LinearCAUTION
MCP server that enables AI assistants to interact with Linear project management system through natural language, allowing users to retrieve, create, and update issues, projects, and teams.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for the Linear GraphQL API, built for real project-management workflows — not just basic issue CRUD.
[](https://www.npmjs.com/package/@tacticlaunch/mcp-linear)
Features
MCP Linear bridges AI assistants and Linear by implementing the MCP protocol. With it you can:
- Retrieve issues, projects, teams, cycles, milestones, roadmaps, customers, customer needs, and workspace/project/initiative/team/issue/release/cycle documents
- Create and update issues, change status, assign, and comment
- Manage projects, full diff-aware project and initiative update lifecycles, milestones, roadmaps, saved views, and favorites
- Create and manage workspace webhooks, including updates and signing-secret rotation
- Prepare OAuth app manifests and authorization URLs, issue scoped client-credentials tokens, or manage child OAuth apps when authenticated as a managing OAuth application
- Work with templates, custom fields, and attachments
- Work with customer records, customer statuses/tiers, and customer needs linked to issues or projects
- Read notifications, subscriptions, sessions, audits, and integrations without leaving MCP
- Inspect rate-limit and server health before running heavy planning sessions
See TOOLS.md for the full inventory.
MCP-native resources and prompts
The server exposes MCP resources and prompts in addition to tools, including:
- Resources:
linear://viewer,linear://organization,linear://teams, `linear://project
afc93e8fd672OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-linear --env LINEAR_API_KEY=${LINEAR_API_KEY} --env LINEAR_API_TOKEN=${LINEAR_API_TOKEN} --env LINEAR_OAUTH_ACCESS_TOKEN=${LINEAR_OAUTH_ACCESS_TOKEN} --env LINEAR_OAUTH_CLIENT_ID=${LINEAR_OAUTH_CLIENT_ID} -- npx -y @tacticlaunch/[email protected]{
"mcpServers": {
"mcp-linear": {
"command": "npx",
"args": [
"-y",
"@tacticlaunch/[email protected]"
],
"env": {
"LINEAR_API_KEY": "${LINEAR_API_KEY}",
"LINEAR_API_TOKEN": "${LINEAR_API_TOKEN}",
"LINEAR_OAUTH_ACCESS_TOKEN": "${LINEAR_OAUTH_ACCESS_TOKEN}",
"LINEAR_OAUTH_CLIENT_ID": "${LINEAR_OAUTH_CLIENT_ID}"
}
}
}
}Exposed tools (18)
16 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Beta | read | |
Platform | read | Build the platform |
Project | read | |
Severity | read | Risk score |
audience | read | Optional audience such as execs, eng, or customers |
customFieldValues | read | Issue custom field values |
customFields | read | List custom field definitions |
documentId | read | Linear document ID |
draft-project-update | write | Draft a project update using current project issues and documents |
focus | read | Optional focus area such as risks, scope, or delivery |
issueCustomFieldUpdate | write | Update a custom field value for an issue |
issueId | read | Linear issue ID or identifier |
issues | read | List issues |
projectId | read | Linear project ID to summarize |
summarize-document | read | Summarize a Linear document and connect it to the surrounding project context |
summarize-project-status | read | Summarize project status using Linear project, issue, and document resources |
title | read | Issue title |
triage-issue | read | Triage a Linear issue using the canonical issue resource |
Trust audit
CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (20)
print(` Access token: ${maskToken(credentials.accessToken)}`);print(` Refresh token: ${credentials.refreshToken ? 'stored' : 'none'}`);token: 'refreshed-access-token',
token: 'refreshed-access-token',
rotateSecretWebhook: jest.fn().mockResolvedValue({ success: true, secret: 'rotated-webhook-secret' }),secret: 'rotated-webhook-secret',
import { MCPToolDefinition } from '../../types.js';} from '../../tool-annotations.js';
import { MCPToolDefinition } from '../../types.js';} from '../../tool-annotations.js';
import { MCPToolDefinition } from '../../types.js';'https://169.254.169.254/webhooks/linear', // link-local / metadata
`http://127.0.0.1:${pending.port}/callback?code=auth-code-1&state=expected-state`,`http://127.0.0.1:${pending.port}/callback?code=auth-code-1&state=attacker-state`,`http://127.0.0.1:${pending.port}/callback?error=access_denied&state=expected-state`,const stray = await fetch(`http://127.0.0.1:${pending.port}/favicon.ico`);`http://127.0.0.1:${pending.port}/callback?code=auth-code-2&state=expected-state`,@linear/sdk, @modelcontextprotocol/sdk, @types/cors, @types/express, cors, dotenv, express, graphql
Client-credentials tokens normally last 30 days and do not include refresh tokens. Linear allows multiple active tokens only when they share the same scope set; requesting a different scope set revoke
Linear exposes managed OAuth application lifecycle operations as an alpha GraphQL surface and does not yet include first-class methods for them in `@linear/sdk`; this server therefore uses minimal raw
Gates applied: no_behavioural_pass.
afc93e8fd672full audit observations/trust-audit/mcp-server/tacticlaunch__linear-13.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | afc93e8fd672 | CAUTION | C | 75 | first audit |
Questions
What is the Linear MCP server?
MCP server that enables AI assistants to interact with Linear project management system through natural language, allowing users to retrieve, create, and update issues, projects, and teams.
What tools does Linear expose?
18 in total: 16 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Linear safe to connect to an agent?
With care. The audit graded it C (75/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Linear need?
It reads LINEAR_API_KEY, LINEAR_API_TOKEN, LINEAR_OAUTH_ACCESS_TOKEN, LINEAR_OAUTH_CLIENT_ID, LINEAR_OAUTH_CLIENT_SECRET and LINEAR_WEBHOOK_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Linear run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @tacticlaunch/mcp-linear at 1.4.4.
How current is this page?
The grade is for one exact copy of the source (afc93e8fd672), read on 2026-10-07. The repository is watched and re-audited when it changes.