TodoistSAFE
MCP server that connects Claude to Todoist for natural language task and project management with bulk operations
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An MCP (Model Context Protocol) server that connects Claude with Todoist for complete task and project management through natural language.
Installation
Claude Desktop (One-Click Install)
- Download [todoist-mcp.mcpb](https://github.com/greirson/mcp-todoist/releases/latest) from the latest release
- Double-click the file (or drag onto Claude Desktop)
- Enter your Todoist API token when prompted
- Start chatting: "Show me my Todoist projects"
Claude Code / Other MCP Clients
claude mcp add todoist -e TODOIST_API_TOKEN=your_token -- npx @greirson/mcp-todoist
Manual JSON configuration
Add to your MCP client config (claude_desktop_config.json, ~/.claude.json, etc.):
{
"mcpServers": {
"todoist": {
"command": "npx",
"args": ["@greirson/mcp-todoist"],
"env": {
"TODOIST_API_TOKEN": "your_api_token_here"
}
}
}
}Config locations:
- Claude Desktop (macOS):
~/Library/Application Support/Claude/claude_desktop_config.json - Claude Desktop (Windows):
%APPDATA%\Claude\claude_desktop_config.json - Claude Code:
~/.claude.json
Features
- 19 MCP Tools for complete Todoist management
- Task Management: Create, update, delete, complete, reopen tasks with priorities, due dates, labels
- Bulk Operations: Process multiple tasks efficiently
- Subtasks: Hierarchical task management with completion tracking
- Projects & Sections: Full organization support
- Labels, Filters, Reminders: Pro/Business features supported
- Natural Language: Quick add with Todoist's natural language parsing
- Dry-Run Mode: Test operations without making changes
Dry-Run Mode
Dry-run mode allows you to test operations and automations without making any real changes to your Todoist workspace. This is perfect for testing, debugging, learning the AP
95543700ab2bOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-todoist --env TODOIST_API_TOKEN=${TODOIST_API_TOKEN} -- npx -y @greirson/[email protected]{
"mcpServers": {
"mcp-todoist": {
"command": "npx",
"args": [
"-y",
"@greirson/[email protected]"
],
"env": {
"TODOIST_API_TOKEN": "${TODOIST_API_TOKEN}"
}
}
}
}Exposed tools (105)
53 read · 36 write · 16 destructive. Blast radius: 16 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
todoist_activity | read | Get Todoist activity logs and audit trails. Actions: - get: Get activity log entries with optional filters Example: {action: |
todoist_activity_by_date_range | read | Get Todoist activity log within a specific date range. Returns all events that occurred between the specified dates. Useful for generating activity reports and reviewing changes over time periods. |
todoist_activity_by_project | read | Get Todoist activity log for a specific project. Returns all events (tasks added/completed/deleted, comments, etc.) related to the project. Useful for project auditing and tracking project-specific changes. |
todoist_activity_get | read | Get Todoist activity log with optional filters. Returns events for items, notes, projects, sections, labels, filters, and reminders. Useful for auditing changes, tracking productivity, and understanding workspace history. |
todoist_archived_projects_get | read | Get a list of all archived projects. Useful for reviewing or restoring archived projects. |
todoist_backup | read | Manage Todoist backups - list available backups and download backup files. Actions: - list: Get list of available backup versions with dates Example: {action: |
todoist_backup_download | read | Get the download URL for a specific backup version. The URL is time-limited. Backups are ZIP files containing CSV exports of your Todoist data. |
todoist_backups_get | read | List all available automatic backups of your Todoist data. Todoist creates backups automatically. Returns version timestamps and download URLs. |
todoist_collaboration | read | Manage Todoist collaboration, invitations, and notifications. Actions: - workspaces: List workspaces (Business accounts) Example: {action: |
todoist_collaborators_get | read | Get a list of collaborators for a shared project. Returns user IDs, names, and emails that can be used for task assignment with assignee_id. |
todoist_comment | write | Manage comments on Todoist tasks and projects. Actions: - create: Add a comment to a task or project Example: {action: |
todoist_comment_create | write | Add a comment to a task or project in Todoist. For task comments, provide task_id or task_name. For project comments, provide project_id. |
todoist_comment_delete | destructive | Delete a comment by its ID |
todoist_comment_get | read | Get comments for a task or project in Todoist |
todoist_comment_update | write | Update an existing comment |
