Skip to Content
AgentsConnect ChatGPT

Connect Gavana to ChatGPT

ChatGPT connects to Gavana’s hosted MCP endpoint using browser OAuth. You never paste a token into ChatGPT.

Connect with full access

https://app.gavana.ai/mcp

This is the default Gavana connection. It requests all eight permissions and remains active until you disconnect or revoke it.

Connect

Open custom connector setup

In an MCP-capable ChatGPT workspace, open the custom connector setup. Your workspace may require an administrator to allow custom connectors.

Add the endpoint

https://app.gavana.ai/mcp

Choose Connect

Gavana opens a sign-in and consent screen.

Review the requested permissions and approve

The normal endpoint requests all eight permissions: canvas, asset, Element, image, video, and job access. Read the list before approving.

ChatGPT returns to the connector once the OAuth authorization-code flow completes. The flow uses PKCE and an exact callback binding.

To get the endpoint from the CLI rather than typing it, run:

gavana mcp config chatgpt

This prints the endpoint and setup instructions — it does not configure ChatGPT for you, since ChatGPT has no local CLI to install into.

Resulting permission surface

Full endpoint

The full 29-tool catalog includes complete Element management alongside canvas, asset, Recipe, image, video, and Run tools. Important side effects include:

ToolSide effect
canvas_apply_batchWrites canvas state — free
save_image_to_canvasWrites a durable image node — free
create_canvas_workflowWrites a workflow card — free, never generates
run_canvas_workflowProvider cost
get_canvas_workflow_runReads run state — free
find_video_modelsReads connected models — free, but needs video:generate
generate_image_in_canvasProvider cost
generate_videoProvider cost
get_video_jobReads job state — free
element_create, element_update, element_restoreWrites the Element library — free
element_archiveRecoverable archive; requires explicit confirmation
element_collection_deleteDeletes only the collection; requires explicit confirmation

Cost exposure: real. Three tools can charge your connected AI provider. See hosted MCP tools for full schemas.

The full endpoint’s OAuth consent requests canvas:read, canvas:write, asset:read, element:read, element:write, image:generate, video:generate, and job:manage. There is no partial approval on this path.

What to ask

Read-only review:

List my Gavana canvases, inspect the most relevant one for this brief, and open it for review. Summarise its nodes, connections, and current revision. Do not change anything.

Free canvas work on the full endpoint:

Save this image to my Agent Canvas, then create a reusable workflow with the saved image as a fixed default. Do not run it yet.

Explicitly approved generation:

I approve one video generation. Find a connected model with image-to-video support, use this saved Gavana image as the first frame, and return the job status and the review link.

Notice the shape of the third prompt: the approval is in the same message as the request, it names one run, and it asks for the handle back. That is what the safety contract expects.

Elements with generation:

List my lighting Elements, use the exact version I choose, and apply it to one image generation. Show me the pinned element:<id>@v<n> handle before starting the paid run.

The Agent Canvas

When no specific canvas is chosen, work goes to your persistent Agent Canvas. It is a real canvas you can open and review in the browser like any other.

Disconnect

Remove the connector in ChatGPT to stop new use from that client. You can also revoke the Gavana OAuth delegation from Gavana’s Personal Access Tokens screen — normal connections do not expire automatically, and revocation takes effect on the next request.

Do both if the connection was made from a device or workspace you no longer control.

Security notes

  • The hosted endpoint accepts OAuth bearer tokens only. Do not attempt to use a cba_… Personal Access Token here — that is the local MCP and API path.
  • Image imports accept public HTTPS URLs and reject private or local-network destinations.
  • Webhooks are not available through MCP by design: a signing secret must never enter model-visible tool arguments or tool logs. Use the CLI or the API when you need callbacks.
  • Generation charges the AI provider connection on your Gavana account, not ChatGPT.
Last updated on