Atlas / MCP servers / asachs01 / Autotask

AutotaskCAUTION

mcp/asachs01/autotask

MCP server for Kaseya Autotask PSA — 39 tools for companies, tickets, projects, time entries, and more

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
113 71r · 36w · 6d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
57
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/WYRE-AI/autotask-mcp/actions/workflows/release.yml) [](https://codecov.io/gh/WYRE-AI/autotask-mcp) [](https://opensource.org/licenses/Apache-2.0) [](https://nodejs.org/)

Give your AI assistant direct access to Autotask. Search tickets, create time entries, look up companies, manage projects — all through natural language. No more copy-pasting between browser tabs and chat windows.

This is a Model Context Protocol (MCP) server that connects Claude (or any MCP-compatible AI) to your Autotask PSA environment. Your AI assistant gets 101 tools covering the operations MSP teams use daily: ticket triage, time logging, company lookups, project management, billing review, and more.

If you run an MSP on Autotask and you're tired of the context-switching tax, this is for you.

Part of the [MSP Claude Plugins](https://github.com/WYRE-AI/msp-claude-plugins) ecosystem — a growing suite of AI integrations for the MSP stack including Datto RMM, IT Glue, HaloPSA, ConnectWise Automate, NinjaOne, Huntress, and more. Built by MSPs, for MSPs.

One-Click Deployment

[](https://clou

Read from source at commit 9b120d27ca67OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add autotask-mcp:0.0.0 --env AUTOTASK_SECRET=${AUTOTASK_SECRET} --env AUTOTASK_INTEGRATION_CODE=${AUTOTASK_INTEGRATION_CODE} -- docker run -i --rm ghcr.io/wyre-ai/autotask-mcp:0.0.0:None
03

Exposed tools (113)