todoist_completed | read | Get completed tasks history from Todoist. Actions: - get: Retrieve completed tasks with optional filters Example: {action: |
todoist_completed_tasks_get | write | Retrieve completed tasks from Todoist. Uses the Sync API to fetch tasks that have been marked as complete. Supports filtering by project, date range, and pagination. |
todoist_duplicates_find | read | Find duplicate or similar tasks using content similarity analysis. Returns grouped tasks that have similar titles, sorted by similarity percentage. |
todoist_duplicates_merge | write | Merge duplicate tasks by keeping one task and completing or deleting the others. Use after todoist_duplicates_find to clean up duplicates. |
todoist_filter | read | Manage custom filters in Todoist (requires Pro/Business plan). Actions: - create: Create a custom filter Example: {action: |
todoist_filter_create | write | Create a new custom filter in Todoist. Filters use Todoist |
todoist_filter_delete | destructive | Delete a filter from Todoist. This action cannot be undone. Note: Frozen filters (from cancelled subscriptions) cannot be deleted. |
todoist_filter_get | read | Get all custom filters in Todoist. Filters are saved searches that help you organize and view tasks based on specific criteria. Note: Requires Todoist Pro or Business plan. |
todoist_filter_update | write | Update an existing filter in Todoist. Can update name, query, color, order, or favorite status. Note: Frozen filters (from cancelled subscriptions) cannot be modified. |
todoist_invitation_accept | read | Accept a project sharing invitation. Requires both the invitation ID and secret from the invitation email. |
todoist_invitation_delete | destructive | Delete/revoke a pending invitation that you sent. Use this to cancel an invitation before it is accepted. |
todoist_invitation_reject | read | Reject a project sharing invitation. Requires both the invitation ID and secret. |
todoist_invitations_get | read | Get all pending project sharing invitations received by the current user. |
todoist_label | write | Manage Todoist labels for task organization. Actions: - create: Create a new label Example: {action: |
todoist_label_create | write | Create a new label in Todoist |
todoist_label_delete | destructive | Delete a label from Todoist |
todoist_label_get | read | Get all labels in Todoist |
todoist_label_stats | read | Get usage statistics for all labels in Todoist |
todoist_label_update | write | Update an existing label in Todoist |
todoist_notes | destructive | Manage Todoist project notes - create, read, update, and delete notes attached to projects. Actions: - create: Create a new note for a project Example: {action: |
todoist_notification_mark_read | read | Mark a specific notification as read. |
todoist_notifications_get | read | Get live notifications including comments, assignments, sharing invitations, and other collaboration events. |
todoist_notifications_mark_all_read | read | Mark all notifications as read. |
todoist_productivity_stats_get | read | Get detailed productivity statistics including karma, task completion history, daily/weekly streaks, and goals progress. |
todoist_project | destructive | Manage Todoist projects - create, read, update, delete, archive, or get collaborators. Actions: - create: Create a new project with optional hierarchy and styling Example: {action: |
todoist_project_archive | read | Archive or unarchive a project in Todoist. Archived projects are hidden from the main view but can be restored. |
todoist_project_collaborators_get | read | Get a list of collaborators for a shared project in Todoist. Returns collaborator names and emails. |
todoist_project_create | write | Create a new project in Todoist with optional sub-project hierarchy, description, and view style |
todoist_project_delete | destructive | Delete a project from Todoist. This will also delete all tasks and sub-projects within the project. |
todoist_project_get | read | Get a list of all projects from Todoist with their IDs, names, descriptions, and hierarchy information |
todoist_project_invite | read | Invite a user to collaborate on a project by email. The invitee will receive an email notification. |
todoist_project_move_to_parent | write | Move a project under another project (making it a sub-project) or to root level. Useful for organizing project hierarchies. |
todoist_project_note_create | write | Create a new note for a project. Project notes are visible to all project collaborators. |
todoist_project_note_delete | destructive | Delete a project note by ID. |
todoist_project_note_update | write | Update an existing project note |
todoist_project_notes_get | read | Get all notes for a specific project. Project notes are shared with all project collaborators. |
