Acquia MCP Source — LIVE Probe Results & Demo-Time Runbook¶
Probed: 2026-04-25 ~22:00 UTC (T-minus < 24h to Denver)
Endpoint: https://168068-f4c1d2ce-9d86-4a40-bc18-18410e23e0bd.cms.acquia.site/mcp
Realm: Source.BlueflyAgents.com (Acquia prod, x-ah-environment: prod, served by Acquia Platform CDN)
Status: GREEN — endpoint live, OAuth 2.1 fully wired¶
| Check | Result |
|---|---|
POST /mcp initialize (no auth) |
HTTP 401 with WWW-Authenticate: Bearer realm="Source.BlueflyAgents.com" resource_metadata=... (correct per MCP spec 2025-06-18) |
| Inspector CLI probe | 401 (expected, confirms transport + content negotiation works) |
/.well-known/oauth-protected-resource/mcp |
200, valid JSON, points to authorization_servers |
/.well-known/oauth-authorization-server |
200, valid JSON, full RFC 8414 metadata |
| Dynamic Client Registration (RFC 7591) | endpoint exposed at /oauth/register |
| PKCE | S256 + plain supported |
| Grants | authorization_code, refresh_token, client_credentials |
Scopes available (20)¶
canvas:asset_library, canvas:brand_kit, canvas:js_component, canvas:media:image:create, canvas:media:view, canvas:page:create, canvas:page:delete, canvas:page:edit, canvas:page:read, content:administer, content_type:administer, content_type:administer_fields, media:administer, media_type:administer, member, menu:administer, page_template:administer, site_settings:administer, taxonomy:administer, taxonomy:administer_fields
Demo-day flow (3 commands, T-30 in hotel)¶
Step 1 — register a service-to-service client (creates OAuth client; do once, save to 1Password)¶
registration=$(curl -sS -X POST https://168068-f4c1d2ce-9d86-4a40-bc18-18410e23e0bd.cms.acquia.site/oauth/register \
-H "Content-Type: application/json" \
-d '{
"client_name": "bluefly-cc-demo",
"grant_types": ["client_credentials"],
"token_endpoint_auth_method": "client_secret_basic"
}')
Response will contain client_id + client_secret. Pipe both into 1Password:
op item create --category=login --title="Acquia Demo MCP Client" --vault=blueflyio \
username="$(printf '%s' "$registration" | jq -r .client_id)" \
password="$(printf '%s' "$registration" | jq -r .client_secret)"
unset registration
Step 2 — get a bearer¶
TOKEN=$(curl -sS -u "$ACQUIA_MCP_CLIENT_ID:$ACQUIA_MCP_CLIENT_SECRET" \
-X POST https://168068-f4c1d2ce-9d86-4a40-bc18-18410e23e0bd.cms.acquia.site/oauth/token \
-d "grant_type=client_credentials&scope=canvas:page:read content:administer media:administer taxonomy:administer" \
| jq -r .access_token)
Step 3 — call MCP¶
curl -sS -X POST https://168068-f4c1d2ce-9d86-4a40-bc18-18410e23e0bd.cms.acquia.site/mcp \
-H "Authorization: Bearer $TOKEN" \
-H "Accept: application/json,text/event-stream" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
Or open the Inspector with the bearer:
npx -y @modelcontextprotocol/inspector https://168068-f4c1d2ce-9d86-4a40-bc18-18410e23e0bd.cms.acquia.site/mcp \
--transport http \
--header "Authorization: Bearer $TOKEN"
Why this matters for the Acquia conversation¶
This is a textbook MCP-over-HTTP-with-OAuth-2.1 deployment. Acquia has shipped the full RFC 9728 / RFC 8414 / RFC 7591 chain. Anything ContextControl.ai builds on top of this can use the standard discovery + registration handshake — no custom Acquia integration code, no API keys, no shared secrets baked into the client.
Pitch line: "You already speak OAuth-resource-metadata. We govern the agents that hold those tokens, with Cedar/contractplane policy gates between the bearer and the tool call."
What still needs you (cannot be automated)¶
- Decide which
client_nameto register (this becomes visible in admin/audit on Acquia side). - Decide which scopes to request — start narrow (
canvas:page:read+content:administer), broaden if demo needs. - Have your 1Password account unlocked at T-60.
- Verify the laptop wifi can reach
*.cms.acquia.sitefrom the venue (run Step 3 from the venue at T-30).