GoCanvas MCP Server (read-only)
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| GOCANVAS_HOST | No | Bind host for HTTP transports. | 127.0.0.1 |
| GOCANVAS_PORT | No | Bind port for HTTP transports. | 8000 |
| GOCANVAS_TIMEOUT | No | HTTP timeout in seconds for GoCanvas API requests. | 30 |
| MCP_GATEWAY_KEYS | No | Comma-separated list of accepted secrets for the gateway key check. Used for HTTP transports; multiple keys allow rotation without downtime. Generate with openssl rand -base64 32. | |
| GOCANVAS_BASE_URL | No | Base URL for the GoCanvas API. | https://api.gocanvas.com/api/v3 |
| GOCANVAS_PASSWORD | No | Password for HTTP Basic authentication with GoCanvas. | |
| GOCANVAS_USERNAME | No | Username for HTTP Basic authentication with GoCanvas. | |
| GOCANVAS_API_TOKEN | No | Static bearer token for GoCanvas API authentication. | |
| GOCANVAS_CLIENT_ID | No | GoCanvas OAuth client ID, used with GOCANVAS_CLIENT_SECRET for client-credentials authentication. | |
| GOCANVAS_SECRET_ID | No | AWS Secrets Manager secret name or ARN whose JSON body may hold client_id, client_secret, scope, gateway_keys. Takes priority over individual environment variables. | |
| GOCANVAS_TRANSPORT | No | Transport protocol: stdio (default), streamable-http, or sse. | stdio |
| MCP_GATEWAY_HEADER | No | Header the gateway secret is read from (default x-mcp-key). Never set to Authorization. | x-mcp-key |
| GOCANVAS_OAUTH_SCOPE | No | Optional OAuth scope to request for server-side OAuth. | |
| GOCANVAS_ALLOWED_HOSTS | No | Comma-separated list of allowed Host headers for DNS-rebinding protection. Defaults to localhost only. | |
| GOCANVAS_CLIENT_SECRET | No | GoCanvas OAuth client secret, used with GOCANVAS_CLIENT_ID for client-credentials authentication. | |
| GOCANVAS_JSON_RESPONSE | No | When true, the server returns JSON instead of an SSE stream. Required for Lambda. | true |
| GOCANVAS_SECRET_REGION | No | AWS region for the Secrets Manager secret. Defaults to AWS_REGION. | |
| GOCANVAS_STATELESS_HTTP | No | When true, no per-session state is maintained between HTTP requests. Required for Lambda. | true |
| GOCANVAS_ALLOWED_ORIGINS | No | Comma-separated list of allowed Origin headers for DNS-rebinding protection. | |
| GOCANVAS_ALLOW_PASSTHROUGH | No | When true, the incoming Authorization header is forwarded verbatim to the GoCanvas API. Off by default to prevent caller override. | false |
| GOCANVAS_REQUIRE_GATEWAY_KEY | No | When true, the endpoint returns 503 if no gateway keys are configured. Set false only for local development bound to loopback. | true |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_formsB | List all Forms in the company. Args: page: Optional page number for pagination. |
| get_formA | Retrieve a single Form (including its full definition) by id. Args: form_id: The identifier of the Form. |
| list_form_assigned_usersC | List the Users assigned to a Form. Args: form_id: The identifier of the Form. |
| list_form_shared_departmentsC | List the Departments a Form is shared with. Args: form_id: The identifier of the Form. |
| list_submissionsA | List Submissions for a Form. Args: form_id: Required. The identifier for the Form associated with the Submissions. page: Optional page number for pagination. department_id: Filter by the Department associated with the Submission. user_id: Filter by the User who created the Submission. status: Status filter. One of: all, completed, deleted, in-progress, overdue, rejected, handed-off, assigned, unassigned, custom, saved-to-cloud, unfinished. hand_off: Workflow handoff state name (required when status is "handed-off"). custom_status: Custom status label (required when status is "custom"). start_date: DateTime lower bound for the Submission created_at. end_date: DateTime upper bound for the Submission created_at. |
| get_submissionA | Retrieve a single Submission (including its values) by GUID. Args: submission_id: The Submission GUID. |
| list_submission_revisionsC | List the revision history of a Submission. Args: submission_id: The identifier of the Submission. page: Optional page number for pagination. |
| get_submission_valueB | Retrieve a single Value from a Submission (e.g. a media field). Args: submission_id: The Submission GUID. value_id: The identifier of the Value within the Submission. |
| list_form_reportsB | List the Report definitions associated with a Form. Args: form_id: The identifier of the Form. page: Optional page number for pagination. |
| get_form_reportB | Retrieve a single Report definition (including its full definition file) for a Form. Args: form_id: The identifier of the Form. report_id: The identifier of the Report definition. |
| get_submission_default_pdfC | Download the default Report PDF for a Submission and return its bytes inline as base64. Args: submission_id: The identifier of the Submission. |
| get_submission_report_pdfB | Generate and download a specific Report PDF for a Submission by Report id. Args: submission_id: The identifier of the Submission. report_id: The identifier of the Report definition to render. |
| get_submission_standard_pdfC | Download the Standard Report PDF for a Submission and return its bytes inline as base64. Args: submission_id: The identifier of the Submission. |
| list_reference_dataA | List all Reference Data resources in the company. |
| get_reference_dataA | Retrieve a single Reference Data resource by id. Args: reference_data_id: The identifier of the Reference Data resource. |
| refresh_oauth_tokenA | Fetch a fresh OAuth bearer token from /oauth/token (client-credentials grant). Requires GOCANVAS_CLIENT_ID and GOCANVAS_CLIENT_SECRET to be configured. The token is cached and used automatically for subsequent API calls; call this to force a refresh (e.g. after a 401). Returns token metadata with the access token masked for safety. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 16 tools
Each tool targets a distinct resource or operation: forms, submissions, reference data, PDFs, and OAuth. No overlapping purposes; descriptions clearly differentiate.
All tools follow a consistent verb_noun pattern in snake_case (e.g., list_forms, get_submission). No deviations or mixed conventions.
16 tools cover the read-only surface of forms, submissions, reports, reference data, and PDFs. The count is well-scoped for the server's purpose.
The tool set provides full read coverage for the domain: listing and getting forms, submissions, reports, reference data, plus PDF downloads. No obvious gaps remain.