Connect Gavana to ChatGPT
ChatGPT connects to Gavana’s hosted MCP endpoint using browser OAuth. You never paste a token into ChatGPT.
Connect with full access
https://app.gavana.ai/mcp
This is the default Gavana connection. It requests all eight permissions and remains active until you disconnect or revoke it.
Connect
Open custom connector setup
In an MCP-capable ChatGPT workspace, open the custom connector setup. Your workspace may require an administrator to allow custom connectors.
Add the endpoint
https://app.gavana.ai/mcpChoose Connect
Gavana opens a sign-in and consent screen.
Review the requested permissions and approve
The normal endpoint requests all eight permissions: canvas, asset, Element, image, video, and job access. Read the list before approving.
ChatGPT returns to the connector once the OAuth authorization-code flow completes. The flow uses PKCE and an exact callback binding.
To get the endpoint from the CLI rather than typing it, run:
gavana mcp config chatgptThis prints the endpoint and setup instructions — it does not configure ChatGPT for you, since ChatGPT has no local CLI to install into.
Resulting permission surface
Full endpoint
The full 29-tool catalog includes complete Element management alongside canvas, asset, Recipe, image, video, and Run tools. Important side effects include:
| Tool | Side effect |
|---|---|
canvas_apply_batch | Writes canvas state — free |
save_image_to_canvas | Writes a durable image node — free |
create_canvas_workflow | Writes a workflow card — free, never generates |
run_canvas_workflow | Provider cost |
get_canvas_workflow_run | Reads run state — free |
find_video_models | Reads connected models — free, but needs video:generate |
generate_image_in_canvas | Provider cost |
generate_video | Provider cost |
get_video_job | Reads job state — free |
element_create, element_update, element_restore | Writes the Element library — free |
element_archive | Recoverable archive; requires explicit confirmation |
element_collection_delete | Deletes only the collection; requires explicit confirmation |
Cost exposure: real. Three tools can charge your connected AI provider. See hosted MCP tools for full schemas.
The full endpoint’s OAuth consent requests canvas:read, canvas:write, asset:read, element:read, element:write, image:generate, video:generate, and job:manage. There is no partial approval on this path.
What to ask
Read-only review:
List my Gavana canvases, inspect the most relevant one for this brief, and open it
for review. Summarise its nodes, connections, and current revision. Do not change
anything.Free canvas work on the full endpoint:
Save this image to my Agent Canvas, then create a reusable workflow with the saved
image as a fixed default. Do not run it yet.Explicitly approved generation:
I approve one video generation. Find a connected model with image-to-video support,
use this saved Gavana image as the first frame, and return the job status and the
review link.Notice the shape of the third prompt: the approval is in the same message as the request, it names one run, and it asks for the handle back. That is what the safety contract expects.
Elements with generation:
List my lighting Elements, use the exact version I choose, and apply it to one image
generation. Show me the pinned element:<id>@v<n> handle before starting the paid run.The Agent Canvas
When no specific canvas is chosen, work goes to your persistent Agent Canvas. It is a real canvas you can open and review in the browser like any other.
Disconnect
Remove the connector in ChatGPT to stop new use from that client. You can also revoke the Gavana OAuth delegation from Gavana’s Personal Access Tokens screen — normal connections do not expire automatically, and revocation takes effect on the next request.
Do both if the connection was made from a device or workspace you no longer control.
Security notes
- The hosted endpoint accepts OAuth bearer tokens only. Do not attempt to use a
cba_…Personal Access Token here — that is the local MCP and API path. - Image imports accept public HTTPS URLs and reject private or local-network destinations.
- Webhooks are not available through MCP by design: a signing secret must never enter model-visible tool arguments or tool logs. Use the CLI or the API when you need callbacks.
- Generation charges the AI provider connection on your Gavana account, not ChatGPT.