todoist_project_ops | write | Advanced project operations - reorder projects, move to parent, or get archived projects. Actions: - reorder: Reorder projects by specifying their new positions in the sidebar Example: {action: |
todoist_project_update | write | Update an existing project in Todoist. Can modify name, color, favorite status, description, or view style. |
todoist_projects_reorder | read | Reorder projects by specifying their new positions. Controls project ordering in the sidebar. |
todoist_reminder | read | Manage task reminders in Todoist (requires Pro/Business plan). Actions: - create: Create a reminder for a task Example (relative): {action: |
todoist_reminder_create | write | Create a new reminder for a task. Supports three reminder types: relative (minutes before due), absolute (specific date/time), and location-based. Requires Todoist Pro or Business plan. |
todoist_reminder_delete | destructive | Delete a reminder. Requires Todoist Pro or Business plan. |
todoist_reminder_get | read | Get all reminders, optionally filtered by task. Reminders require Todoist Pro or Business plan. |
todoist_reminder_update | write | Update an existing reminder. Can change the type, timing, or location settings. Requires Todoist Pro or Business plan. |
todoist_section | write | Manage Todoist sections within projects. Actions: - create: Create a new section in a project Example: {action: |
todoist_section_archive | read | Archive a section. Archived sections are hidden but not deleted. Tasks in the section are also archived. |
todoist_section_create | write | Create a new section within a project in Todoist |
todoist_section_delete | destructive | Delete a section and all its tasks from Todoist. Can delete by section ID or section name search. |
todoist_section_get | read | Get a list of sections within a project from Todoist with their IDs and names |
todoist_section_move | write | Move a section to a different project. All tasks in the section will move with it. |
todoist_section_unarchive | read | Unarchive a previously archived section. Restores the section and its tasks to active status. |
todoist_section_update | write | Update an existing section in Todoist. Can update name by section ID or section name search. |
todoist_sections_reorder | read | Reorder sections within a project by specifying their new positions. |
todoist_shared_label_remove | destructive | Remove a shared label from all items in the workspace. This removes the label from all tasks but does not delete the tasks. Requires Todoist Business account. |
todoist_shared_label_rename | write | Rename a shared label across all items in the workspace. Updates the label name for all team members. Requires Todoist Business account. |
todoist_shared_labels | read | Manage shared labels in Todoist Business workspaces. Actions: - get: List all shared labels Example: {action: |
todoist_shared_labels_get | read | Get all shared labels in the workspace. Shared labels are available in Todoist Business accounts for team collaboration. |
todoist_subtask | write | Manage hierarchical subtasks in Todoist. Actions: - create: Create a subtask under a parent task Example: {action: |
todoist_subtask_create | write | Create a new subtask under a parent task in Todoist |
todoist_subtask_promote | destructive | Promote a subtask to a main task (remove parent relationship) |
todoist_subtasks_bulk_create | write | Create multiple subtasks under a parent task in a single operation |
todoist_task | destructive | Manage Todoist tasks - create, read, update, delete, complete, reopen, or quick add using natural language. Actions: - create: Create a new task with full attribute support Example: {action: |
todoist_task_bulk | destructive | Perform bulk operations on Todoist tasks - create, update, delete, or complete multiple tasks at once. Actions: - bulk_create: Create multiple tasks at once Example: {action: |
todoist_task_close | read | Close a task. For recurring tasks, this completes the current occurrence and schedules the next one. For non-recurring tasks, this is equivalent to completing the task. |
todoist_task_complete | read | Mark a task as complete found by ID or partial name search (case-insensitive) |
todoist_task_convert_to_subtask | read | Convert an existing task to a subtask of another task |
todoist_task_create | write | Create a new task in Todoist with optional description, due date, priority, labels, deadline, project, section, and duration for time blocking |
todoist_task_day_order_update | write | Update the day order of tasks in the Today view. Controls the order tasks appear when viewing today |
todoist_task_delete | destructive | Delete a task found by ID or partial name search (case-insensitive) |
