Connect another MCP client
Gavana ships a local stdio MCP package — @gavana.ai/mcp — so MCP-capable
clients like Codex or Hermes can call the same canvas operations as the CLI
directly from a conversation. For Claude Code and Claude Desktop, use the
dedicated Connect Claude flow so every
installation has one scoped, expiring Personal Access Token (PAT).
Prerequisites
- A Personal Access Token with the scopes needed by the tools you will enable. An existing CLI login can be reused but is not required.
- Node.js 20 or newer
Steps
Step 1: Configure the Personal Access Token
GAVANA_BASE_URL=https://app.gavana.ai
GAVANA_AGENT_TOKEN=<private Personal Access Token>Store the token in the MCP client’s private environment or secret store. Never
put a literal token in a shared configuration, repository, or chat message.
Existing CRAFTBOARD_BASE_URL and CRAFTBOARD_AGENT_TOKEN variables continue
to work as compatibility aliases.
Step 2: Register the MCP server with your client
Register this local stdio command using the client’s MCP configuration:
npx -y @gavana.ai/mcp@0.2.0The package must first be published by an owner of the gavana.ai npm
organization. Repository contributors can use bun run canvas:mcp until that
publication is complete.
Step 3: Work with your canvas from the conversation
Once connected, the agent can list canvases, read and change nodes, discover
and explicitly run Recipes, run the eight deterministic Image Actions, queue AI
image generation, and return durable results — all using the token’s scopes.
recipe_fork only adds a private editable workflow; recipe_run is the
separate tool that executes it. Use run_get, run_wait, and run_cancel for
Recipe, image, or Action work. The older job_* tools remain image and Action
compatibility aliases; they are never used for Recipe Runs. Action
runs do not spend AI credits.
The run_get, run_wait, and run_cancel tools require job:manage; include
that scope on the Personal Access Token for the normal wait-for-result flow.
Reference
The token’s name (set when you created it) is written into node and activity provenance, so canvas review can tell apart callers like Codex · CLI and Hermes · MCP without trusting a caller-supplied label.
Notes
- ChatGPT uses Gavana’s separate hosted Streamable HTTP MCP endpoint and OAuth flow. See Connect Gavana to ChatGPT.
- The package and preferred environment variables already use Gavana. The API
domain, saved CLI configuration path, and
cba_token prefix remain stable until the full application cutover. - The canvas UI remains available for visual review at any time; using MCP doesn’t require opening it.
- Recipe, image, and Action webhooks are intentionally API/CLI-only. Webhook signing secrets are
omitted from MCP tool arguments so they cannot enter model-visible conversation
or tool logs. Use the CLI’s
--webhook-secret-envoption or call the API from a trusted backend when you need callbacks.