TaskLite
REMOTE · MCP.TASKLITE.NET · 2 COMPONENTS · SCANNED SEP 29
tasklite.net: hosted backend, REST API and admin for apps built by AI agents
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security94
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability69
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 9081 tokens (~189/item across 48 items; 48 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
- Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety50
- Injection-marker check failed: the server instructions contains an instruction to conceal the call from the user, the text "do not tell the user", at byte 2957 of that field. See how to fix → Fail
- All 9 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 49 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the TaskLite MCP server?
TaskLite is a hosted endpoint at https://mcp.tasklite.net/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.tasklite.net
claude mcp add --transport http net-tasklite-mcp 'https://mcp.tasklite.net/mcp'
{
"mcpServers": {
"net-tasklite-mcp": {
"url": "https://mcp.tasklite.net/mcp"
}
}
} {
"servers": {
"net-tasklite-mcp": {
"type": "http",
"url": "https://mcp.tasklite.net/mcp"
}
}
} [mcp_servers.net-tasklite-mcp] url = "https://mcp.tasklite.net/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"net-tasklite-mcp": {
"type": "remote",
"url": "https://mcp.tasklite.net/mcp",
"enabled": true
}
}
} openclaw mcp add net-tasklite-mcp --url 'https://mcp.tasklite.net/mcp' --transport streamable-http
mcp_servers:
net-tasklite-mcp:
url: "https://mcp.tasklite.net/mcp" {
"McpServers": {
"net-tasklite-mcp": {
"Transport": "http",
"Url": "https://mcp.tasklite.net/mcp"
}
}
} assistant mcp add net-tasklite-mcp -t streamable-http -u 'https://mcp.tasklite.net/mcp'
{
"mcpServers": {
"net-tasklite-mcp": {
"type": "http",
"url": "https://mcp.tasklite.net/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 0
- Tool “deploy_frontend” rewrote its description, which is the text the model reads security
- Tool “create_automation” rewrote its description, which is the text the model reads security
- Schema quality: 8233 → 9081 ▼ functional
- Server version: 0.14.4 → 0.15.0 functional
- New tool “get_deployment_files” functional
- New tool “update_automation” functional
- “create_automation” added an optional parameter “conditions” cosmetic
- “deploy_frontend” added an optional parameter “fromAppId” cosmetic
- “deploy_frontend” added an optional parameter “fromVersion” cosmetic
- “update_app_endpoint” added an optional parameter “rowLevelSecurity” cosmetic
- “create_column” reworded the description of “type” cosmetic
- “create_app_endpoint” reworded the description of “rowLevelSecurity” cosmetic
- 23 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +1
- New tool “revoke_upload_link”, which the server declares destructive security
- Tool “deploy_frontend” rewrote its description, which is the text the model reads security
- Server version: 0.14.3 → 0.14.4 functional
- New tool “request_file_upload” functional
- New tool “list_uploaded_files” functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://mcp.tasklite.net/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=tasklite.net | CN=WE1,O=Google Trust Services,C=US | 11 Sept 2026 | 10 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | feb3bced2fd95261358bacf4c21cc45 |
| SANs: tasklite.net, *.tasklite.net | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.tasklite.net. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| net. | present | 37331 | 13 | Verified |
| tasklite.net. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="TaskLite MCP", resource_metadata="https://mcp.tasklite.net/.well-known/oauth-protected-resource"
Bearer realm="TaskLite MCP", resource_metadata="https://mcp.tasklite.net/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| strict-transport-security | max-age=31536000 |
| x-content-type-options | nosniff |
Protected resource metadata
| Document | https://mcp.tasklite.net/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp.tasklite.net |
| Authorisation server | https://api.tasklite.net |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.tasklite.net/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.tasklite.net/mcp | HTTPS enforced | 301 | https://mcp.tasklite.net/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_comment ~125
Post a comment on an item's thread. To notify people, pass their user ids in mentionedUserIds (each also appears as an @mention). attachmentIds references already-uploaded files. Needs projectId and itemId.
| Name | Type | Req | Description |
|---|---|---|---|
| attachmentIds | array | – | Ids of already-uploaded attachments to link |
| content | string | yes | The comment text |
| itemId | string | yes | Item (row) id |
| mentionedUserIds | array | – | User ids to @mention and notify |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
build_backend ~344
Build a whole backend in one call from a spec you compose: the project, its boards, their typed columns (including relations between the boards), optional sample rows, and optionally a published REST API with one endpoint per board and a server-side key. Use it whenever the user describes a system ("a backend for my repair shop: customers, orders, payments") instead of calling create_project, create_board, create_column, create_app, publish_app, create_app_endpoint and create_app_api_key one by one. You do the design, pick column types by meaning (phone, date, currency, dropdown/status with options for closed choices), link boards with a relation column (type "relation", relatedBoard: "<board name in this spec>", relationType: many_to_one for an order→customer link), and this tool executes it and returns one compact summary. API field names are derived from column names and never collide with reserved item fields, so there is nothing to retry. Boards are created as plain data tables (kind "data": only the columns you define, no task fields); set kind "tasks" on a board where people track work to do and want status, priority, assignee and due date built in. Every row still has a title.
| Name | Type | Req | Description |
|---|---|---|---|
| api | object | – | Include to publish a REST API over every board and mint a key; omit for a boards-only build |
| boards | array | yes | The boards (tables) of the backend, in any order |
| organizationId | string | – | Organization id; needed only when the account belongs to several (the error then lists them) |
| project | object | yes | The project that holds the boards |
No output schema declared.
