Atlas / MCP servers / greirson / Todoist

TodoistSAFE

mcp/greirson/todoist-8

MCP server that connects Claude to Todoist for natural language task and project management with bulk operations

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
105 53r · 36w · 16d
Transport
stdio
License
MIT
Stars
245
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server that connects Claude with Todoist for complete task and project management through natural language.

Installation

Claude Desktop (One-Click Install)

  1. Download [todoist-mcp.mcpb](https://github.com/greirson/mcp-todoist/releases/latest) from the latest release
  2. Double-click the file (or drag onto Claude Desktop)
  3. Enter your Todoist API token when prompted
  4. Start chatting: "Show me my Todoist projects"

Claude Code / Other MCP Clients

claude mcp add todoist -e TODOIST_API_TOKEN=your_token -- npx @greirson/mcp-todoist

Manual JSON configuration

Add to your MCP client config (claude_desktop_config.json, ~/.claude.json, etc.):

{
"mcpServers": {
"todoist": {
"command": "npx",
"args": ["@greirson/mcp-todoist"],
"env": {
"TODOIST_API_TOKEN": "your_api_token_here"
}
}
}
}

Config locations:

  • Claude Desktop (macOS): ~/Library/Application Support/Claude/claude_desktop_config.json
  • Claude Desktop (Windows): %APPDATA%\Claude\claude_desktop_config.json
  • Claude Code: ~/.claude.json

Features

  • 19 MCP Tools for complete Todoist management
  • Task Management: Create, update, delete, complete, reopen tasks with priorities, due dates, labels
  • Bulk Operations: Process multiple tasks efficiently
  • Subtasks: Hierarchical task management with completion tracking
  • Projects & Sections: Full organization support
  • Labels, Filters, Reminders: Pro/Business features supported
  • Natural Language: Quick add with Todoist's natural language parsing
  • Dry-Run Mode: Test operations without making changes

Dry-Run Mode

Dry-run mode allows you to test operations and automations without making any real changes to your Todoist workspace. This is perfect for testing, debugging, learning the AP

Read from source at commit 95543700ab2bOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-todoist --env TODOIST_API_TOKEN=${TODOIST_API_TOKEN} -- npx -y @greirson/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-todoist": {
      "command": "npx",
      "args": [
        "-y",
        "@greirson/[email protected]"
      ],
      "env": {
        "TODOIST_API_TOKEN": "${TODOIST_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (105)