71 read · 36 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
autotask_create_companywriteCreate new company record
autotask_create_company_notewriteCreate a new note for a company
autotask_create_contactwriteCreate new contact record
autotask_create_contractwriteCreate a new Contract in Autotask. Field names match the Autotask REST API exactly. status: 1=In Effect, 0=Inactive. Dates are ISO format (YYYY-MM-DD).
autotask_create_contract_servicewriteAdd a ContractService (service line item) to an existing Contract.
autotask_create_contracts_bulkwriteCreate multiple contract shells (header records, no service lines) in one call — e.g. onboarding a customer with several location-based contracts. Shells are created one at a time; a failure on one shell does not stop the rest, and each item reports its own success or error.
autotask_create_expense_itemwriteCreate an expense item on an existing expense report
autotask_create_expense_reportwriteCreate a new expense report
autotask_create_opportunitywriteCreate a new sales opportunity in Autotask
autotask_create_phasewriteCreate a new phase in an Autotask project
autotask_create_projectwriteCreate a new project in Autotask
autotask_create_project_notewriteCreate a new note for a project
autotask_create_quotewriteCreate a new quote
autotask_create_quote_itemwriteCreate a line item on a quote. Set exactly ONE item reference (serviceID, productID, or serviceBundleID). Required: quoteId, quantity. Defaults: unitDiscount=0, lineDiscount=0, percentageDiscount=0, isOptional=false.
autotask_create_service_callwriteCreate a new service call in Autotask. Service calls are used to schedule and plan work on tickets.
autotask_create_service_call_ticketwriteLink a ticket to a service call. This associates the ticket with the service call for scheduling purposes.
autotask_create_service_call_ticket_resourcewriteAssign a resource (technician) to a service call ticket.
autotask_create_taskwriteCreate a new task in Autotask
autotask_create_ticketwriteCreate new ticket record
autotask_create_ticket_attachmentwriteUpload a file attachment to an existing ticket. The file content must be passed as a base64-encoded string in the
autotask_create_ticket_chargewriteCreate charge on ticket for materials, costs, or expenses.
autotask_create_ticket_checklist_itemwriteAdd a new checklist item to a ticket.
autotask_create_ticket_notewriteCreate a new note for a ticket
autotask_create_time_entrywriteCreate a time entry in Autotask. Can be tied to a ticket or task, OR created as
autotask_delete_quote_itemdestructive⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently deletes a quote item
autotask_delete_service_calldestructive⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently deletes a service call
autotask_delete_service_call_ticketdestructive⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently removes a ticket
autotask_delete_service_call_ticket_resourcedestructive⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently removes a resource
autotask_delete_ticket_chargedestructive⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently deletes a ticket charge
autotask_delete_ticket_checklist_itemdestructive⚠ DESTRUCTIVE — IRREVERSIBLE. Permanently deletes a checklist item
autotask_execute_toolwriteExecute any Autotask tool by name. Use after discovering tools via autotask_list_category_tools.
autotask_get_billing_itemreadGet detailed information for a specific billing item by ID
autotask_get_company_notereadGet a specific company note by company ID and note ID
autotask_get_company_site_configurationreadGet company site configuration records. Call first to discover available fields.
autotask_get_contractreadGet a single contract by ID (header fields only, no service lines)
autotask_get_expense_reportreadGet a specific expense report by ID
autotask_get_field_inforeadGet field definitions for an Autotask entity type, including picklist values. Useful for discovering valid values for any picklist field.
autotask_get_invoice_detailsreadGet a single Autotask invoice with its nested line items (billing items posted to the invoice). Use for finance workflows that need to see exactly what an invoice contains.
autotask_get_opportunityreadGet a specific opportunity by ID
autotask_get_productreadGet a specific product by ID
autotask_get_project_notereadGet a specific project note by project ID and note ID
autotask_get_quotereadGet a specific quote by ID
autotask_get_quote_itemreadGet a specific quote item by ID
autotask_get_servicereadGet a specific service by ID
autotask_get_service_bundlereadGet a specific service bundle by ID
autotask_get_service_callreadGet a specific service call by ID
autotask_get_ticket_chargereadGet a specific ticket charge by ID
autotask_get_ticket_detailsreadGet full ticket details including notes, time entries, and custom fields.
autotask_get_ticket_historyreadGet a single ticket history entry by ID. Each entry records one audited change to a ticket field (who, when, before/after).
autotask_get_ticket_notereadGet a specific ticket note by ticket ID and note ID
autotask_list_categoriesreadList available tool categories. Use this to discover what types of Autotask operations are available before loading specific tools.
autotask_list_category_toolsreadList tools in a specific category with full schemas. Use after autotask_list_categories to see available tools and their parameters.
autotask_list_expiring_contractsreadList contracts whose end date falls within the next N days (expiring-contracts report). Optionally include already-expired contracts, and scope to one company or the whole org.
autotask_list_phasesreadList phases for a project in Autotask
autotask_list_queuesreadList all available ticket queues in Autotask. Use this to find queue IDs for filtering tickets by queue.
