The Canva Apps SDK, Connect APIs, and MCP are now unified in the Canva Developers SDK. Learn more⁠(opens in a new tab or window).
Canva Developers SDK
The Canva Apps SDK, Connect APIs, and MCP are now unified in the Canva Developers SDK. Learn more⁠(opens in a new tab or window).
Canva REST API reference

Create image generation job

This API is currently provided as a preview. Be aware of the following:

  • There might be unannounced breaking changes.
  • Any breaking changes to preview APIs won't produce a new API version.
  • Public apps that use preview APIs will not pass the review process, and can't be made available to all Canva users.

Starts a new asynchronous job to generate an image from a plain-text prompt. When the image is generated, you can download it using the URL provided. The download URL is only valid for 24 hours.

The request requires a prompt and an idempotency key. Call this API with a user access token that has the asset:write scope.

To also save the generated image to the user's Canva account as an image asset, set asset_upload to type: upload. The job then returns the asset alongside the download URL. Saving the asset requires a user access token.

Starting a job consumes the user's AI credit allowance⁠(opens in a new tab or window). If the user has reached their AI allowance limit, the request returns a 429 error with the credit_quota_exceeded code.

For more information on the workflow for using asynchronous jobs, see API requests and responses. You can check the status and get the results of image generation jobs created with this API using the Get image generation job API.

HTTP method and URL path

POST https://api.canva.com/rest/v1/image-generations

This operation is rate limited to 20 requests per minute for each user of your app.

Authentication and authorization

This endpoint requires a valid access token that acts on behalf of a user.

Scopes

The access token must have all the following scopes (permissions):

  • asset:write

Header parameters

Authorizationstring
Required

Provides credentials to authenticate the request, in the form of a Bearer token.

For example: Authorization: Bearer {token}

Content-Typestring
Required

Indicates the media type of the information sent in the request. This must be set to application/json.

For example: Content-Type: application/json

Body parameters

promptstring
Required

A plain-text description of the image to generate.

Minimum length: 1

Maximum length: 2000

idempotency_keystring
Required

A key to make create requests idempotent. Retrying with the same key returns the original job without creating a duplicate, even if the other request parameters differ. Keys are held for 24 hours from job creation.

aspect_ratiostring
Optional

The aspect ratio of the generated image.

Default value: square

Available values:

  • square: A square (1:1) image.
  • landscape: A wide (16:9) image, suitable for landscape-oriented content.
  • portrait: A tall (9:16) image, suitable for portrait-oriented content.
modelstring
Optional

The model to use for image generation. If omitted, Canva selects the best available model for the request. If the requested model can't serve the request, the job fails. Canva never uses a different model to serve the request.

Available values:

  • lucid_origin: The Lucid Origin image generation model.
  • z_image_turbo: The Z Image Turbo image generation model.
asset_uploadImageGenerationAssetUpload
Optional

Whether to save the generated image as an image asset in the user's Canva account. Omitting asset_upload (or using type: none) returns only a download URL.

Saving the asset (type: upload) requires a user access token.

Don't save the generated image. The result contains only its download URL.

typestring
Required

Available values: The only valid value is none.

Save the generated image as an image asset in the user's Canva account. The asset appears in the user's Uploads, and the generated image in the result includes the asset alongside its download url.

typestring
Required

Available values: The only valid value is upload.

asset_namestring
Optional

A name for the image asset. Canva doesn't localize this value, so provide a name in the user's language. If omitted, Canva generates a name for the asset.

Minimum length: 1

Maximum length: 255

Example request

Examples for using the /v1/image-generations endpoint:

