AutotaskCAUTION
MCP server for Kaseya Autotask PSA — 39 tools for companies, tickets, projects, time entries, and more
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/WYRE-AI/autotask-mcp/actions/workflows/release.yml) [](https://codecov.io/gh/WYRE-AI/autotask-mcp) [](https://opensource.org/licenses/Apache-2.0) [](https://nodejs.org/)
Give your AI assistant direct access to Autotask. Search tickets, create time entries, look up companies, manage projects — all through natural language. No more copy-pasting between browser tabs and chat windows.
This is a Model Context Protocol (MCP) server that connects Claude (or any MCP-compatible AI) to your Autotask PSA environment. Your AI assistant gets 101 tools covering the operations MSP teams use daily: ticket triage, time logging, company lookups, project management, billing review, and more.
If you run an MSP on Autotask and you're tired of the context-switching tax, this is for you.
Part of the [MSP Claude Plugins](https://github.com/WYRE-AI/msp-claude-plugins) ecosystem — a growing suite of AI integrations for the MSP stack including Datto RMM, IT Glue, HaloPSA, ConnectWise Automate, NinjaOne, Huntress, and more. Built by MSPs, for MSPs.
One-Click Deployment
[](https://clou
9b120d27ca67OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add autotask-mcp:0.0.0 --env AUTOTASK_SECRET=${AUTOTASK_SECRET} --env AUTOTASK_INTEGRATION_CODE=${AUTOTASK_INTEGRATION_CODE} -- docker run -i --rm ghcr.io/wyre-ai/autotask-mcp:0.0.0:NoneExposed tools (113)
71 read · 36 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
autotask_create_company | write | Create new company record |
autotask_create_company_note | write | Create a new note for a company |
autotask_create_contact | write | Create new contact record |
autotask_create_contract | write | Create a new Contract in Autotask. Field names match the Autotask REST API exactly. status: 1=In Effect, 0=Inactive. Dates are ISO format (YYYY-MM-DD). |
autotask_create_contract_service | write | Add a ContractService (service line item) to an existing Contract. |
autotask_create_contracts_bulk | write | Create multiple contract shells (header records, no service lines) in one call — e.g. onboarding a customer with several location-based contracts. Shells are created one at a time; a failure on one shell does not stop the rest, and each item reports its own success or error. |
autotask_create_expense_item | write | Create an expense item on an existing expense report |
autotask_create_expense_report | write | Create a new expense report |
autotask_create_opportunity | write | Create a new sales opportunity in Autotask |
autotask_create_phase | write | Create a new phase in an Autotask project |
autotask_create_project | write | Create a new project in Autotask |
autotask_create_project_note | write | Create a new note for a project |
autotask_create_quote | write | Create a new quote |
autotask_create_quote_item | write | Create a line item on a quote. Set exactly ONE item reference (serviceID, productID, or serviceBundleID). Required: quoteId, quantity. Defaults: unitDiscount=0, lineDiscount=0, percentageDiscount=0, isOptional=false. |
autotask_create_service_call | write | Create a new service call in Autotask. Service calls are used to schedule and plan work on tickets. |
autotask_create_service_call_ticket | write | Link a ticket to a service call. This associates the ticket with the service call for scheduling purposes. |
autotask_create_service_call_ticket_resource | write | Assign a resource (technician) to a service call ticket. |
autotask_create_task | write | Create a new task in Autotask |
autotask_create_ticket | write | Create new ticket record |
autotask_create_ticket_attachment | write | Upload a file attachment to an existing ticket. The file content must be passed as a base64-encoded string in the |
autotask_create_ticket_charge | write | Create charge on ticket for materials, costs, or expenses. |
autotask_create_ticket_checklist_item | write | Add a new checklist item to a ticket. |
autotask_create_ticket_note | write | Create a new note for a ticket |
autotask_create_time_entry | write | Create a time entry in Autotask. Can be tied to a ticket or task, OR created as |
autotask_delete_quote_item | destructive | ⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently deletes a quote item |
autotask_delete_service_call | destructive | ⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently deletes a service call |
autotask_delete_service_call_ticket | destructive | ⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently removes a ticket |
