Connect Gavana to Cursor
Cursor is configured by editing its MCP configuration file rather than by running an install command, so Gavana’s CLI prints the block for you instead of writing it.
Option A — Hosted MCP over OAuth
Get the configuration block
gavana mcp config cursorAdd it to Cursor’s MCP configuration
The block it prints is:
{
"mcpServers": {
"gavana": {
"url": "https://app.gavana.ai/mcp"
}
}
}If your configuration already has an mcpServers object, add the gavana entry to it rather than replacing the file.
Restart Cursor and sign in
Complete the Gavana browser sign-in when prompted, and review the requested scopes before approving.
Verify
Using Gavana, list my canvases and read the most recently updated one. Report its
handle, revision, node count, and connection count. Do not change anything.Resulting permission surface. The full URL gives the 29-tool hosted catalog, with canvas:read, canvas:write, asset:read, element:read, element:write, image:generate, video:generate, and job:manage requested at consent — so run_canvas_workflow, generate_image_in_canvas, and generate_video can charge your connected AI provider.
No token is stored on disk on this path; the credential is an OAuth token held by Cursor.
Option B — Local MCP with a Personal Access Token
Use this when you want per-scope control, a read-only agent, or the full 57-tool surface including Image Actions, Recipe forking, node-level operations, and Run control.
Create a token
Follow Create an Agent Access Token and name it Cursor · <your machine>. New tokens default to all eight permissions and Never expiry; narrow them or choose a custom 1–90 day expiry only when appropriate.
Get the configuration block
gavana mcp config localAdd it to Cursor’s MCP configuration
{
"mcpServers": {
"gavana": {
"command": "npx",
"args": ["-y", "@gavana.ai/mcp@0.2.0"],
"env": {
"GAVANA_BASE_URL": "https://app.gavana.ai",
"GAVANA_AGENT_TOKEN": "PASTE_YOUR_TOKEN_HERE"
}
}
}
}For a hard read-only local server, add "GAVANA_MCP_READ_ONLY": "true" to env.
Restart Cursor and verify
This file now contains a live credential. Keep it out of your repository, out of screenshots, and out of support tickets. If Cursor’s MCP configuration lives inside a project directory, add it to .gitignore before you paste the token — not after.
Resulting permission surface. Exactly the token’s scopes. A tool called outside them fails with a permission error. If the token has neither image:generate nor video:generate, nothing Cursor does can spend a credit.
Which option
| You want | Use |
|---|---|
| Fastest setup, no secret on disk | Option A |
| A strictly read-only agent | Either — Option A read-only URL, or Option B with a canvas:read token |
| Image Actions, Recipe forking, node-level control | Option B |
| Precise scope control per client | Option B |
Disconnect
Remove the gavana entry from Cursor’s MCP configuration and restart. Then revoke the OAuth delegation (Option A) or the Personal Access Token (Option B) from Gavana’s Personal Access Tokens screen.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| Cursor does not list the server | Configuration was not reloaded, or the JSON is malformed | Restart Cursor; validate the JSON |
| Every call is unauthorized (Option B) | Token expired, revoked, or mistyped | Create a new token and update the file |
| Generation refused (Option B) | Token lacks the generation scope | Create a new token with image:generate or video:generate |
| Waits fail immediately | Token lacks job:manage | Add it |
| The server starts but no tools appear (Option B) | Node.js older than 20 | Install Node.js 20 or newer |
More: MCP troubleshooting.