todoist_task_get | read | Retrieve tasks from Todoist. Use |
todoist_task_hierarchy_get | read | Get a task with all its subtasks in a hierarchical structure |
todoist_task_move | write | Move a task to a different project, section, or under a parent task. Uses Todoist Sync API for reliable movement operations. |
todoist_task_ops | write | Advanced task operations for moving, reordering, and organizing tasks via Sync API. Actions: - move: Move a task to a different project, section, or parent task Example: {action: |
todoist_task_quick_add | write | Create a task using natural language parsing like the Todoist app. |
todoist_task_reopen | read | Reopen a previously completed task found by ID or partial name search (case-insensitive). Use this to restore a task that was marked as complete. |
todoist_task_reorder | write | Set the order of a task within its project/section. Lower numbers appear first. |
todoist_task_update | write | Update an existing task found by ID or partial name search. Supports updating content, description, due date, priority, labels, deadline, project, section, and duration |
todoist_tasks_bulk_complete | read | Complete multiple tasks at once based on search criteria. Efficiently mark many tasks as done. |
todoist_tasks_bulk_create | write | Create multiple tasks at once for improved efficiency. Each task can have full attributes including duration for time blocking. |
todoist_tasks_bulk_delete | destructive | Delete multiple tasks at once based on search criteria. Use with caution - this will permanently delete matching tasks. |
todoist_tasks_bulk_update | write | Update multiple tasks at once based on search criteria. Supports updating content, priority, due dates, labels, project, section, and duration. |
todoist_tasks_reorder_bulk | read | Reorder multiple tasks at once by specifying their new positions. Efficient for reorganizing task lists. |
todoist_test_all_features | write | Run comprehensive tests on all Todoist MCP features to verify functionality |
todoist_test_connection | read | Test the connection to Todoist API and verify API token validity |
todoist_test_performance | read | Measure performance and response times of Todoist API operations |
todoist_user | read | Get Todoist user information and productivity stats. Actions: - info: Get user profile information (name, email, timezone, avatar) Example: {action: |
todoist_user_get | read | Get information about the current Todoist user including name, email, timezone, karma, and account settings. |
todoist_user_settings_get | read | Get user settings including reminder preferences, notification settings, sounds, and theme configuration. |
todoist_utility | read | Todoist utility operations for testing API connectivity and finding/merging duplicate tasks. Actions: - test_connection: Quick API token validation and connection test Example: {action: |
todoist_workspaces_get | read | Get all workspaces for the current user. Workspaces are available with Todoist Business accounts for team organization. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
todoist_comment_delete, todoist_filter_delete, todoist_invitation_delete, todoist_label_delete, todoist_notes, todoist_project, todoist_project_delete, todoist_project_note_delete, todoist_reminder_de
} from "../../types/index.js";
import { CacheManager } from "../../cache/index.js";} from "../../validation/index.js";
import type { DurationUnit } from "../../types/index.js";} from "../../utils/api-helpers.js";
@modelcontextprotocol/sdk, @doist/todoist-api-typescript, uuid, @eslint/js, @types/jest, @types/node, @types/uuid, @typescript-eslint/eslint-plugin
Gates applied: no_behavioural_pass.
95543700ab2bfull audit observations/trust-audit/mcp-server/greirson__todoist-8.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 95543700ab2b | SAFE | B | 89 | first audit |
Questions
What is the Todoist MCP server?
MCP server that connects Claude to Todoist for natural language task and project management with bulk operations
What tools does Todoist expose?
105 in total: 53 read-only, 36 that write, and 16 that can delete or overwrite (todoist_comment_delete, todoist_filter_delete, todoist_invitation_delete, todoist_label_delete, todoist_notes). Every one is listed on this page with its risk.
Is Todoist safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 16 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Todoist need?
It reads TODOIST_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Todoist run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @greirson/mcp-todoist at 1.0.3.
How current is this page?
The grade is for one exact copy of the source (95543700ab2b), read on 2026-10-06. The repository is watched and re-audited when it changes.