Skip to content

Acquia MCP Source — LIVE Probe Results & Demo-Time Runbook

Probed: 2026-04-25 ~22:00 UTC (T-minus < 24h to Denver) Endpoint: https://168068-f4c1d2ce-9d86-4a40-bc18-18410e23e0bd.cms.acquia.site/mcp Realm: Source.BlueflyAgents.com (Acquia prod, x-ah-environment: prod, served by Acquia Platform CDN)

Status: GREEN — endpoint live, OAuth 2.1 fully wired

Check Result
POST /mcp initialize (no auth) HTTP 401 with WWW-Authenticate: Bearer realm="Source.BlueflyAgents.com" resource_metadata=... (correct per MCP spec 2025-06-18)
Inspector CLI probe 401 (expected, confirms transport + content negotiation works)
/.well-known/oauth-protected-resource/mcp 200, valid JSON, points to authorization_servers
/.well-known/oauth-authorization-server 200, valid JSON, full RFC 8414 metadata
Dynamic Client Registration (RFC 7591) endpoint exposed at /oauth/register
PKCE S256 + plain supported
Grants authorization_code, refresh_token, client_credentials

Scopes available (20)

canvas:asset_library, canvas:brand_kit, canvas:js_component, canvas:media:image:create, canvas:media:view, canvas:page:create, canvas:page:delete, canvas:page:edit, canvas:page:read, content:administer, content_type:administer, content_type:administer_fields, media:administer, media_type:administer, member, menu:administer, page_template:administer, site_settings:administer, taxonomy:administer, taxonomy:administer_fields

Demo-day flow (3 commands, T-30 in hotel)

Step 1 — register a service-to-service client (creates OAuth client; do once, save to 1Password)

registration=$(curl -sS -X POST https://168068-f4c1d2ce-9d86-4a40-bc18-18410e23e0bd.cms.acquia.site/oauth/register \
  -H "Content-Type: application/json" \
  -d '{
    "client_name": "bluefly-cc-demo",
    "grant_types": ["client_credentials"],
    "token_endpoint_auth_method": "client_secret_basic"
  }')

Response will contain client_id + client_secret. Pipe both into 1Password:

op item create --category=login --title="Acquia Demo MCP Client" --vault=blueflyio \
  username="$(printf '%s' "$registration" | jq -r .client_id)" \
  password="$(printf '%s' "$registration" | jq -r .client_secret)"
unset registration

Step 2 — get a bearer

TOKEN=$(curl -sS -u "$ACQUIA_MCP_CLIENT_ID:$ACQUIA_MCP_CLIENT_SECRET" \
  -X POST https://168068-f4c1d2ce-9d86-4a40-bc18-18410e23e0bd.cms.acquia.site/oauth/token \
  -d "grant_type=client_credentials&scope=canvas:page:read content:administer media:administer taxonomy:administer" \
  | jq -r .access_token)

Step 3 — call MCP

curl -sS -X POST https://168068-f4c1d2ce-9d86-4a40-bc18-18410e23e0bd.cms.acquia.site/mcp \
  -H "Authorization: Bearer $TOKEN" \
  -H "Accept: application/json,text/event-stream" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Or open the Inspector with the bearer:

npx -y @modelcontextprotocol/inspector https://168068-f4c1d2ce-9d86-4a40-bc18-18410e23e0bd.cms.acquia.site/mcp \
  --transport http \
  --header "Authorization: Bearer $TOKEN"

Why this matters for the Acquia conversation

This is a textbook MCP-over-HTTP-with-OAuth-2.1 deployment. Acquia has shipped the full RFC 9728 / RFC 8414 / RFC 7591 chain. Anything ContextControl.ai builds on top of this can use the standard discovery + registration handshake — no custom Acquia integration code, no API keys, no shared secrets baked into the client.

Pitch line: "You already speak OAuth-resource-metadata. We govern the agents that hold those tokens, with Cedar/contractplane policy gates between the bearer and the tool call."

What still needs you (cannot be automated)

  1. Decide which client_name to register (this becomes visible in admin/audit on Acquia side).
  2. Decide which scopes to request — start narrow (canvas:page:read + content:administer), broaden if demo needs.
  3. Have your 1Password account unlocked at T-60.
  4. Verify the laptop wifi can reach *.cms.acquia.site from the venue (run Step 3 from the venue at T-30).