HarvestSAFE
MCP Server for Harvest
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/taiste-harvest-mcp-server)
This MCP (Model Context Protocol) server provides integration with the Harvest time tracking and project management API. It allows Claude and other MCP-compatible AI assistants to interact with your Harvest account, helping you manage time entries, projects, clients, and more.
Features
The server provides the following functionality:
Users
- List users
- Get user details
Time Entries
- List time entries with filtering options
- Create new time entries
- Start/stop timers
- Query time entry details
- Get unsubmitted timesheets (time entries not yet submitted for approval)
Projects
- List projects with filtering options (by client, isactive, updatedsince, page, per_page)
- Retrieve detailed project information
- Create new projects
- Update existing projects (also used to archive: pass
is_active=False) - Delete projects (destructive — also deletes the project's time entries and expenses, though invoices are retained; archiving is recommended instead)
Task Assignments
- List task assignments (account-wide or scoped to a project)
- Retrieve detailed task assignment information
- Create new task assignments (link a task to a project)
- Update existing task assignments
- Delete task assignments (only when no time entries are logged against them)
User Assignments
- List user assignments (account-wide or scoped to a project)
- Retrieve detailed user assignment information
- Create new user assignments (link a user to a project)
- Update existing user assignments
- Delete user assignments (only when no time entries or expenses are logged against them)
Clients
- List clients with filtering options
- Retrieve detailed client information
Tasks
- List available tasks with filtering options
Estimates
- List estimates with filtering options (by client, state, date r
11527c7930ceOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add harvest-mcp --env HARVEST_API_KEY=${HARVEST_API_KEY} -- uvx harvest-mcp{
"mcpServers": {
"harvest-mcp": {
"command": "uvx",
"args": [
"harvest-mcp"
],
"env": {
"HARVEST_API_KEY": "${HARVEST_API_KEY}"
}
}
}
}Exposed tools (34)
18 read · 12 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
change_estimate_state | read | Change the state of an estimate by creating a state-transition message. |
create_estimate | write | Create a new estimate. |
create_project | write | Create a new project. |
create_task_assignment | write | Create a task assignment, linking a task to a project. |
create_time_entry | write | Create a new time entry. |
create_user_assignment | write | Create a user assignment, linking a user to a project. |
delete_estimate | destructive | Delete an estimate. |
delete_project | destructive | Delete a project. |
delete_task_assignment | destructive | Delete a task assignment. |
delete_user_assignment | destructive | Delete a user assignment. |
get_client_details | read | Get detailed information about a specific client. |
get_estimate_by_number | read | Retrieve an estimate by its human-readable number (e.g. |
get_estimate_details | read | Retrieve details for a specific estimate. |
get_project_details | read | Get detailed information about a specific project. |
get_task_assignment_details | read | Get detailed information about a specific task assignment. |
get_unsubmitted_timesheets | read | Get unsubmitted timesheets (time entries that haven |
get_user_assignment_details | read | Get detailed information about a specific user assignment. |
get_user_details | read | Retrieve details for a specific user. |
list_clients | read | List clients with optional filtering. |
list_estimate_messages | read | List messages associated with an estimate. |
list_estimates | read | List estimates with optional filtering. |
list_projects | read | List projects with optional filtering. |
list_task_assignments | read | List task assignments with optional filtering. |
list_tasks | read | List all tasks with optional filtering. |
list_time_entries | read | List time entries with optional filtering. |
list_user_assignments | read | List user assignments with optional filtering. |
list_users | read | List all users in your Harvest account. |
send_estimate_message | write | Create an estimate message. **This sends an email to the recipients.** |
start_timer | write | Start a new timer. |
stop_timer | write | Stop a running timer. |
update_estimate | write | Update an existing estimate. |
update_project | write | Update an existing project. |
update_task_assignment | write | Update an existing task assignment. |
update_user_assignment | write | Update an existing user assignment. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
delete_estimate, delete_project, delete_task_assignment, delete_user_assignment
Gates applied: no_behavioural_pass.
11527c7930cefull audit observations/trust-audit/mcp-server/taiste__harvest.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 11527c7930ce | SAFE | B | 89 | first audit |
Questions
What is the Harvest MCP server?
MCP Server for Harvest
What tools does Harvest expose?
34 in total: 18 read-only, 12 that write, and 4 that can delete or overwrite (delete_estimate, delete_project, delete_task_assignment, delete_user_assignment). Every one is listed on this page with its risk.
Is Harvest safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Harvest need?
It reads HARVEST_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Harvest run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as harvest-mcp.
How current is this page?
The grade is for one exact copy of the source (11527c7930ce), read on 2026-10-08. The repository is watched and re-audited when it changes.