Claude web & desktop
Claude connects to Gavana as a custom connector over streamable HTTP with browser OAuth. https://claude.ai is an allowed browser origin on the hosted endpoint, so the connection works without any additional configuration on the Gavana side.
Add the connector
Open connector settings
In Claude, go to Customize → Connectors. On Team and Enterprise plans only an Owner can add a connector — from Organization settings → Connectors — after which members connect to it individually.
Add the Gavana endpoint
Use the normal connection:
https://app.gavana.ai/mcpConnect
Choose Connect. Gavana opens a sign-in and consent screen in your browser.
Review the permissions before approving
The consent screen asks for all eight: canvas:read, canvas:write, asset:read, element:read, element:write, image:generate, video:generate, job:manage.
Approve, and Claude returns to the conversation with the connector active. The flow is a standard authorization-code exchange with PKCE and an exact callback binding — you never paste an Agent Access token into Claude.
Resulting permission surface
29 hosted tools: read the guide, list and read canvases, lint a graph, inspect Elements, plus create and delete nodes, save images, build and run workflows, and start image and video generation — including three tools that can charge your connected provider.
Three tools — run_canvas_workflow, generate_image_in_canvas, and generate_video — can incur provider cost. Start with Inspect before you write and require explicit current-turn approval before any paid call.
Claude Desktop with the local stdio server
Claude Desktop can also run the local server, which exposes 57 tools instead of 29. You need Node.js 20 or newer and an Agent Access token.
Add this to your Claude Desktop MCP configuration, replacing the placeholder with your token:
{
"mcpServers": {
"gavana": {
"command": "npx",
"args": ["-y", "@gavana.ai/mcp@0.2.0"],
"env": {
"GAVANA_BASE_URL": "https://app.gavana.ai",
"GAVANA_AGENT_TOKEN": "cba_your-token-here"
}
}
}
}Restart Claude Desktop after saving.
This file now contains a live credential. Keep it out of backups you share, out of any repository, and off screenshots. If it leaks, revoke the token from the Agent Access screen — that invalidates it immediately, and creating a replacement takes under a minute.
To narrow the local server without changing the token, add environment variables alongside the two above:
"GAVANA_MCP_READ_ONLY": "true",
"GAVANA_MCP_TOOLSETS": "canvas,assets"@gavana.ai/mcp is published on the public npm registry at version 0.2.0, so npx -y @gavana.ai/mcp@0.2.0 resolves without extra configuration. If your environment proxies npm through a private registry that does not mirror it, use a hosted endpoint instead.
Verify
Ask Claude to list your Gavana canvases. A successful answer with real canvas titles and canvas: handles confirms transport and auth together.
If the connector shows as active but every call fails, that is authentication — see Troubleshooting.