autotask_list_ticket_prioritiesreadList all available ticket priorities in Autotask. Use this to find priority values for filtering or creating tickets.
autotask_list_ticket_statusesreadList all available ticket statuses in Autotask. Use this to find status values for filtering or creating tickets.
autotask_routerreadIntelligent tool router - describe what you want to do and get the right tool suggestion with pre-filled parameters. Use this when unsure which tool to call.
autotask_search_billing_item_approval_levelsreadSearch for billing item approval levels. These describe multi-level approval records for Autotask time entries, enabling visibility into tiered approval workflows.
autotask_search_billing_itemsreadSearch for billing items in Autotask. Billing items represent approved and posted billable items from the
autotask_search_companiesreadSearch companies by name or status. Max 200/page.
autotask_search_company_notesreadSearch for notes on a specific company. Iterating across many companies trips Autotask\
autotask_search_configuration_itemsreadSearch for configuration items in Autotask with optional filters
autotask_search_contactsreadSearch contacts by name, email, or company. Max 200/page.
autotask_search_contract_service_bundle_unitsreadBilled unit rows for bundle lines on a contract (ContractServiceBundleUnits), active on a given day (default today). Read-only.
autotask_search_contract_service_bundlesreadList the service-bundle line items on a contract (ContractServiceBundles). Read-only.
autotask_search_contract_service_unitsreadBilled unit rows for a contract (ContractServiceUnits): the quantity and contract price of each service line over a date range. By default returns only rows active today, i.e. what is currently being invoiced. Read-only.
autotask_search_contract_servicesreadList the service line items on a contract (ContractServices): which catalog services are on the contract and at what contract-specific unit price. Read-only. Pair with autotask_search_contract_service_units for billed quantities, or use autotask_get_contract_recurring_lines for both in one call.
autotask_search_contractsreadSearch for contracts in Autotask with optional filters
autotask_search_expense_reportsreadSearch for expense reports with optional filters
autotask_search_invoicesreadSearch for invoices in Autotask with optional filters
autotask_search_opportunitiesreadSearch for opportunities with optional filters
autotask_search_productsreadSearch for products with optional filters
autotask_search_project_notesreadSearch for notes on a specific project. Fan-out across many projects trips Autotask\
autotask_search_projectsreadSearch for projects in Autotask. Returns 25 results per page by default. Use page parameter for more results.
autotask_search_quote_itemsreadSearch for quote items, typically filtered by quote ID
autotask_search_quotesreadSearch for quotes with optional filters
autotask_search_resourcesreadSearch for resources (users) in Autotask. Returns 25 results per page by default. Use page parameter for more results.
autotask_search_service_bundlesreadSearch for service bundles with optional filters
autotask_search_service_call_ticket_resourcesreadSearch for resource (technician) assignments on service call tickets.
autotask_search_service_call_ticketsreadSearch for ticket associations on service calls. Use this to find which tickets are linked to a service call, or which service calls contain a specific ticket.
autotask_search_service_callsreadSearch for service calls in Autotask. Filter by company, status, or date range.
autotask_search_servicesreadSearch for services with optional filters
autotask_search_tasksreadSearch for tasks in Autotask. Returns 25 results per page by default. Use page parameter for more results.
autotask_search_ticket_attachmentsreadSearch for attachments on a specific ticket. Each parent triggers a separate query — scope the parent ticket list before iterating.
autotask_search_ticket_chargesreadSearch ticket charges (materials, costs, expenses). Provide ticketId for best performance. Max 10 if unfiltered.
autotask_search_ticket_checklist_itemsreadList all checklist items on a ticket, including their completion status. Checklist items are a sub-resource of a ticket and cannot be queried without a ticket ID.
autotask_search_ticket_historyreadGet the audit trail of field changes for a ticket (status transitions, assignment changes, priority edits, etc.). Use this to answer questions like
autotask_search_ticket_note_attachmentsreadSearch for attachments on a specific ticket note — use this when autotask_search_ticket_notes returns a note with an empty or unhelpful
autotask_search_ticket_notesreadSearch for notes on a specific ticket. Iterating across many tickets trips Autotask\
autotask_search_ticketsreadSearch tickets by company, queue, status, priority. Use autotask_get_ticket_details for full data. Max 500/page.
autotask_search_time_entriesreadSearch for time entries in Autotask. Returns 25 results per page by default. Time entries can be filtered by resource, ticket, task, date range, or approval status. Use approvalStatus=
autotask_test_connectionreadTest Autotask API connection
autotask_update_companywriteUpdate company record. invoiceTemplateID sets payment terms (103=Due on Receipt, 104=NET 30). Billing address fields separate from regular address.
autotask_update_company_site_configurationwriteUpdate company site configuration. Fields are tenant-defined; call get first.
autotask_update_contactwriteUpdate contact record. Only provided fields are changed.
autotask_update_contractwriteUpdate an existing Contract in Autotask (PATCH). Pass only fields you want to change; everything except id is optional. status: 1=In Effect, 0=Inactive.