curl --request POST 'https://api.canva.com/rest/v1/image-generations' \
--header 'Authorization: Bearer {token}' \
--header 'Content-Type: application/json' \
--data '{
"prompt": "string",
"aspect_ratio": "square",
"model": "lucid_origin",
"idempotency_key": "550e8400-e29b-41d4-a716-446655440000",
"asset_upload": {
"type": "none"
}
}'
SH
const fetch = require("node-fetch");
fetch("https://api.canva.com/rest/v1/image-generations", {
method: "POST",
headers: {
"Authorization": "Bearer {token}",
"Content-Type": "application/json",
},
body: JSON.stringify({
"prompt": "string",
"aspect_ratio": "square",
"model": "lucid_origin",
"idempotency_key": "550e8400-e29b-41d4-a716-446655440000",
"asset_upload": {
"type": "none"
}
}),
})
.then(async (response) => {
const data = await response.json();
console.log(data);
})
.catch(err => console.error(err));
JS
import java.io.IOException;
import java.net.URI;
import java.net.http.*;
public class ApiExample {
public static void main(String[] args) throws IOException, InterruptedException {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.canva.com/rest/v1/image-generations"))
.header("Authorization", "Bearer {token}")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("{\"prompt\": \"string\", \"aspect_ratio\": \"square\", \"model\": \"lucid_origin\", \"idempotency_key\": \"550e8400-e29b-41d4-a716-446655440000\", \"asset_upload\": {\"type\": \"none\"}}"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request,
HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}
JAVA
import requests
headers = {
"Authorization": "Bearer {token}",
"Content-Type": "application/json"
}
data = {
"prompt": "string",
"aspect_ratio": "square",
"model": "lucid_origin",
"idempotency_key": "550e8400-e29b-41d4-a716-446655440000",
"asset_upload": {
"type": "none"
}
}
response = requests.post("https://api.canva.com/rest/v1/image-generations",
headers=headers,
json=data
)
print(response.json())
PY
using System.Net.Http;
var client = new HttpClient();
var request = new HttpRequestMessage
{
Method = HttpMethod.Post,
RequestUri = new Uri("https://api.canva.com/rest/v1/image-generations"),
Headers =
{
{ "Authorization", "Bearer {token}" },
},
Content = new StringContent(
"{\"prompt\": \"string\", \"aspect_ratio\": \"square\", \"model\": \"lucid_origin\", \"idempotency_key\": \"550e8400-e29b-41d4-a716-446655440000\", \"asset_upload\": {\"type\": \"none\"}}",
Encoding.UTF8,
"application/json"
),
};
using (var response = await client.SendAsync(request))
{
response.EnsureSuccessStatusCode();
var body = await response.Content.ReadAsStringAsync();
Console.WriteLine(body);
};
CSHARP
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
payload := strings.NewReader(`{
"prompt": "string",
"aspect_ratio": "square",
"model": "lucid_origin",
"idempotency_key": "550e8400-e29b-41d4-a716-446655440000",
"asset_upload": {
"type": "none"
}
}`)
url := "https://api.canva.com/rest/v1/image-generations"
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer {token}")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}
GO
$curl = curl_init();
curl_setopt_array($curl, array(
CURLOPT_URL => "https://api.canva.com/rest/v1/image-generations",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => array(
'Authorization: Bearer {token}',
'Content-Type: application/json',
),
CURLOPT_POSTFIELDS => json_encode([
"prompt" => "string",
"aspect_ratio" => "square",
"model" => "lucid_origin",
"idempotency_key" => "550e8400-e29b-41d4-a716-446655440000",
"asset_upload" => [
"type" => "none"
]
])
));
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if (empty($err)) {
echo $response;
} else {
echo "Error: " . $err;
}
PHP
require 'net/http'
require 'uri'
url = URI('https://api.canva.com/rest/v1/image-generations')
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request['Authorization'] = 'Bearer {token}'
request['Content-Type'] = 'application/json'
request.body = <<REQUEST_BODY
{
"prompt": "string",
"aspect_ratio": "square",
"model": "lucid_origin",
"idempotency_key": "550e8400-e29b-41d4-a716-446655440000",
"asset_upload": {
"type": "none"
}
}
REQUEST_BODY
response = http.request(request)
puts response.read_body
RUBY

Success response

If successful, the endpoint returns a 200 response with a JSON body with the following parameters:

jobImageGenerationJob

Details about the image generation job. If the job status is success, the job's result is present.

idstring

The image generation job ID.

statusstring

The status of the image generation job. A newly created job will be in_progress and will eventually become success or failed. If the status is success, the job's result is present.

Available values:

  • failed
  • in_progress
  • success
resultImageGenerationJobResult
Optional

Result of the image generation job. Only present if job status is success.

imageGeneratedImage

A generated image.

urlstring

A download URL for the generated image. The download URL is only valid for 24 hours.

widthinteger

The width of the generated image in pixels.

heightinteger

The height of the generated image in pixels.

assetobject
Optional

The image asset the generated image was saved as. Only present if the job was created with asset_upload set to type: upload and the asset still exists (for example, it's absent if the user has since deleted the asset).

typestring

Type of an asset.

Available values:

  • image
  • video
idstring

The ID of the asset.

namestring

The name of the asset.

tagsstring[]

The user-facing tags attached to the asset. Users can add these tags to their uploaded assets, and they can search their uploaded assets in the Canva UI by searching for these tags. For information on how users use tags, see the Canva Help Center page on asset tags⁠(opens in a new tab or window).

created_atinteger

When the asset was added to Canva, as a Unix timestamp (in seconds since the Unix Epoch).

updated_atinteger

When the asset was last updated in Canva, as a Unix timestamp (in seconds since the Unix Epoch).

thumbnailThumbnail
Optional

A thumbnail image representing the object.

widthinteger

The width of the thumbnail image in pixels.

heightinteger

The height of the thumbnail image in pixels.

urlstring

A URL for retrieving the thumbnail image. This URL expires after 15 minutes. This URL includes a query string that's required for retrieving the thumbnail.

errorImageGenerationError
Optional

If the image generation job fails, this object provides details about the error. Only present if status is failed.

codestring

Error code indicating what went wrong with the image generation.

Available values:

  • unsafe_input: Content safety checks rejected the prompt.
  • timeout: The generation did not complete in time.
  • model_not_available: The requested model can't currently serve this request, and Canva doesn't retry the job with another model. This is usually temporary. Retry later, retry without the model parameter to use automatic model selection, or retry with a different model.
  • model_retired: The requested model has been permanently retired from this version of the API, and you can't use it again in this version. Use a different model. The API documentation lists retired models, which keep their enum value for the lifetime of this API version.
  • internal_error: An unexpected error occurred during generation.
messagestring

A human-readable description of what went wrong.

quota_usageobject
Optional

Credit quota usage after reserving credits for this job. Not present if quota data is unavailable.

Example response

{
"job": {
"id": "string",
"status": "failed",
"result": {
"image": {
"url": "string",
"asset": {},
"width": 1024,
"height": 1024
}
},
"error": {
"code": "unsafe_input",
"message": "string"
}
},
"quota_usage": {}
}
JSON

Error responses

400 Bad Request

codestring

A short string indicating what failed. This field can be used to handle errors programmatically. For a complete list of error codes, see Error responses.

messagestring

A human-readable description of what went wrong.

Example error responses

The request field does not match expected format
{
"code": "invalid_request",
"message": "{fieldValue} does not match expected format for {fieldName}"
}
JSON
A required header is missing
{
"code": "invalid_request",
"message": "missing required header {headerName}"
}
JSON
Access token is missing from the request
{
"code": "invalid_request",
"message": "Access token is missing from the request."
}
JSON
Client credentials are missing from the request
{
"code": "invalid_request",
"message": "Client credentials are missing from the request."
}
JSON
Content-Type header is missing
{
"code": "invalid_header_value",
"message": "Content-Type header is missing for {path}"
}
JSON
Content-Type header is invalid
{
"code": "invalid_header_value",
"message": "Content-Type {contentType} is invalid for {path}"
}
JSON
Validating client failed
{
"code": "unauthorized_client",
"message": "Validating client failed for {clientAppId}"
}
JSON
Validating client failed with error code
{
"code": "unauthorized_client",
"message": "Validating client failed for {clientAppId}: {errorCode}"
}
JSON
Client secret is invalid
{
"code": "invalid_client",
"message": "Client secret is invalid for {clientAppId}"
}
JSON
Number of column-separated components in the base64 value is not 2
{
"code": "invalid_request",
"message": "Malformed encoded client ID and secret"
}
JSON
Could not decode the base64 value for client credentials
{
"code": "invalid_request",
"message": "Credentials could not be decoded from base64"
}
JSON
Failed to read request body
{
"code": "bad_request_body",
"message": "Failed to read request body"
}
JSON
Expected integer for query parameter
{
"code": "bad_query_params",
"message": "Expected integer for query parameter `{key}` but found {value}"
}
JSON
Expected long for query parameter
{
"code": "bad_query_params",
"message": "Expected long for query parameter `{key}` but found {value}"
}
JSON
Expected long list for query parameter
{
"code": "bad_query_params",
"message": "Expected long list for query parameter `{key}` but found {value}"
}
JSON
Expected 1 query parameter but found multiple
{
"code": "bad_query_params",
"message": "Expected 1 query parameter {key} but found {count}"
}
JSON
Missing required query parameter
{
"code": "bad_query_params",
"message": "Missing required query parameter: {key}"
}
JSON
Confidential clients must not authenticate via CORS requests
{
"code": "unauthorized_client",
"message": "Confidential clients must not authenticate via CORS requests"
}
JSON
The request URI could not be parsed
{
"code": "bad_request_params",
"message": "Invalid URI: {uri}"
}
JSON
The Origin header could not be parsed
{
"code": "bad_request_params",
"message": "Invalid Origin: {origin}"
}
JSON
One or more IDs could not be deobfuscated
{
"code": "invalid_field",
"message": "Invalid Ids: {ids}"
}
JSON

401 Unauthorized

codestring

A short string indicating what failed. This field can be used to handle errors programmatically. For a complete list of error codes, see Error responses.

messagestring

A human-readable description of what went wrong.

Example error responses

The OAuth client credentials are invalid
{
"code": "invalid_client",
"message": "Client {clientId} not available"
}
JSON
Access token could not be decoded or signature could not be verified.
{
"code": "invalid_access_token",
"message": "Access token is invalid"
}
JSON
Client credentials or body auth are missing from the request
{
"code": "invalid_client",
"message": "Client credentials or body auth are missing from the request."
}
JSON
Authorization header has wrong number of components
{
"code": "invalid_access_token",
"message": "Malformed Authorization header: wrong number of components"
}
JSON
Authorization header has invalid mode
{
"code": "invalid_access_token",
"message": "Malformed Authorization header: invalid mode"
}
JSON
Token couldn't be introspected
{
"code": "invalid_access_token",
"message": "Token couldn't be introspected"
}
JSON
Access token is revoked
{
"code": "revoked_access_token",
"message": "Access token is revoked"
}
JSON
Missing Authorization header
{
"code": "invalid_access_token",
"message": "Missing Authorization header"
}
JSON
Malformed Authorization header
{
"code": "invalid_access_token",
"message": "Malformed Authorization header"
}
JSON

403 Forbidden

codestring

A short string indicating what failed. This field can be used to handle errors programmatically. For a complete list of error codes, see Error responses.

messagestring

A human-readable description of what went wrong.

Example error responses

Image generation is not enabled for this client
{
"code": "permission_denied",
"message": "Image generation is not enabled"
}
JSON
The required OAuth scope is missing
{
"code": "missing_scope",
"message": "Missing scopes: {scopes}"
}
JSON
Request must be made on behalf of a user
{
"code": "user_role_required",
"message": "This request must be made on behalf of a user."
}
JSON

429 Credit Quota Exceeded

codestring

A short string indicating what failed. This field can be used to handle errors programmatically. For a complete list of error codes, see Error responses.

messagestring

A human-readable description of what went wrong.

quota_usageobject
Optional

Credit quota usage at the time of the error. Not present if quota data is unavailable.

Example error responses

User has reached their credit quota limit
{
"code": "credit_quota_exceeded",
"message": "User has exceeded their credit quota",
"quota_usage": {
"used_percentage": 100,
"resets_at": 1735689600,
"using_bonus_credits": false,
"upgrade_url": "https://www.canva.com/upgrade",
"is_admin": false,
"generation_pending": false
}
}
JSON
User is in a cooldown period after heavy credit usage
{
"code": "credit_quota_cooldown",
"message": "Credit quota cooldown is active",
"quota_usage": {
"used_percentage": 100,
"resets_at": 1735689600,
"using_bonus_credits": false,
"upgrade_url": "https://www.canva.com/upgrade",
"cooldown_ends_at": 1767182400,
"is_admin": false,
"generation_pending": true
}
}
JSON

Try it out

This uses your live Canva data.

This is not a sandbox/playground. This form performs API requests against your account's actual live Canva data. Make sure that you understand what the request is doing, as well as the requirements for each parameter detailed above.

Step 1: Enter your access token

To get started, generate an access token or provide your own below