LinearSAFE
a private MCP server for accessing Linear
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP server for interacting with Linear's API. This server provides a set of tools for managing Linear issues, projects, and teams through Cline.
Setup Guide
1. Environment Setup
- Clone the repository
- Install dependencies:
npm install
- Copy
.env.exampleto.env:
cp .env.example .env
2. Authentication
The server supports two authentication methods:
API Key (Recommended)
- Go to Linear Settings
- Navigate to the "Security & access" section
- Find the "Personal API keys" section
- Click "New API key"
- Give the key a descriptive label (e.g. "Cline MCP")
- Copy the generated token immediately
- Add the token to your
.envfile:
LINEAR_API_KEY=your_api_key
OAuth Flow (Alternative) *NOT IMPLEMENTED*
- Create an OAuth application at https://linear.app/settings/api/applications
- Configure OAuth environment variables in
.env:
LINEAR_CLIENT_ID=your_oauth_client_id LINEAR_CLIENT_SECRET=your_oauth_client_secret LINEAR_REDIRECT_URI=http://localhost:3000/callback
3. Running the Server
- Build the server:
npm run build
- Start the server:
npm start
4. Cline Integration
- Open your Cline MCP settings file:
- macOS:
~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json - Windows:
%APPDATA%/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json - Linux:
~/.config/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json
- Add the Linear MCP server configuration:
{
"mcpServers": {
"linear": {
"command": "node",
"args": ["/path/to/linear-mcp/build/index.js"],
"env": {
"LINEAR_API_KEY": "your_personal_access_token"
},
"disabled": false,
"autoApprove": []
}
3a285248b732OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add linear-mcp --env LINEAR_API_KEY=${LINEAR_API_KEY} --env LINEAR_AUTH_CODE=${LINEAR_AUTH_CODE} --env LINEAR_CLIENT_SECRET=${LINEAR_CLIENT_SECRET} --env LINEAR_REFRESH_TOKEN=${LINEAR_REFRESH_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"linear-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"LINEAR_API_KEY": "${LINEAR_API_KEY}",
"LINEAR_AUTH_CODE": "${LINEAR_AUTH_CODE}",
"LINEAR_CLIENT_SECRET": "${LINEAR_CLIENT_SECRET}",
"LINEAR_REFRESH_TOKEN": "${LINEAR_REFRESH_TOKEN}"
}
}
}
}Exposed tools (22)
11 read · 8 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
linear_auth | read | Initialize OAuth flow with Linear |
linear_auth_callback | read | Handle OAuth callback |
linear_bulk_update_issues | write | Update multiple issues at once |
linear_create_comment | write | Create a new comment on an issue or reply to an existing comment |
linear_create_issue | write | Create a new issue in Linear |
linear_create_issues | write | Create multiple issues at once |
linear_create_project_milestone | write | Create a new project milestone in Linear |
linear_create_project_milestones | write | Create multiple project milestones at once |
linear_create_project_with_issues | write | Create a new project with associated issues. Note: Project requires teamIds (array) not teamId (single value). |
linear_delete_issue | destructive | Delete an issue |
linear_delete_issues | destructive | Delete multiple issues |
linear_delete_project_milestone | destructive | Delete a project milestone |
linear_get_issue_comments | read | Get comments for a specific issue, including threaded replies |
linear_get_project | read | Get project information |
linear_get_project_milestone | read | Get information about a specific project milestone |
linear_get_project_milestones | read | Get all milestones for a specific project |
linear_get_teams | read | Get all teams with their states and labels |
linear_get_user | read | Get current user information |
linear_search_issues | read | Search for issues with filtering and pagination |
linear_search_project_milestones | read | Search for project milestones with filtering and pagination |
linear_search_projects | read | Search for projects by name |
linear_update_project_milestone | write | Update an existing project milestone |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
linear_delete_issue, linear_delete_issues, linear_delete_project_milestone
import type { LinearGraphQLClient } from '../../graphql/client';import { LinearAuth } from '../../auth.js';import { LinearGraphQLClient } from '../../graphql/client.js';import { LinearAuth } from '../../auth.js';import { LinearGraphQLClient } from '../../graphql/client.js';@graphql-typed-document-node/core, @linear/sdk, @modelcontextprotocol/sdk, graphql, graphql-tag, @types/dotenv, @types/express, @types/jest
Gates applied: no_behavioural_pass, no_license.
3a285248b732full audit observations/trust-audit/mcp-server/cline__linear-19.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 3a285248b732 | SAFE | B | 89 | first audit |
Questions
What is the Linear MCP server?
a private MCP server for accessing Linear
What tools does Linear expose?
22 in total: 11 read-only, 8 that write, and 3 that can delete or overwrite (linear_delete_issue, linear_delete_issues, linear_delete_project_milestone). Every one is listed on this page with its risk.
Is Linear safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Linear need?
It reads LINEAR_API_KEY, LINEAR_AUTH_CODE, LINEAR_CLIENT_SECRET and LINEAR_REFRESH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Linear run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as linear-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (3a285248b732), read on 2026-10-07. The repository is watched and re-audited when it changes.