TodoistSAFE
A set of tools to connect to AI agents, to allow them to use Todoist on a user's behalf. Includes MCP support.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Library for connecting AI agents to Todoist. Includes tools that can be integrated into LLMs, enabling them to access and modify a Todoist account on the user's behalf.
These tools can be used both through an MCP server, or imported directly in other projects to integrate them to your own AI conversational interfaces.
Using tools
1. Add this repository as a dependency
npm install @doist/todoist-mcp
2. Import the tools and plug them to an AI
Here's an example using Vercel's AI SDK.
import { findTasksByDate, addTasks } from '@doist/todoist-mcp'
import { TodoistApi } from '@doist/todoist-sdk'
import { streamText } from 'ai'
// Create Todoist API client
const client = new TodoistApi(process.env.TODOIST_API_KEY)
// Helper to wrap tools with the client
function wrapTool(tool, todoistClient) {
return {
...tool,
execute(args) {
return tool.execute(args, todoistClient)
},
}
}
const result = streamText({
model: yourModel,
system: 'You are a helpful Todoist assistant',
tools: {
findTasksByDate: wrapTool(findTasksByDate, client),
addTasks: wrapTool(addTasks, client),
},
})Using as an MCP server
Quick Start
You can run the MCP server directly with npx:
npx @doist/todoist-mcp
Setup Guide
The Todoist MCP server is available as a streamable HTTP service for easy integration with various AI clients:
Primary URL (Streamable HTTP): https://ai.todoist.net/mcp
Claude Desktop
- Open Settings → Connectors → Add custom connector
- Enter
https://ai.todoist.net/mcpand complete OAuth authentication
Cursor
Create a configuration file:
- Global:
~/.cursor/mcp.json - Project-specific:
.cursor/mcp.json
{
"mcpServers": {
"todoist": {
"command": "npx",
"args": ["-y", "mcp-remote", "htt00a9d4828791OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add todoist-mcp --env MCP_TOKEN_BUDGET=${MCP_TOKEN_BUDGET} --env TODOIST_API_KEY=${TODOIST_API_KEY} -- npx -y @doist/[email protected]{
"mcpServers": {
"todoist-mcp": {
"command": "npx",
"args": [
"-y",
"@doist/[email protected]"
],
"env": {
"MCP_TOKEN_BUDGET": "${MCP_TOKEN_BUDGET}",
"TODOIST_API_KEY": "${TODOIST_API_KEY}"
}
}
}
}Exposed tools (7)
7 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Docs | read | A handy reference |
Inbox | read | |
QA | read | Bugs to verify |
no-schema-tool | read | Tool without output schema |
piped-schema-tool | read | Tool with different input and output schemas |
productivity-analysis | read | Analyze your Todoist productivity with insights on completion trends, goal streaks, project distribution, and actionable recommendations. Gathers data from multiple tools and synthesizes a comprehensive report. |
schema-tool | read | Tool with output schema |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (12)
.oxfmtrc.json
.oxlintrc.json
import { ArgsSchema } from '../../tools/find-tasks-by-date.js'import { ToolNames } from '../../utils/tool-names.js'import type { Priority } from '../../utils/priorities.js'import { convertPriorityToNumber } from '../../utils/priorities.js'import type { Priority } from '../../utils/priorities.js'This will expose the service at `http://127.0.0.1:8080/mcp` with hot-reload.
"args": ["mcp-remote", "http://127.0.0.1:3000/mcp"]
curl http://127.0.0.1:3000/health
it.each([['http://localhost:3000'], ['http://127.0.0.1:8080']])(
src/mcp-apps/task-list/empty.svg
Gates applied: no_behavioural_pass.
00a9d4828791full audit observations/trust-audit/mcp-server/doist__todoist-7.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 00a9d4828791 | SAFE | B | 89 | first audit |
Questions
What is the Todoist MCP server?
A set of tools to connect to AI agents, to allow them to use Todoist on a user's behalf. Includes MCP support.
What tools does Todoist expose?
7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Todoist safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Todoist need?
It reads MCP_TOKEN_BUDGET and TODOIST_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Todoist run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @doist/todoist-mcp at 13.3.1.
How current is this page?
The grade is for one exact copy of the source (00a9d4828791), read on 2026-09-29. The repository is watched and re-audited when it changes.