@@ -203,6 +203,39 @@ specialist's own 1:1 — never an invite into Myra's DM.
203203A create-succeeded / mint-failed split is a completed tool result that
204204names both halves, not a bare error.
205205
206+ ## Canva MCP connect (shipped)
207+
208+ Canva is the ` canva ` MCP preset (` packages/connections/src/mcp-presets.ts ` ):
209+ ` https://mcp.canva.com/mcp ` , ` connectionMode: "oauth" ` , with the 16
210+ advertised PRM scopes space-joined onto RFC 7591 DCR ` clientMetadata.scope `
211+ (` createMcpOAuthProvider ` in ` packages/connections/src/mcp-oauth.ts ` ).
212+ Other presets omit ` oauthScopes ` and stay on the SDK's SEP-835 PRM
213+ fallback.
214+
215+ Connect-time probe and credential fetch share
216+ ` mcpOriginPinnedFetch ` (` packages/credential-providers/src/mcp-origin-pinned-fetch.ts ` ):
217+ pin to the stored origin, extra first hop only
218+ ` https://mcp.canva.com ` → ` https://canva.ai ` (not a host suffix),
219+ ` redirect: "manual" ` so a 302 is never followed. ` /start ` classifies
220+ DCR/client refusal as ` client_rejected ` versus unreachable discovery as
221+ ` discovery_failed ` (` packages/connections/src/mcp-oauth-routes.ts ` ).
222+ RFC 7591 ` invalid_redirect_uri ` (and ` invalid_client_metadata ` ,
223+ ` invalid_client ` , ` unauthorized_client ` ) count as ` client_rejected ` ; the
224+ route clones 4xx/5xx JSON before the MCP SDK 1.30.0 maps unknown codes
225+ onto ` ServerError ` .
226+
227+ A successful OAuth callback probes with the new token and, on success,
228+ appends ` toolCount ` to the Plugins return query. The Canva row
229+ (` packages/plugins-ui/src/mcp-preset-cards.tsx ` ) shows that count when
230+ it is a non-negative integer; otherwise the row stays "Connected".
231+ ` @corbits/mcp-tools ` per-request timeout is two minutes
232+ (` MCP_REQUEST_TIMEOUT_MS ` in ` packages/mcp-tools/src/mcp-client.ts ` ) —
233+ above the SDK's 60s default, below a five-minute chat turn.
234+
235+ These are unit-tested control-flow facts. Live Canva OAuth against
236+ Canva's own servers is ** not** verified; do not document a proven live
237+ handshake.
238+
206239## Related docs
207240
208241- [ README.md] ( README.md ) — quickstart, local setup, repo layout, e2e detail
@@ -223,3 +256,5 @@ names both halves, not a bare error.
223256- Whether Pulumi stacks/config live in this repo or a separate
224257 infrastructure repo is not established in the docs reviewed for this
225258 pass.
259+ - Live Canva MCP OAuth (DCR, redirect allowlist, and post-OAuth probe
260+ against ` mcp.canva.com ` / ` canva.ai ` ) is not verified as of CL-7083.
0 commit comments