53 read · 36 write · 16 destructive. Blast radius: 16 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
todoist_activityreadGet Todoist activity logs and audit trails. Actions: - get: Get activity log entries with optional filters Example: {action:
todoist_activity_by_date_rangereadGet Todoist activity log within a specific date range. Returns all events that occurred between the specified dates. Useful for generating activity reports and reviewing changes over time periods.
todoist_activity_by_projectreadGet Todoist activity log for a specific project. Returns all events (tasks added/completed/deleted, comments, etc.) related to the project. Useful for project auditing and tracking project-specific changes.
todoist_activity_getreadGet Todoist activity log with optional filters. Returns events for items, notes, projects, sections, labels, filters, and reminders. Useful for auditing changes, tracking productivity, and understanding workspace history.
todoist_archived_projects_getreadGet a list of all archived projects. Useful for reviewing or restoring archived projects.
todoist_backupreadManage Todoist backups - list available backups and download backup files. Actions: - list: Get list of available backup versions with dates Example: {action:
todoist_backup_downloadreadGet the download URL for a specific backup version. The URL is time-limited. Backups are ZIP files containing CSV exports of your Todoist data.
todoist_backups_getreadList all available automatic backups of your Todoist data. Todoist creates backups automatically. Returns version timestamps and download URLs.
todoist_collaborationreadManage Todoist collaboration, invitations, and notifications. Actions: - workspaces: List workspaces (Business accounts) Example: {action:
todoist_collaborators_getreadGet a list of collaborators for a shared project. Returns user IDs, names, and emails that can be used for task assignment with assignee_id.
todoist_commentwriteManage comments on Todoist tasks and projects. Actions: - create: Add a comment to a task or project Example: {action:
todoist_comment_createwriteAdd a comment to a task or project in Todoist. For task comments, provide task_id or task_name. For project comments, provide project_id.
todoist_comment_deletedestructiveDelete a comment by its ID
todoist_comment_getreadGet comments for a task or project in Todoist
todoist_comment_updatewriteUpdate an existing comment
todoist_completedreadGet completed tasks history from Todoist. Actions: - get: Retrieve completed tasks with optional filters Example: {action:
todoist_completed_tasks_getwriteRetrieve completed tasks from Todoist. Uses the Sync API to fetch tasks that have been marked as complete. Supports filtering by project, date range, and pagination.
todoist_duplicates_findreadFind duplicate or similar tasks using content similarity analysis. Returns grouped tasks that have similar titles, sorted by similarity percentage.
todoist_duplicates_mergewriteMerge duplicate tasks by keeping one task and completing or deleting the others. Use after todoist_duplicates_find to clean up duplicates.
todoist_filterreadManage custom filters in Todoist (requires Pro/Business plan). Actions: - create: Create a custom filter Example: {action:
todoist_filter_createwriteCreate a new custom filter in Todoist. Filters use Todoist
todoist_filter_deletedestructiveDelete a filter from Todoist. This action cannot be undone. Note: Frozen filters (from cancelled subscriptions) cannot be deleted.
todoist_filter_getreadGet all custom filters in Todoist. Filters are saved searches that help you organize and view tasks based on specific criteria. Note: Requires Todoist Pro or Business plan.
todoist_filter_updatewriteUpdate an existing filter in Todoist. Can update name, query, color, order, or favorite status. Note: Frozen filters (from cancelled subscriptions) cannot be modified.
todoist_invitation_acceptreadAccept a project sharing invitation. Requires both the invitation ID and secret from the invitation email.
todoist_invitation_deletedestructiveDelete/revoke a pending invitation that you sent. Use this to cancel an invitation before it is accepted.
todoist_invitation_rejectreadReject a project sharing invitation. Requires both the invitation ID and secret.
todoist_invitations_getreadGet all pending project sharing invitations received by the current user.
todoist_labelwriteManage Todoist labels for task organization. Actions: - create: Create a new label Example: {action:
todoist_label_createwriteCreate a new label in Todoist
todoist_label_deletedestructiveDelete a label from Todoist
todoist_label_getreadGet all labels in Todoist
todoist_label_statsreadGet usage statistics for all labels in Todoist
todoist_label_updatewriteUpdate an existing label in Todoist
todoist_notesdestructiveManage Todoist project notes - create, read, update, and delete notes attached to projects. Actions: - create: Create a new note for a project Example: {action:
todoist_notification_mark_readreadMark a specific notification as read.
todoist_notifications_getreadGet live notifications including comments, assignments, sharing invitations, and other collaboration events.
todoist_notifications_mark_all_readreadMark all notifications as read.
todoist_productivity_stats_getreadGet detailed productivity statistics including karma, task completion history, daily/weekly streaks, and goals progress.