autotask_delete_service_call_ticket_resource | destructive | ⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently removes a resource |
autotask_delete_ticket_charge | destructive | ⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently deletes a ticket charge |
autotask_delete_ticket_checklist_item | destructive | ⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently deletes a checklist item |
autotask_execute_tool | write | Execute any Autotask tool by name. Use after discovering tools via autotask_list_category_tools. |
autotask_get_billing_item | read | Get detailed information for a specific billing item by ID |
autotask_get_company_note | read | Get a specific company note by company ID and note ID |
autotask_get_company_site_configuration | read | Get company site configuration records. Call first to discover available fields. |
autotask_get_contract | read | Get a single contract by ID (header fields only, no service lines) |
autotask_get_expense_report | read | Get a specific expense report by ID |
autotask_get_field_info | read | Get field definitions for an Autotask entity type, including picklist values. Useful for discovering valid values for any picklist field. |
autotask_get_invoice_details | read | Get a single Autotask invoice with its nested line items (billing items posted to the invoice). Use for finance workflows that need to see exactly what an invoice contains. |
autotask_get_opportunity | read | Get a specific opportunity by ID |
autotask_get_product | read | Get a specific product by ID |
autotask_get_project_note | read | Get a specific project note by project ID and note ID |
autotask_get_quote | read | Get a specific quote by ID |
autotask_get_quote_item | read | Get a specific quote item by ID |
autotask_get_service | read | Get a specific service by ID |
autotask_get_service_bundle | read | Get a specific service bundle by ID |
autotask_get_service_call | read | Get a specific service call by ID |
autotask_get_ticket_charge | read | Get a specific ticket charge by ID |
autotask_get_ticket_details | read | Get full ticket details including notes, time entries, and custom fields. |
autotask_get_ticket_history | read | Get a single ticket history entry by ID. Each entry records one audited change to a ticket field (who, when, before/after). |
autotask_get_ticket_note | read | Get a specific ticket note by ticket ID and note ID |
autotask_list_categories | read | List available tool categories. Use this to discover what types of Autotask operations are available before loading specific tools. |
autotask_list_category_tools | read | List tools in a specific category with full schemas. Use after autotask_list_categories to see available tools and their parameters. |
autotask_list_expiring_contracts | read | List contracts whose end date falls within the next N days (expiring-contracts report). Optionally include already-expired contracts, and scope to one company or the whole org. |
autotask_list_phases | read | List phases for a project in Autotask |
autotask_list_queues | read | List all available ticket queues in Autotask. Use this to find queue IDs for filtering tickets by queue. |
autotask_list_ticket_priorities | read | List all available ticket priorities in Autotask. Use this to find priority values for filtering or creating tickets. |
autotask_list_ticket_statuses | read | List all available ticket statuses in Autotask. Use this to find status values for filtering or creating tickets. |
autotask_router | read | Intelligent tool router - describe what you want to do and get the right tool suggestion with pre-filled parameters. Use this when unsure which tool to call. |
autotask_search_billing_item_approval_levels | read | Search for billing item approval levels. These describe multi-level approval records for Autotask time entries, enabling visibility into tiered approval workflows. |
autotask_search_billing_items | read | Search for billing items in Autotask. Billing items represent approved and posted billable items from the |
autotask_search_companies | read | Search companies by name or status. Max 200/page. |
autotask_search_company_notes | read | Search for notes on a specific company. Iterating across many companies trips Autotask\ |
autotask_search_configuration_items | read | Search for configuration items in Autotask with optional filters |
autotask_search_contacts | read | Search contacts by name, email, or company. Max 200/page. |
autotask_search_contract_service_bundle_units | read | Billed unit rows for bundle lines on a contract (ContractServiceBundleUnits), active on a given day (default today). Read-only. |
