TodoistSAFE
Full implementation of Todoist Rest API & support Todoist Sync API for MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Todoist MCP Server A Model Context Protocol (MCP) server implementation that integrates Claude and other AI assistants with Todoist, enabling natural language task management.
Features
- Complete Todoist API Integration: Access to the full Todoist REST API v2, and support for the Todoist Sync API through natural language
- Batch Processing: Client can process multiple tasks in a single request
- Search by name: AI can search for tasks, projects, and labels by name instead of ID
- Tasks: Create, update, close, reopen, move, and delete tasks using conversational language
- Projects: Create and manage projects and sections
- Comments: Add and manage comments on tasks and projects
- Labels: Create and manage personal and shared labels
- Smart Context: On startup, automatically provides your projects and labels to the AI via server instructions — no extra tool calls needed
- Prompt Support: You can easily provide information about your projects to client
Configuration
You'll need a Todoist API token to use this MCP server.
Getting a Todoist API Token
- Log in to your Todoist account
- Navigate to Settings → Integrations
- Find your API token under "Developer"
Usage
Add to mcpServers in your platform config:
"todoist": {
"command": "npx",
"args": ["-y", "todoist-mcp"],
"env": { "API_KEY": "your_todoist_api_token" }
}ed6aa6a9349dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add todoist-mcp --env API_KEY=${API_KEY} -- npx -y [email protected]{
"mcpServers": {
"todoist-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"API_KEY": "${API_KEY}"
}
}
}
}Exposed tools (35)
16 read · 13 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
close_tasks | read | Close tasks in Todoist |
create_comments | write | Create new comments in Todoist |
create_labels | write | Create a new personal labels in Todoist |
create_projects | write | Create new projects in Todoist |
create_sections | write | Create new sections in Todoist |
create_tasks | write | Create new tasks in Todoist |
delete_comments | destructive | Delete comments in Todoist |
delete_labels | destructive | Delete a personal label in Todoist |
delete_projects | destructive | Delete projects from Todoist |
delete_sections | destructive | Delete sections in Todoist |
delete_tasks | destructive | Delete tasks from Todoist |
get_collaborators | read | Get all collaborators for a project in Todoist |
get_comments | read | Get comments from Todoist by ID |
get_comments_list | read | Get comments list from Todoist |
get_labels | read | Get a personal label from Todoist |
get_labels_list | read | Get all personal labels from Todoist |
get_projects | read | Get projects from Todoist |
get_projects_list | read | Get all projects from Todoist |
get_sections | read | Get sections from Todoist |
get_sections_list | read | Get sections list from Todoist |
get_shared_labels | read | Get all shared labels from Todoist |
get_tasks | read | Get tasks from Todoist |
get_tasks_by_filter | read | Get tasks from Todoist using filter language. Use for queries like |
get_tasks_list | read | Get tasks list from Todoist. For advanced filtering use get_tasks_by_filter tool |
move_projects | write | Move a projects to a different parent in Todoist |
move_tasks | write | Move tasks to a different parent or section in Todoist. Exactly one of parent_id, section_id, or project_id must be provided |
projects_list | read | List of projects |
remove_shared_labels | destructive | Remove a shared label in Todoist |
rename_shared_labels | write | Rename a shared label in Todoist |
reopen_tasks | read | Reopen tasks in Todoist |
update_comments | write | Update comments in Todoist |
update_labels | write | Update a personal label in Todoist |
update_projects | write | Update projects in Todoist |
update_sections | write | Update sections in Todoist |
update_tasks | write | Update tasks in Todoist |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
delete_comments, delete_labels, delete_projects, delete_sections, delete_tasks, remove_shared_labels
@modelcontextprotocol/sdk, uuid, zod, @eslint/js, @types/node, @types/uuid, @vitest/coverage-v8, eslint
Gates applied: no_behavioural_pass.
ed6aa6a9349dfull audit observations/trust-audit/mcp-server/stanislavlysenko0912__todoist-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ed6aa6a9349d | SAFE | B | 89 | first audit |
Questions
What is the Todoist MCP server?
Full implementation of Todoist Rest API & support Todoist Sync API for MCP server
What tools does Todoist expose?
35 in total: 16 read-only, 13 that write, and 6 that can delete or overwrite (delete_comments, delete_labels, delete_projects, delete_sections, delete_tasks). Every one is listed on this page with its risk.
Is Todoist safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Todoist need?
It reads API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Todoist run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as todoist-mcp at 1.3.4.
How current is this page?
The grade is for one exact copy of the source (ed6aa6a9349d), read on 2026-10-07. The repository is watched and re-audited when it changes.