Atlas / MCP servers / taiste / Harvest

HarvestSAFE

mcp/taiste/harvest

MCP Server for Harvest

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
34 18r · 12w · 4d
Transport
stdio
License
MIT
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/taiste-harvest-mcp-server)

This MCP (Model Context Protocol) server provides integration with the Harvest time tracking and project management API. It allows Claude and other MCP-compatible AI assistants to interact with your Harvest account, helping you manage time entries, projects, clients, and more.

Features

The server provides the following functionality:

Users

  • List users
  • Get user details

Time Entries

  • List time entries with filtering options
  • Create new time entries
  • Start/stop timers
  • Query time entry details
  • Get unsubmitted timesheets (time entries not yet submitted for approval)

Projects

  • List projects with filtering options (by client, isactive, updatedsince, page, per_page)
  • Retrieve detailed project information
  • Create new projects
  • Update existing projects (also used to archive: pass is_active=False)
  • Delete projects (destructive — also deletes the project's time entries and expenses, though invoices are retained; archiving is recommended instead)

Task Assignments

  • List task assignments (account-wide or scoped to a project)
  • Retrieve detailed task assignment information
  • Create new task assignments (link a task to a project)
  • Update existing task assignments
  • Delete task assignments (only when no time entries are logged against them)

User Assignments

  • List user assignments (account-wide or scoped to a project)
  • Retrieve detailed user assignment information
  • Create new user assignments (link a user to a project)
  • Update existing user assignments
  • Delete user assignments (only when no time entries or expenses are logged against them)

Clients

  • List clients with filtering options
  • Retrieve detailed client information

Tasks

  • List available tasks with filtering options

Estimates

  • List estimates with filtering options (by client, state, date r
Read from source at commit 11527c7930ceOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add harvest-mcp --env HARVEST_API_KEY=${HARVEST_API_KEY} -- uvx harvest-mcp
claude-desktop
{
  "mcpServers": {
    "harvest-mcp": {
      "command": "uvx",
      "args": [
        "harvest-mcp"
      ],
      "env": {
        "HARVEST_API_KEY": "${HARVEST_API_KEY}"
      }
    }
  }
}
03

Exposed tools (34)

18 read · 12 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
change_estimate_statereadChange the state of an estimate by creating a state-transition message.
create_estimatewriteCreate a new estimate.
create_projectwriteCreate a new project.
create_task_assignmentwriteCreate a task assignment, linking a task to a project.
create_time_entrywriteCreate a new time entry.
create_user_assignmentwriteCreate a user assignment, linking a user to a project.
delete_estimatedestructiveDelete an estimate.
delete_projectdestructiveDelete a project.
delete_task_assignmentdestructiveDelete a task assignment.
delete_user_assignmentdestructiveDelete a user assignment.
get_client_detailsreadGet detailed information about a specific client.
get_estimate_by_numberreadRetrieve an estimate by its human-readable number (e.g.
get_estimate_detailsreadRetrieve details for a specific estimate.
get_project_detailsreadGet detailed information about a specific project.
get_task_assignment_detailsreadGet detailed information about a specific task assignment.
get_unsubmitted_timesheetsreadGet unsubmitted timesheets (time entries that haven
get_user_assignment_detailsreadGet detailed information about a specific user assignment.
get_user_detailsreadRetrieve details for a specific user.
list_clientsreadList clients with optional filtering.
list_estimate_messagesreadList messages associated with an estimate.
list_estimatesreadList estimates with optional filtering.
list_projectsreadList projects with optional filtering.
list_task_assignmentsreadList task assignments with optional filtering.
list_tasksreadList all tasks with optional filtering.
list_time_entriesreadList time entries with optional filtering.
list_user_assignmentsreadList user assignments with optional filtering.
list_usersreadList all users in your Harvest account.
send_estimate_messagewriteCreate an estimate message. **This sends an email to the recipients.**
start_timerwriteStart a new timer.
stop_timerwriteStop a running timer.
update_estimatewriteUpdate an existing estimate.
update_projectwriteUpdate an existing project.
update_task_assignmentwriteUpdate an existing task assignment.
update_user_assignmentwriteUpdate an existing user assignment.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_estimate, delete_project, delete_task_assignment, delete_user_assignment
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 11527c7930cefull audit observations/trust-audit/mcp-server/taiste__harvest.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0811527c7930ceSAFEB89first audit
06

Questions

What is the Harvest MCP server?

MCP Server for Harvest

What tools does Harvest expose?

34 in total: 18 read-only, 12 that write, and 4 that can delete or overwrite (delete_estimate, delete_project, delete_task_assignment, delete_user_assignment). Every one is listed on this page with its risk.

Is Harvest safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Harvest need?

It reads HARVEST_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Harvest run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as harvest-mcp.

How current is this page?

The grade is for one exact copy of the source (11527c7930ce), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement