TickTickSAFE
MCP server that interacts with TickTick (Dida 365) via the TickTick Open API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for TickTick that enables interacting with your TickTick task management system directly through Claude and other MCP clients.
Features
- 📋 View all your TickTick projects and tasks
- ✏️ Create new projects and tasks through natural language
- 🔄 Update existing task details (title, content, dates, priority)
- ✅ Mark tasks as complete
- 🗑️ Delete tasks and projects
- 🔄 Full integration with TickTick's open API
- 🔌 Seamless integration with Claude and other MCP clients
Prerequisites
- Python 3.10 or higher
- uv - Fast Python package installer and resolver
- TickTick account with API access
- TickTick API credentials (Client ID, Client Secret, Access Token)
Installation
- Clone this repository:
git clone https://github.com/jacepark12/ticktick-mcp.git cd ticktick-mcp
- Install with uv:
# Install uv if you don't have it already curl -LsSf https://astral.sh/uv/install.sh | sh # Create a virtual environment uv venv # Activate the virtual environment # On macOS/Linux: source .venv/bin/activate # On Windows: .venv\Scripts\activate # Install the package uv pip install -e .
- Authenticate with TickTick:
# Run the authentication flow uv run -m ticktick_mcp.cli auth
This will:
- Ask for your TickTick Client ID and Client Secret
- Open a browser window for you to log in to TickTick
- Automatically save your access tokens to a
.envfile
- Test your configuration:
uv run test_server.py
This will verify that your TickTick credentials are working correctly.
Authentication with TickTick
This server uses OAuth2 to authenticate with TickTick. The setup process is straightforward:
- Register your application at the [TickTick Developer Center](https://developer.ticktick.com/ma
1f25959deeccOBSERVED · 2026-10-05Exposed tools (22)
15 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
batch_create_tasks | write | |
complete_task | read | |
create_project | write | |
create_subtask | write | |
create_task | write | |
delete_project | destructive | |
delete_task | destructive | |
get_all_tasks | read | Get all tasks from TickTick. Ignores closed projects. |
get_engaged_tasks | read | |
get_next_tasks | read | |
get_overdue_tasks | read | Get all overdue tasks from TickTick. Ignores closed projects. |
get_project | read | |
get_project_tasks | read | |
get_projects | read | Get all projects from TickTick. |
get_task | read | |
get_tasks_by_priority | read | |
get_tasks_due_in_days | read | |
get_tasks_due_this_week | read | Get all tasks from TickTick that are due within the next 7 days. Ignores closed projects. |
get_tasks_due_today | read | Get all tasks from TickTick that are due today. Ignores closed projects. |
get_tasks_due_tomorrow | read | Get all tasks from TickTick that are due today. Ignores closed projects. |
search_tasks | read | |
update_task | write |
Trust audit
SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
delete_project, delete_task
.env.template
mcp, python-dotenv, requests
- Automatically save your access tokens to a `.env` file
The server handles token refresh automatically, so you won't need to reauthenticate unless you revoke access or delete your `.env` file.
In order to call TickTick's Open API, it is necessary to obtain an access token for the corresponding user. TickTick uses the OAuth2 protocol to obtain the access token.
curl -LsSf https://astral.sh/uv/install.sh | sh
To exchange the authorization code for an access token, make a POST request to `https://ticktick.com/oauth/token` with the following parameters(Content-Type: application/x-www-form-urlencoded):
Gates applied: no_behavioural_pass, no_license.
1f25959deeccfull audit observations/trust-audit/mcp-server/jacepark12__ticktick.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | 1f25959deecc | SAFE | B | 87 | first audit |
Questions
What is the TickTick MCP server?
MCP server that interacts with TickTick (Dida 365) via the TickTick Open API
What tools does TickTick expose?
22 in total: 15 read-only, 5 that write, and 2 that can delete or overwrite (delete_project, delete_task). Every one is listed on this page with its risk.
Is TickTick safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does TickTick need?
It reads TICKTICK_ACCESS_TOKEN, TICKTICK_AUTH_URL, TICKTICK_CLIENT_SECRET, TICKTICK_REFRESH_TOKEN and TICKTICK_TOKEN_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does TickTick run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (1f25959deecc), read on 2026-10-05. The repository is watched and re-audited when it changes.