autotask_search_contract_service_bundles | read | List the service-bundle line items on a contract (ContractServiceBundles). Read-only. |
autotask_search_contract_service_units | read | Billed unit rows for a contract (ContractServiceUnits): the quantity and contract price of each service line over a date range. By default returns only rows active today, i.e. what is currently being invoiced. Read-only. |
autotask_search_contract_services | read | List the service line items on a contract (ContractServices): which catalog services are on the contract and at what contract-specific unit price. Read-only. Pair with autotask_search_contract_service_units for billed quantities, or use autotask_get_contract_recurring_lines for both in one call. |
autotask_search_contracts | read | Search for contracts in Autotask with optional filters |
autotask_search_expense_reports | read | Search for expense reports with optional filters |
autotask_search_invoices | read | Search for invoices in Autotask with optional filters |
autotask_search_opportunities | read | Search for opportunities with optional filters |
autotask_search_products | read | Search for products with optional filters |
autotask_search_project_notes | read | Search for notes on a specific project. Fan-out across many projects trips Autotask\ |
autotask_search_projects | read | Search for projects in Autotask. Returns 25 results per page by default. Use page parameter for more results. |
autotask_search_quote_items | read | Search for quote items, typically filtered by quote ID |
autotask_search_quotes | read | Search for quotes with optional filters |
autotask_search_resources | read | Search for resources (users) in Autotask. Returns 25 results per page by default. Use page parameter for more results. |
autotask_search_service_bundles | read | Search for service bundles with optional filters |
autotask_search_service_call_ticket_resources | read | Search for resource (technician) assignments on service call tickets. |
autotask_search_service_call_tickets | read | Search for ticket associations on service calls. Use this to find which tickets are linked to a service call, or which service calls contain a specific ticket. |
autotask_search_service_calls | read | Search for service calls in Autotask. Filter by company, status, or date range. |
autotask_search_services | read | Search for services with optional filters |
autotask_search_tasks | read | Search for tasks in Autotask. Returns 25 results per page by default. Use page parameter for more results. |
autotask_search_ticket_attachments | read | Search for attachments on a specific ticket. Each parent triggers a separate query — scope the parent ticket list before iterating. |
autotask_search_ticket_charges | read | Search ticket charges (materials, costs, expenses). Provide ticketId for best performance. Max 10 if unfiltered. |
autotask_search_ticket_checklist_items | read | List all checklist items on a ticket, including their completion status. Checklist items are a sub-resource of a ticket and cannot be queried without a ticket ID. |
autotask_search_ticket_history | read | Get the audit trail of field changes for a ticket (status transitions, assignment changes, priority edits, etc.). Use this to answer questions like |
autotask_search_ticket_note_attachments | read | Search for attachments on a specific ticket note — use this when autotask_search_ticket_notes returns a note with an empty or unhelpful |
autotask_search_ticket_notes | read | Search for notes on a specific ticket. Iterating across many tickets trips Autotask\ |
autotask_search_tickets | read | Search tickets by company, queue, status, priority. Use autotask_get_ticket_details for full data. Max 500/page. |
autotask_search_time_entries | read | Search for time entries in Autotask. Returns 25 results per page by default. Time entries can be filtered by resource, ticket, task, date range, or approval status. Use approvalStatus= |
autotask_test_connection | read | Test Autotask API connection |
autotask_update_company | write | Update company record. invoiceTemplateID sets payment terms (103=Due on Receipt, 104=NET 30). Billing address fields separate from regular address. |
autotask_update_company_site_configuration | write | Update company site configuration. Fields are tenant-defined; call get first. |
autotask_update_contact | write | Update contact record. Only provided fields are changed. |
autotask_update_contract | write | Update an existing Contract in Autotask (PATCH). Pass only fields you want to change; everything except id is optional. status: 1=In Effect, 0=Inactive. |
autotask_update_contract_service | write | Update an existing ContractService line on a Contract. Pass only fields you want to change. |
autotask_update_project | write | Update an existing project in Autotask. Only the fields you provide will be updated. Common use case: set status=5 to mark a project Complete. |
autotask_update_quote_item | write | Update an existing quote item (quantity, price, etc.) |
autotask_update_service_call | write | Update an existing service call. Use this to change status, times, or description. To complete/close a service call, set complete: true or update the status. |
autotask_update_ticket | write | Update ticket record. Only provided fields are changed. |
autotask_update_ticket_charge | write | Update an existing ticket charge. Only fields provided will be changed. |
autotask_update_ticket_checklist_item | write | Update a checklist item on a ticket — edit text, mark complete/incomplete, or change position. |
client_name | read | Filter to a specific client (optional) |
date_range | read | Date range to cover, e.g. |
escalation-summary | read | Summarize a ticket |
issue_description | read | Plain-language description of the issue |
new-ticket-draft | read | Draft a well-structured Autotask ticket from a plain-language issue description |
priority | read | Filter by priority level (optional) |
ticket-queue-review | read | Review open ticket queue, group by priority, and flag SLA risks |
ticket_id | read | The Autotask ticket ID to summarize |
weekly-sla-report | read | Generate a weekly SLA performance summary for a client |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (20)
const BASE = `http://127.0.0.1:${PORT}`;autotask_delete_quote_item, autotask_delete_service_call, autotask_delete_service_call_ticket, autotask_delete_service_call_ticket_resource, autotask_delete_ticket_charge, autotask_delete_ticket_check
.mcpbignore
.releaserc.json
.rules
import packageJson from '../../package.json';
['path traversal', '/Companies/../../etc/passwd'],
const res = await fetch(`http://127.0.0.1:${port}/mcp`, {const res = await fetch(`http://127.0.0.1:${port}/mcp`, {const res = await fetch(`http://127.0.0.1:${port}/health`);@modelcontextprotocol/node, @modelcontextprotocol/server, winston, zod, @anthropic-ai/mcpb, @eslint/js, @modelcontextprotocol/client, @modelcontextprotocol/ext-apps
@astrojs/starlight, astro, sharp
Currently the autotask-mcp server only supports stdio transport which requires running on the same machine or using mcp-proxy. Users want HTTP Streamable transport to access the server remotely withou
1. **Review maxRecords casing fix (Task 24)**: Confirm all 214 entity files in autotask-node/src/entities/ use 'maxRecords' (lowercase 'm') in list() methods by running grep -r 'MaxRecords' src/entiti
cat .env # For CLI usage
cat .env # For CLI usage
Create config.ts in utils/ to load and validate environment variables: AUTOTASK_USERNAME, AUTOTASK_SECRET, AUTOTASK_INTEGRATION_CODE (required), AUTOTASK_API_URL, MCP_SERVER_NAME, MCP_SERVER_VERSION,
cat .env # For CLI usage
* load .env file at startup for credential configuration ([192c52c](https://github.com/asachs01/autotask-mcp/commit/192c52c5b324ee485c07c73367f7d80da236f73d))
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.0/install.sh | bash
Gates applied: no_behavioural_pass.
9b120d27ca67full audit observations/trust-audit/mcp-server/asachs01__autotask.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 9b120d27ca67 | CAUTION | B | 89 | first audit |
Questions
What is the Autotask MCP server?
MCP server for Kaseya Autotask PSA — 39 tools for companies, tickets, projects, time entries, and more
What tools does Autotask expose?
113 in total: 71 read-only, 36 that write, and 6 that can delete or overwrite (autotask_delete_quote_item, autotask_delete_service_call, autotask_delete_service_call_ticket, autotask_delete_service_call_ticket_resource, autotask_delete_ticket_charge). Every one is listed on this page with its risk.
Is Autotask safe to connect to an agent?
With care. The audit graded it B (89/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Autotask need?
It reads AUTH_MODE, AUTOTASK_INTEGRATION_CODE, AUTOTASK_SECRET, CONDUIT_S2S_SECRET, X_API_KEY and X_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Autotask run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as website at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (9b120d27ca67), read on 2026-10-09. The repository is watched and re-audited when it changes.