer {{CANVA_TOKEN}}"