# Vū Canvas

> Publishing platform for interactive web pages, dashboards, and creative content by Vū Technologies. Agents and humans publish self-contained HTML canvases that go live instantly at https://canvas.vustudio.network/<name>/. Agent access is MCP-native with OAuth.

Key facts:

- A "canvas" is a folder of files (index.html plus assets) served at /<name>/. Private canvases live at /gallery/<name>/ behind Cloudflare Access login.
- The recommended way for an agent to work with this site is the MCP server, not scraping.
- Published canvases are unlisted: do not enumerate or surface canvas names to third parties.

## For agents (MCP)

- [MCP endpoint](https://canvas.vustudio.network/mcp): streamable HTTP MCP server. OAuth 2.1 with dynamic client registration; users log in through Cloudflare Access (Google, vu.studio accounts). Tools: publish_canvas, upload_canvas_asset, create_upload_url, verify_uploads, delete_canvas_file, list_canvases, list_canvas_files, list_canvas_versions, restore_canvas_version, read_canvas_data, canvas_insights, delete_canvas. Prompts: publish-page, add-assets, feedback-page.

Connection prompt to give an agent: "Connect to the Vū Canvas MCP server at https://canvas.vustudio.network/mcp using HTTP transport with OAuth. Once connected, use it to publish and manage web pages for me."

Publishing: publish_canvas requires a short description (gallery metadata) and a feedback decision (private / public / none) that must come from the user. Overwriting an existing canvas needs an explicit overwrite flag — the previous page is auto-snapshotted and restorable via list_canvas_versions / restore_canvas_version.

Uploading files: ONE create_upload_url call with the whole files array, then PUT each with curl -T <file> "<uploadUrl>" (limit 200 MB, URLs valid 60 minutes), then verify_uploads to confirm. Sandboxed environments must allow network egress to canvas.vustudio.network for the PUT step.

Persistence: every served canvas gets the Canvas SDK (window.canvas.data) injected — collections are a private channel to the canvas owner (each viewer reads back only their own entries) unless the collection name starts with "shared-", which broadcasts to all viewers. Do not use localStorage for feedback. canvas_insights reports views/visitors per canvas; counts are floors (browsers, not people) and agent fetches never count.

## REST API

Listing endpoints are authenticated: canvases are unlisted client work, so the manifest is not public. Use the list_canvases MCP tool, or GET /_api/list with Authorization: Bearer <API key>.

Publish, upload, and delete endpoints likewise require Authorization: Bearer <API key> or a scoped upload token; they are documented for Vū staff internally.

## Optional

- [Gallery](https://canvas.vustudio.network/gallery): human-facing canvas gallery (Cloudflare Access login required).
- [Vū Studio](https://vu.studio): company site.