autotask_update_contract_servicewriteUpdate an existing ContractService line on a Contract. Pass only fields you want to change.
autotask_update_projectwriteUpdate an existing project in Autotask. Only the fields you provide will be updated. Common use case: set status=5 to mark a project Complete.
autotask_update_quote_itemwriteUpdate an existing quote item (quantity, price, etc.)
autotask_update_service_callwriteUpdate an existing service call. Use this to change status, times, or description. To complete/close a service call, set complete: true or update the status.
autotask_update_ticketwriteUpdate ticket record. Only provided fields are changed.
autotask_update_ticket_chargewriteUpdate an existing ticket charge. Only fields provided will be changed.
autotask_update_ticket_checklist_itemwriteUpdate a checklist item on a ticket — edit text, mark complete/incomplete, or change position.
client_namereadFilter to a specific client (optional)
date_rangereadDate range to cover, e.g.
escalation-summaryreadSummarize a ticket
issue_descriptionreadPlain-language description of the issue
new-ticket-draftreadDraft a well-structured Autotask ticket from a plain-language issue description
priorityreadFilter by priority level (optional)
ticket-queue-reviewreadReview open ticket queue, group by priority, and flag SLA risks
ticket_idreadThe Autotask ticket ID to summarize
weekly-sla-reportreadGenerate a weekly SLA performance summary for a client
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (7 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (20)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/smoke-dual-era.mjs:24
const BASE = `http://127.0.0.1:${PORT}`;
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
autotask_delete_quote_item, autotask_delete_service_call, autotask_delete_service_call_ticket, autotask_delete_service_call_ticket_resource, autotask_delete_ticket_charge, autotask_delete_ticket_check
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc.json
.releaserc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.rules
.rules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/utils/config.ts:13
import packageJson from '../../package.json';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/raw-request-security.test.ts:35
['path traversal', '/Companies/../../etc/passwd'],
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/http-cors.test.ts:50
const res = await fetch(`http://127.0.0.1:${port}/mcp`, {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/http-cors.test.ts:73
const res = await fetch(`http://127.0.0.1:${port}/mcp`, {
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/http-cors.test.ts:99
const res = await fetch(`http://127.0.0.1:${port}/health`);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/node, @modelcontextprotocol/server, winston, zod, @anthropic-ai/mcpb, @eslint/js, @modelcontextprotocol/client, @modelcontextprotocol/ext-apps
Why it matters. 24 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
website/package.json
@astrojs/starlight, astro, sharp
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.taskmaster/tasks/task_025.md:15
Currently the autotask-mcp server only supports stdio transport which requires running on the same machine or using mcp-proxy. Users want HTTP Streamable transport to access the server remotely withou
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.taskmaster/tasks/task_027.md:15
1. **Review maxRecords casing fix (Task 24)**: Confirm all 214 entity files in autotask-node/src/entities/ use 'maxRecords' (lowercase 'm') in list() methods by running grep -r 'MaxRecords' src/entiti
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.taskmaster/AGENT.md:345
cat .env                           # For CLI usage
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.taskmaster/CLAUDE.md:345
cat .env                           # For CLI usage
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.taskmaster/tasks/task_003.md:15
Create config.ts in utils/ to load and validate environment variables: AUTOTASK_USERNAME, AUTOTASK_SECRET, AUTOTASK_INTEGRATION_CODE (required), AUTOTASK_API_URL, MCP_SERVER_NAME, MCP_SERVER_VERSION,
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
AGENTS.md:345
cat .env                           # For CLI usage
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:435
* load .env file at startup for credential configuration ([192c52c](https://github.com/asachs01/autotask-mcp/commit/192c52c5b324ee485c07c73367f7d80da236f73d))
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
.claude/commands/tm/setup/install-taskmaster.md:95
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.0/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 9b120d27ca67full audit observations/trust-audit/mcp-server/asachs01__autotask.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-099b120d27ca67CAUTIONB89first audit
06

Questions

What is the Autotask MCP server?

MCP server for Kaseya Autotask PSA — 39 tools for companies, tickets, projects, time entries, and more

What tools does Autotask expose?

113 in total: 71 read-only, 36 that write, and 6 that can delete or overwrite (autotask_delete_quote_item, autotask_delete_service_call, autotask_delete_service_call_ticket, autotask_delete_service_call_ticket_resource, autotask_delete_ticket_charge). Every one is listed on this page with its risk.

Is Autotask safe to connect to an agent?

With care. The audit graded it B (89/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Autotask need?

It reads AUTH_MODE, AUTOTASK_INTEGRATION_CODE, AUTOTASK_SECRET, CONDUIT_S2S_SECRET, X_API_KEY and X_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Autotask run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as website at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (9b120d27ca67), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement