DEV Community

Cover image for Figma let us in with one email. Canva took forty-seven days.
Eugeniya Ivanova
Eugeniya Ivanova

Posted on

Figma let us in with one email. Canva took forty-seven days.

A couple of weeks ago I wrote about getting our plugin into Figma. They sent one email asking for a video, we sent it, and that was basically it. I remember being surprised by how calmly the whole thing went.

Canva was running in parallel. Canva was not calm.

Forty-seven days from submission to approval. Four rounds of review. Five versions of the app. This wasn't because we'd managed to do everything wrong. Canva has three review stages that happen in order, and design review alone can take up to two weeks and involve several people. One reviewer even warned me that most apps get notes and that getting them doesn't mean you're failing review. This was useful information somewhere around round two. By round four, less so.

A lot of what slowed us down wasn't code. It was figuring out what a review comment was actually asking us to fix. If you're submitting an app there, these are the things I wish I'd known before we started.

The requirement is called one thing, and the real issue is another

The title of a Canva review note isn't always a particularly good description of the problem. We learned to stop treating it as one.

The clearest example came in the third round. We got three different checklist items back. Under all three, the reviewer had attached essentially the same evidence: "even if you pick 'Add video,' the exported file is still a PNG." I saw three items and started looking for three problems. There was one.

The bug itself was in the format config, not Publora. I checked that first because blaming our own API is a habit I've developed. We had one format with a single slot for "image or video." Canva goes through the formats in order, that combined slot doesn't match a video page correctly, the fallback kicks in, and the video comes out as a freeze frame. We split it into two formats. To make sure we'd understood what was happening, we put video first and got the opposite bug: static pages started rendering as mp4. At least that was convincing.

Another review item was called "Buttons not full width." I went looking for buttons. In the attached screenshot, the problem was actually a narrow dropdown that said "In an hour." After that I started opening the screenshots before doing much with the title of the ticket. It saved time.

Then there was one where the documentation and the reviewer simply disagreed. The docs said the object panel on the featured image should be dark grey. The reviewer wanted it white. We made it white. At that point I was no longer interested in winning an argument with a PDF.

We did it not the way they asked, and it came out more honest

One request was harder because we couldn't implement it literally. Canva wanted an account block that was always visible, with the user's name and avatar.

Publora doesn't really have that concept in this part of the product. What matters is which social channels you're connected to and where the post is going. I still tried every endpoint name I could think of: me, user, account, profile. Four different ways to get a 404.

So we built the block from the information we actually have. We fetch the connected channels and show their names and platforms in the header. Instead of a generic user profile, you see the actual accounts you're about to publish to: this X account, this LinkedIn, this Instagram.

That ended up making more sense for Publora anyway. The reviewer wanted the user to have account context while publishing. We could provide that context; it just wasn't the name-and-avatar version described in the ticket.

A piece of technical luck I didn't earn

There was also one part I expected to be difficult that turned out not to be difficult at all.

We don't have to upload the media from Canva ourselves. Canva exports the design and gives us a link, then Publora downloads the file from that link. The separate upload flow I'd been expecting to build simply wasn't necessary.

Our OAuth was an even better surprise. At some point we discovered that we'd already rolled out what we needed and apparently forgotten about it. Our regular REST API accepted the token, so sign-in worked without any new code. I would like more integrations to be solved by discovering that we already did the work six months ago.

The Cloudflare shim ended up at about a hundred lines and stores nothing. It's there for CORS: our API only accepts browser requests from our own domains, while Canva naturally runs on Canva's.

A few things from off-screen, so you don't step on them

Design review is separate and, for us, was the longest stage. Our fourth round came back with six comments, all about the listing images. Nothing was wrong with the app itself. So if you're planning around the technical work only, leave some time for somebody to have opinions about screenshots.

You also can't keep changing things while the review is running. When they say, "Please hold off on making any changes while it's under review," they mean it. Fixes go into a new version, and not everything necessarily carries over, so we ended up checking each version again from the beginning.

A demo video is mandatory, although we didn't find it in the main checklist. The requirement appears next to the field itself: without a video link, you can't submit. We recorded three versions because the app changed after review rounds and the previous recording stopped matching it.

And then we nearly published TEST to a real LinkedIn account. During one recording, the post went quite happily into the real schedule for the next morning because the publishing control still said "Tomorrow, 9:00" instead of "Save as draft." Technically, everything worked. Unfortunately, that was the problem. We noticed it while checking the recording and deleted the post before morning. I've already written an entire article about checking publishing state, so naturally I had to demonstrate the problem again myself.

How it ended

On September 21, the status changed to Application Approved. After that, the listing text was translated into eighteen languages and we got an email saying the app was ready for release. I then waited for the release button to become active before realizing that nothing was going to happen until I actually pressed it myself. Forty-seven days had apparently trained me to wait for permission.

Publora is in Canva now. Publer, Metricool and a few other social tools have been there for a while. Our flow is a little different: instead of exporting the design to a media library and finishing the post in another dashboard, we use Canva's Content Publisher intent. You can take the design you're already working on and publish it to one of your connected networks without leaving the Canva editor.

Canva says more than 250 million people use the product each month. Some of them can now finish the job without downloading a picture, opening another tab and uploading the same picture again.

After five versions, I'll take that.


I wrote this one with Claude as well. I told it what happened over those forty-seven days, it drafted, and I cut anything that hadn't happened that way.

Have you ever spent a review round fixing the thing the ticket was named after, only to find the real problem was in the screenshot?

Top comments (0)