todoist_projectdestructiveManage Todoist projects - create, read, update, delete, archive, or get collaborators. Actions: - create: Create a new project with optional hierarchy and styling Example: {action:
todoist_project_archivereadArchive or unarchive a project in Todoist. Archived projects are hidden from the main view but can be restored.
todoist_project_collaborators_getreadGet a list of collaborators for a shared project in Todoist. Returns collaborator names and emails.
todoist_project_createwriteCreate a new project in Todoist with optional sub-project hierarchy, description, and view style
todoist_project_deletedestructiveDelete a project from Todoist. This will also delete all tasks and sub-projects within the project.
todoist_project_getreadGet a list of all projects from Todoist with their IDs, names, descriptions, and hierarchy information
todoist_project_invitereadInvite a user to collaborate on a project by email. The invitee will receive an email notification.
todoist_project_move_to_parentwriteMove a project under another project (making it a sub-project) or to root level. Useful for organizing project hierarchies.
todoist_project_note_createwriteCreate a new note for a project. Project notes are visible to all project collaborators.
todoist_project_note_deletedestructiveDelete a project note by ID.
todoist_project_note_updatewriteUpdate an existing project note
todoist_project_notes_getreadGet all notes for a specific project. Project notes are shared with all project collaborators.
todoist_project_opswriteAdvanced project operations - reorder projects, move to parent, or get archived projects. Actions: - reorder: Reorder projects by specifying their new positions in the sidebar Example: {action:
todoist_project_updatewriteUpdate an existing project in Todoist. Can modify name, color, favorite status, description, or view style.
todoist_projects_reorderreadReorder projects by specifying their new positions. Controls project ordering in the sidebar.
todoist_reminderreadManage task reminders in Todoist (requires Pro/Business plan). Actions: - create: Create a reminder for a task Example (relative): {action:
todoist_reminder_createwriteCreate a new reminder for a task. Supports three reminder types: relative (minutes before due), absolute (specific date/time), and location-based. Requires Todoist Pro or Business plan.
todoist_reminder_deletedestructiveDelete a reminder. Requires Todoist Pro or Business plan.
todoist_reminder_getreadGet all reminders, optionally filtered by task. Reminders require Todoist Pro or Business plan.
todoist_reminder_updatewriteUpdate an existing reminder. Can change the type, timing, or location settings. Requires Todoist Pro or Business plan.
todoist_sectionwriteManage Todoist sections within projects. Actions: - create: Create a new section in a project Example: {action:
todoist_section_archivereadArchive a section. Archived sections are hidden but not deleted. Tasks in the section are also archived.
todoist_section_createwriteCreate a new section within a project in Todoist
todoist_section_deletedestructiveDelete a section and all its tasks from Todoist. Can delete by section ID or section name search.
todoist_section_getreadGet a list of sections within a project from Todoist with their IDs and names
todoist_section_movewriteMove a section to a different project. All tasks in the section will move with it.
todoist_section_unarchivereadUnarchive a previously archived section. Restores the section and its tasks to active status.
todoist_section_updatewriteUpdate an existing section in Todoist. Can update name by section ID or section name search.
todoist_sections_reorderreadReorder sections within a project by specifying their new positions.
todoist_shared_label_removedestructiveRemove a shared label from all items in the workspace. This removes the label from all tasks but does not delete the tasks. Requires Todoist Business account.
todoist_shared_label_renamewriteRename a shared label across all items in the workspace. Updates the label name for all team members. Requires Todoist Business account.
todoist_shared_labelsreadManage shared labels in Todoist Business workspaces. Actions: - get: List all shared labels Example: {action:
todoist_shared_labels_getreadGet all shared labels in the workspace. Shared labels are available in Todoist Business accounts for team collaboration.
todoist_subtaskwriteManage hierarchical subtasks in Todoist. Actions: - create: Create a subtask under a parent task Example: {action:
todoist_subtask_createwriteCreate a new subtask under a parent task in Todoist
todoist_subtask_promotedestructivePromote a subtask to a main task (remove parent relationship)
todoist_subtasks_bulk_createwriteCreate multiple subtasks under a parent task in a single operation
todoist_taskdestructiveManage Todoist tasks - create, read, update, delete, complete, reopen, or quick add using natural language. Actions: - create: Create a new task with full attribute support Example: {action:
todoist_task_bulkdestructivePerform bulk operations on Todoist tasks - create, update, delete, or complete multiple tasks at once. Actions: - bulk_create: Create multiple tasks at once Example: {action:
todoist_task_closereadClose a task. For recurring tasks, this completes the current occurrence and schedules the next one. For non-recurring tasks, this is equivalent to completing the task.
todoist_task_completereadMark a task as complete found by ID or partial name search (case-insensitive)
