Connect Gavana to OpenClaw
OpenClaw reaches Gavana over streamable HTTP with browser OAuth. It runs as a local gateway process rather than a browser tab, so no token is pasted into a chat and nothing depends on Gavana’s browser-origin allowlist.
Connect with full access
https://app.gavana.ai/mcp
This is the default Gavana connection. It requests all eight permissions and remains active until you disconnect or revoke it.
Add the server
OpenClaw’s configuration lives at ~/.openclaw/openclaw.json, in JSON5 — comments and trailing commas are allowed. MCP servers go under mcp.servers.
Normal connection:
{
"mcp": {
"servers": {
"gavana": {
"url": "https://app.gavana.ai/mcp",
"transport": "streamable-http",
"auth": "oauth"
}
}
}
}transport is required for a remote server — "streamable-http" for Gavana. Leave it out and OpenClaw has no way to know the entry is remote rather than a local command. The other accepted value, "sse", is the legacy transport; do not use it here.
You do not need an oauth block. That key exists only to override the scope, redirect URL, or client metadata URL, and Gavana supports dynamic client registration — so auth: "oauth" on its own is the whole authentication configuration.
If you prefer not to hand-edit the file, the same block is managed by openclaw mcp set; openclaw mcp list and openclaw mcp show read it back, and openclaw mcp unset removes an entry.
Sign in
openclaw mcp login gavanaThat runs the OAuth flow and stores the tokens in OpenClaw’s own state. Approve the scopes on Gavana’s consent screen when the browser opens.
Verify
openclaw mcp listThen ask for something read-only:
Using Gavana, list my canvases and read the most recently updated one. Report its
handle, revision, node count, and connection count. Do not change anything.openclaw doctor runs OpenClaw’s own diagnostics, including sandbox gate checks, if a server connects but tools do not behave.
Tuning the connection
Four optional fields on the server entry are worth knowing:
| Field | What it does |
|---|---|
requestTimeoutMs | Per-request timeout. Raise it if generation calls are cut short. |
connectionTimeoutMs | Connection timeout at startup. |
toolFilter | include and exclude lists, to narrow what OpenClaw sees. |
enabled | Set false to switch the server off without deleting the entry. |
toolFilter is ergonomics, not a security boundary. The endpoint you point at is the boundary.
Resulting permission surface
Read-only endpoint
| Can | Cannot |
|---|---|
| List and read canvases | Create, update, move, or delete anything |
| Validate a canvas graph | Save an image |
| Preview a canvas or get a review link | Create or run a workflow |
| Read Gavana’s own agent guidance | Discover video models, or generate an image or a video |
| Spend a single credit |
Tools exposed: guide_search, guide_get, canvas_list, canvas_get, canvas_validate, get_canvas_image, open_canvas, element_collection_list, element_get, element_history, and element_list — 11 in total. It issues canvas:read and element:read.
find_video_models is absent even though it only reads. It requires video:generate, and this endpoint never issues that scope.
Cost exposure: none.
Full endpoint
Sixteen tools: everything above, plus canvas writes, workflow authoring, and generation. Three of them can charge your connected AI provider — run_canvas_workflow, generate_image_in_canvas, and generate_video. Full schemas: hosted MCP tools.
Cost exposure: real.
The full endpoint’s OAuth consent requests canvas:read, canvas:write, asset:read, element:read, element:write, image:generate, video:generate, and job:manage. There is no partial approval on this path.
The local stdio server
OpenClaw can also launch Gavana’s local server as a child process, which exposes 57 tools instead of 29 and authenticates with a Personal Access Token rather than OAuth. Use command and args in place of url and transport:
{
"mcp": {
"servers": {
"gavana": {
"command": "npx",
"args": ["-y", "@gavana.ai/mcp@0.2.0"],
"env": {
"GAVANA_BASE_URL": "https://app.gavana.ai",
"GAVANA_AGENT_TOKEN": "PASTE_YOUR_TOKEN_HERE"
}
}
}
}
}Needs Node.js 20 or newer. The real permission surface here is the token’s scopes, not the tool list — a tool called outside them fails with a permission error. Add "GAVANA_MCP_READ_ONLY": "true" for a hard read-only server, or "GAVANA_MCP_TOOLSETS" to narrow the catalog; scoping the token is still the stronger control.
openclaw.json now contains a live credential. Keep it out of backups you share and out of any repository. If it leaks, revoke that token immediately and create a new one — see the safety contract.
Disconnect
Remove the entry with openclaw mcp unset, or set "enabled": false to keep it but switch it off. Then revoke the OAuth delegation from Gavana’s Personal Access Tokens screen — revocation takes effect on the next request. If you used the local stdio path, revoke the Personal Access Token as well.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| Server never connects | transport missing on a remote entry | Add "transport": "streamable-http" |
| Every call is unauthorized | OAuth not completed | Run openclaw mcp login gavana |
| Connection drops on long calls | Default request timeout too short | Raise requestTimeoutMs |
| Generation is refused | Token lacks image:generate or video:generate | Re-authenticate and approve the generation scopes |
| Fewer tools than expected | toolFilter is narrowing the list | Check include and exclude on the entry |
| Config edit seems ignored | JSON5 parse error earlier in the file | Run openclaw doctor |
More: MCP troubleshooting.
Security notes
- The hosted endpoints accept OAuth bearer tokens only. Do not attempt to use a
cba_…Personal Access Token there — that is the local MCP and API path. - Webhooks are not available through MCP by design: a signing secret must never enter model-visible tool arguments or tool logs. Use the CLI or the API when you need callbacks.
- Generation charges the AI provider connection on your Gavana account.