Todoist ExtendedSAFE
Todoist MCP Server Extended - Enabling natural language management of todoist via Claude, MCP and todoist REST APIv2. Featuring LLM optimized Tools including batch operations and robust error handling.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@Chrusic/todoist-mcp-server-extended)
An MCP (Model Context Protocol) server implementation that integrates Claude - or any MCP compatible LLM if you're crafty - with Todoist, enabling natural language task management via MCP tools. The tools in this server allows Claude to interact with your Todoist tasks, projects, sections, and labels using everyday language, while also optimized for LLM workflow efficiency.
Features Overview
- Task Management: Create, update, complete, and delete tasks using everyday language
- Label Management: Create, update, and manage personal labels and task labels
- Project Management: Create, update, and manage Todoist projects
- Section Organization: Create and manage sections within projects
- Smart Search: Find tasks and labels using partial name matches
- Flexible Filtering: Filter tasks by project, section, due date, priority, and labels
- Rich Task Details: Support for descriptions, due dates, priority levels, and project/section assignment
- Batch Operations: Tools have built in batch operation support and custom parameters for efficient usage with LLM workflows
For a complete list of available tools as well as their usage, see tools.md.
Quick Installation Guide
Assuming you already have npm installed.
A more comprehensive installation guide can be found in the How-to Guide.
Installing via Smithery
To install Todoist MCP Server Extended for Claude Desktop via Smithery:
- Run following command in cmd\pwsh:
25811ebb0977OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add todoist-mcp-server-extended --env TODOIST_API_TOKEN=${TODOIST_API_TOKEN} -- npx -y @chrusic/[email protected]{
"mcpServers": {
"todoist-mcp-server-extended": {
"command": "npx",
"args": [
"-y",
"@chrusic/[email protected]"
],
"env": {
"TODOIST_API_TOKEN": "${TODOIST_API_TOKEN}"
}
}
}
}Exposed tools (19)
7 read · 9 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
todoist_complete_task | read | Mark one or more tasks as complete in Todoist |
todoist_create_personal_label | write | Create one or more personal labels in Todoist |
todoist_create_project | write | Create one or more projects with support for nested hierarchies |
todoist_create_project_section | write | Create one or more sections in Todoist projects |
todoist_create_task | write | Create one or more tasks in Todoist with full parameter support |
todoist_delete_personal_label | destructive | Delete a personal label from Todoist |
todoist_delete_task | destructive | Delete one or more tasks from Todoist |
todoist_get_personal_label | read | Get a personal label by ID |
todoist_get_personal_labels | read | Get all personal labels from Todoist |
todoist_get_project_sections | read | Get sections from one or more projects in Todoist |
todoist_get_projects | read | Get projects with optional filtering and hierarchy information |
todoist_get_shared_labels | read | Get all shared labels from Todoist |
todoist_get_tasks | read | Get a list of tasks from Todoist with various filters - handles both single and batch retrieval |
todoist_remove_shared_labels | destructive | Remove one or more shared labels from Todoist tasks |
todoist_rename_shared_labels | write | Rename one or more shared labels in Todoist |
todoist_update_personal_label | write | Update one or more existing personal labels in Todoist |
todoist_update_project | write | Update one or more projects in Todoist |
todoist_update_task | write | Update one or more tasks in Todoist with full parameter support |
todoist_update_task_labels | write | Update the labels of one or more tasks in Todoist |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
todoist_delete_personal_label, todoist_delete_task, todoist_remove_shared_labels
@doist/todoist-api-typescript, @modelcontextprotocol/sdk, @types/node, shx, typescript
Gates applied: no_behavioural_pass.
25811ebb0977full audit observations/trust-audit/mcp-server/chrusic__todoist-extended.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 25811ebb0977 | SAFE | B | 89 | first audit |
Questions
What is the Todoist Extended MCP server?
Todoist MCP Server Extended - Enabling natural language management of todoist via Claude, MCP and todoist REST APIv2. Featuring LLM optimized Tools including batch operations and robust error handling.
What tools does Todoist Extended expose?
19 in total: 7 read-only, 9 that write, and 3 that can delete or overwrite (todoist_delete_personal_label, todoist_delete_task, todoist_remove_shared_labels). Every one is listed on this page with its risk.
Is Todoist Extended safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Todoist Extended need?
It reads TODOIST_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Todoist Extended run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @chrusic/todoist-mcp-server-extended at 0.2.5.
How current is this page?
The grade is for one exact copy of the source (25811ebb0977), read on 2026-10-09. The repository is watched and re-audited when it changes.