todoist_task_convert_to_subtaskreadConvert an existing task to a subtask of another task
todoist_task_createwriteCreate a new task in Todoist with optional description, due date, priority, labels, deadline, project, section, and duration for time blocking
todoist_task_day_order_updatewriteUpdate the day order of tasks in the Today view. Controls the order tasks appear when viewing today
todoist_task_deletedestructiveDelete a task found by ID or partial name search (case-insensitive)
todoist_task_getreadRetrieve tasks from Todoist. Use
todoist_task_hierarchy_getreadGet a task with all its subtasks in a hierarchical structure
todoist_task_movewriteMove a task to a different project, section, or under a parent task. Uses Todoist Sync API for reliable movement operations.
todoist_task_opswriteAdvanced task operations for moving, reordering, and organizing tasks via Sync API. Actions: - move: Move a task to a different project, section, or parent task Example: {action:
todoist_task_quick_addwriteCreate a task using natural language parsing like the Todoist app.
todoist_task_reopenreadReopen a previously completed task found by ID or partial name search (case-insensitive). Use this to restore a task that was marked as complete.
todoist_task_reorderwriteSet the order of a task within its project/section. Lower numbers appear first.
todoist_task_updatewriteUpdate an existing task found by ID or partial name search. Supports updating content, description, due date, priority, labels, deadline, project, section, and duration
todoist_tasks_bulk_completereadComplete multiple tasks at once based on search criteria. Efficiently mark many tasks as done.
todoist_tasks_bulk_createwriteCreate multiple tasks at once for improved efficiency. Each task can have full attributes including duration for time blocking.
todoist_tasks_bulk_deletedestructiveDelete multiple tasks at once based on search criteria. Use with caution - this will permanently delete matching tasks.
todoist_tasks_bulk_updatewriteUpdate multiple tasks at once based on search criteria. Supports updating content, priority, due dates, labels, project, section, and duration.
todoist_tasks_reorder_bulkreadReorder multiple tasks at once by specifying their new positions. Efficient for reorganizing task lists.
todoist_test_all_featureswriteRun comprehensive tests on all Todoist MCP features to verify functionality
todoist_test_connectionreadTest the connection to Todoist API and verify API token validity
todoist_test_performancereadMeasure performance and response times of Todoist API operations
todoist_userreadGet Todoist user information and productivity stats. Actions: - info: Get user profile information (name, email, timezone, avatar) Example: {action:
todoist_user_getreadGet information about the current Todoist user including name, email, timezone, karma, and account settings.
todoist_user_settings_getreadGet user settings including reminder preferences, notification settings, sounds, and theme configuration.
todoist_utilityreadTodoist utility operations for testing API connectivity and finding/merging duplicate tasks. Actions: - test_connection: Quick API token validation and connection test Example: {action:
todoist_workspaces_getreadGet all workspaces for the current user. Workspaces are available with Todoist Business accounts for team organization.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
todoist_comment_delete, todoist_filter_delete, todoist_invitation_delete, todoist_label_delete, todoist_notes, todoist_project, todoist_project_delete, todoist_project_note_delete, todoist_reminder_de
Why it matters. 16 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/handlers/task/bulk.ts:8
} from "../../types/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/handlers/task/bulk.ts:9
import { CacheManager } from "../../cache/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/handlers/task/bulk.ts:19
} from "../../validation/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/handlers/task/bulk.ts:20
import type { DurationUnit } from "../../types/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/handlers/task/bulk.ts:24
} from "../../utils/api-helpers.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @doist/todoist-api-typescript, uuid, @eslint/js, @types/jest, @types/node, @types/uuid, @typescript-eslint/eslint-plugin
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 95543700ab2bfull audit observations/trust-audit/mcp-server/greirson__todoist-8.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0695543700ab2bSAFEB89first audit
06

Questions

What is the Todoist MCP server?

MCP server that connects Claude to Todoist for natural language task and project management with bulk operations

What tools does Todoist expose?

105 in total: 53 read-only, 36 that write, and 16 that can delete or overwrite (todoist_comment_delete, todoist_filter_delete, todoist_invitation_delete, todoist_label_delete, todoist_notes). Every one is listed on this page with its risk.

Is Todoist safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 16 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Todoist need?

It reads TODOIST_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Todoist run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @greirson/mcp-todoist at 1.0.3.

How current is this page?

The grade is for one exact copy of the source (95543700ab2b), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement