> Markdown version of [/videos/942-insights-from-building-the-canva-developers-platform-to-empower-185-million-designers?t=1328](https://www.wearedevelopers.com/videos/942-insights-from-building-the-canva-developers-platform-to-empower-185-million-designers?t=1328). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Insights from building the Canva Developers Platform to empower 185 million designers How does Canva safely execute third-party code for 185 million users? Discover the sandboxed architecture, anti-corruption layers, and strict API governance powering their massive developer platform. - **Speakers:** [Anto](https://www.wearedevelopers.com/@anto) - **Event:** World Congress 2024 - **Published:** August 20, 2024 - **Duration:** 23:49 - **URL:** https://www.wearedevelopers.com/videos/942-insights-from-building-the-canva-developers-platform-to-empower-185-million-designers ## Summary Scaling to support over 185 million monthly active users required Canva to look beyond its internal engineering teams to fulfill massively diverse design requests. By launching the Canva Apps SDK and developer marketplace, the organization enabled a community to inject capabilities directly into the editor. Architecturally, third-party apps operate as JavaScript bundles running securely within sandboxed iframes, neutralizing the threat of malicious or faulty code. To bridge these external sandboxes with core functionalities, Canva implemented an "anti-corruption layer"—an API controller that decouples public data representations from internal models. This critical separation allows internal product teams to evolve rapidly without inadvertently breaking ecosystem apps or forcing disruptive public deprecations. Fostering a thriving platform relies heavily on strategic dogfooding and the engineering philosophy of "refining through continuous feedback." Before exposing APIs publicly, internal hackathons stress-test developer experience, proving that utilizing internal and preview releases as early as possible massively influences overall product direction. Initially, the platform embraced "pragmatic excellence," choosing tactical shortcuts like manual S3 uploads to deliver functional value to developers immediately. By deliberately starting small and deferring complex infrastructure, teams could focus exclusively on building core APIs, returning later to pay down technical debt with automated pipelines, dedicated gateway services, and backward-compatible message serialization once the ecosystem was established. Because public-facing endpoints are famously difficult to roll back, Canva approaches API design as a "long-term commitment to our developers." Leadership adheres to strict principles of simplicity, safety, evolvability, and consistency, adopting the rule that delaying a release is always preferable to shipping a problematic API. To ensure that Conway’s Law does not cause internal organizational charts to dictate public API structures, a cross-functional API Design Working Group maintains ecosystem standards. Rather than acting as a gatekeeper, this group shifts governance "to the left" by distributing comprehensive API run sheets and maintaining a public API handbook. This documentation empowers loosely coupled engineering pods to self-govern security and implementation while remaining perfectly aligned with a cohesive platform vision. **Keywords:** canva apps sdk, developer platform architecture, sandbox iframe security, api anti-corruption layer, message bus implementation, backward-compatible serialization, internal hackathon dogfooding, pragmatic technical debt, api deprecation strategies, app archetypes prioritization, api design working group, api life-cycle governance, shift-left api testing, conways law evasion, developer experience design ## Chapters 1. **Scaling a design platform for millions of users** (00:03) — Rapid growth in user-generated designs necessitates bringing external developers into the ecosystem. 1. **Securing external code using sandbox iframes and message buses** (02:42) — The developer platform isolates third-party JavaScript bundles to protect users while facilitating communication via API clients. 1. **Decoupling internal product functionality with an anti-corruption layer** (04:41) — A mapping layer prevents internal product changes from breaking apps or deprecating public APIs. 1. **Refining APIs through continuous feedback and internal dogfooding** (06:10) — Conducting internal hackathons and preview releases uncovers bugs and usability issues early in the development cycle. 1. **Managing technical debt while iterating on API infrastructure** (09:07) — Adopting manual deployment processes early enables rapid iteration before investing in dedicated gateway services. 1. **Prioritizing platform development using specific application archetypes** (12:54) — Categorizing developer requests into distinct application types provides focus and justifies necessary API deprioritization. 1. **Designing outstanding APIs with simplicity, safety, and evolvability** (15:31) — Following strict design principles ensures long-term commitment to developer ecosystems without breaking existing integrations. 1. **Maintaining public API consistency with internal design groups** (19:04) — Establishing an API design group enables team autonomy while avoiding disconnected architectures shaped by system limitations. 1. **Summarizing key engineering lessons for platform API development** (22:08) — A review of the core practices for building robust APIs that keep user impact at the center of development. ## Related Moments - [Summarizing the organizational benefits of platform engineering](https://www.wearedevelopers.com/videos/885-platform-engineering-vs-devops-why-not-both) (from "Platform Engineering vs. DevOps Why not both?") - [Balancing design freedom with framework accessibility restrictions](https://www.wearedevelopers.com/videos/1347-wearedevelopers-live-rendering-in-the-browser-the-state-of-css-and-accessibility-and-more) (from "WeAreDevelopers LIVE - Rendering in the Browser, The State of CSS and Accessibility and more") - [Introduction to Canva and its developer application ecosystem](https://www.wearedevelopers.com/videos/1013-a-journey-from-internal-tools-to-public-sdk) (from "A Journey from Internal Tools to Public SDK") - [Pivoting product strategy toward platform engineering](https://www.wearedevelopers.com/videos/100122-how-agentic-devops-gave-us-dev-time-back) (from "How Agentic DevOps gave us Dev time back") - [Designing internal developer platforms and product team responsibilities](https://www.wearedevelopers.com/videos/1614-ai-augmented-devops-with-platform-engineering) (from "AI-Augmented DevOps with Platform Engineering") - [Focusing on human connections and cohesive product stability](https://www.wearedevelopers.com/videos/850-the-year-3000-a-brief-history-of-web-development) (from "The year 3000, a brief history of Web Development") ## Related Articles - [Why developer experience matters](https://www.wearedevelopers.com/magazine/514-why-developer-experience-matters) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [How to Avoid Over-Engineering](https://www.wearedevelopers.com/magazine/546-how-to-avoid-over-engineering) - [Slopquatting, API Keys, Fun with Fonts, Recruiters vs AI and more - The Best of LIVE 2025 - Part 2](https://www.wearedevelopers.com/magazine/662-slopquatting-api-keys-fun-with-fonts-recruiters-vs-ai-and-more-the-best-of-live-2025-part-2) ## Related Jobs - [Principal Software Engineer, Enterprise AI Platform](https://www.wearedevelopers.com/jobs/ext/1467292-principal-software-engineer-enterprise-ai-platform) at **GitHub** - [Senior Web Designer, Growth](https://www.wearedevelopers.com/jobs/ext/102722-senior-web-designer-growth) at **Intercom, Inc.** - [Senior Engineer, Infrastructure Platform](https://www.wearedevelopers.com/jobs/ext/328836-senior-engineer-infrastructure-platform) at **Intercom, Inc.** - [Senior Software Engineer, Client Apps Platform](https://www.wearedevelopers.com/jobs/ext/1773893-senior-software-engineer-client-apps-platform) at **GitHub** - [Tribe Lead - ( Software) Engineering Centre of Excllence](https://www.wearedevelopers.com/jobs/ext/1475530-tribe-lead-software-engineering-centre-of-excllence) at **SD Worx** - [iOS Engineer, Swift/SwiftUI/Combine (B2C Broker)](https://www.wearedevelopers.com/jobs/ext/1611832-ios-engineer-swift-swiftui-combine-b2c-broker) at **Bitpanda**