Canvas access requires both of these conditions:
If either condition is not met, Canvas behaves as if it does not exist. Running Flows from a Canvas has one more condition; see Canvas Flow Literal Runs.
When Canvas is not enabled for a Space, Canvas requests return NOT_FOUND with no message. The response is never FORBIDDEN, so a disabled Canvas looks the same as a Canvas that does not exist.
Every Canvas operation requires:
UNAUTHORIZED.NOT_FOUND.FORBIDDEN, and callers outside the Space get NOT_FOUND. Operations on a specific Canvas or version check this role: every denial is the same NOT_FOUND as a Canvas that does not exist.Non-admin callers cannot list Canvases, read a Canvas, read a historical version, mutate a Canvas, or act on review candidates.
Canvas pages and the Canvas upload endpoint return 404 Not found to callers who are not Space admins, or when Canvas is not enabled for the Space.
Route | Method | Purpose |
|---|---|---|
| GET | Active Canvas list and create |
| GET | Canvas editor |
| GET | Read-only historical version |
| POST | File upload and ingestion |
For a Space admin in a Space where Canvas is enabled, opening the Space (/spaces/:spaceId) redirects to a Canvas. The Canvas is chosen in this order:
If the Space has no active Canvas, no redirect occurs.
Opening a Canvas records it as your selection for that Space.
Canvas data survives a Space export and import whether or not Canvas is enabled for the source or destination Space. See Canvas Space Transfer.