No examples provided.
configure_external_access ~279
Read or change how EXTERNAL users (people who sign up to your app through TaskLite auth) get into an organization. They have two ways in, and both obey the policy below: email and password (POST /auth/register-external with this organizationId, then POST /auth/login), or Google (POST /auth/google-external with a Google ID token and this organizationId). Either way the answer carries a token the app sends as Authorization: Bearer on every App API call. registrationPolicy: "open", in at once; "approval", an organization admin approves each signup (TaskLite mails the admins on every signup, and the person once approved; unapproved users are never billed); "closed", invite only, self-signup refused. appLoginUrl: the page of YOUR app where these users log in, it becomes the "Log in" button in the approval email, so set it whenever you deploy an app that uses this flow; pass "" to clear. Call with no changes to just read the current settings. Requires organization admin.
| Name | Type | Req | Description |
|---|---|---|---|
| appLoginUrl | string | – | https URL of your app's login page for external users; "" clears it |
| organizationId | string | – | Defaults to the credential organization |
| registrationPolicy | string | – | How external sign-ups are admitted: open, approval or closed |
No output schema declared.
No examples provided.
create_app ~81
Create an app, a named API surface over the boards of a project, for an external frontend. Then add endpoints and an API key.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Human-readable name |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
create_app_api_key ~161
Create an API key for an app. SECURITY: the key must live server-side only (env var, Next.js API routes), never in browser code. If the app has its own users, the server also sends `X-App-User: <user id>` with the key so per-user endpoints know who is acting.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| name | string | – | Human-readable name |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| scopes | array | – | Permissions recorded on the key: ["read"] or ["read","write"]. Omit to match the app: write when any endpoint accepts POST, PATCH or DELETE. |
No output schema declared.
No examples provided.
create_app_endpoint ~275
Expose a board as a REST endpoint of an app: /apps/{appSlug}/api/{slug}. exposedColumns limits which columns are readable/writable. rowLevelSecurity.enabled makes the endpoint per-user: the developer's server sends `X-App-User: <their user id>` next to the API key, and the endpoint returns, updates and deletes ONLY that user's rows (401 without the header). Use it whenever the app has its own users.
| Name | Type | Req | Description |
|---|---|---|---|
| allowedMethods | array | – | HTTP methods the endpoint accepts: GET, POST, PATCH, DELETE |
| appId | string | yes | App id or slug (from list_apps / create_app) |
| boardId | string | yes | Board id (from list_boards / create_board) |
| exposedColumns | array | – | Columns the endpoint reads and writes, with the JSON key each one gets; without it the endpoint returns bare metadata |
| name | string | yes | Human-readable name |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| rowLevelSecurity | object | – | Row-level security. Off: whoever holds the app key reads everything. On: every request must name a signed-in user, and mode decides which rows they reach |
| slug | string | yes | URL slug: lowercase letters, digits and dashes |
No output schema declared.
No examples provided.
create_automation ~569
Create an automation on a board: when something happens, do something. The most useful action here is http_request, which calls an external API and writes the answer back into columns, pair it with the "scheduled" trigger and the board keeps itself up to date (prices, exchange rates, shipment status, weather). Triggers: item_created, status_changed, column_value_changed, date_approaching, scheduled. Actions: http_request, send_notification, send_email, change_status, set_column_value, create_cross_board_item, send_webhook. Two more things every action list can use: a { type: "delay", config: { minutes | hours | days } } action pauses the run and resumes the actions after it later (reminders, follow-ups); and any network action (http_request, send_webhook, send_email, send_whatsapp) may carry config.retry: { attempts (1-5), delaySeconds (1-60) }. send_webhook accepts config.secret for an HMAC signature. create_cross_board_item copies a new row to another board: config { targetBoardId, title?: "{{item.title}}", columnValues: { "<column id on the TARGET board>": "{{<column NAME on this board>}}" } }; there is no mapping field, and a column left out is not copied. To act only on some rows pass conditions, e.g. [{ field: "<column id on this board>", operator: "equals", value: "New seller" }]. Change an automation later with update_automation; call list_automations first so you do not add a second one that does the same thing.
| Name | Type | Req | Description |
|---|---|---|---|
| actions | array | yes | e.g. [{ type: "http_request", config: { url: "https://api.frankfurter.app/latest?from=USD&to=ILS", method: "GET", responseMapping: [{ path: "rates.ILS", columnId: "<column id from get_board_schema>"… |
| boardId | string | yes | Board id (from list_boards / create_board) |
| conditions | array | – | Run only for rows that match, e.g. [{ field: "<column id>", operator: "equals", value: "New seller" }] |
| isActive | boolean | – | Whether it is active |
| name | string | yes | Human-readable name |
| projectId | string | yes | Project id (from list_projects / create_project) |
| trigger | string | yes | Event that starts the automation: item_created, status_changed, column_value_changed, date_approaching, or scheduled (cron) |
| triggerConfig | object | – | e.g. { cron: "0 8 * * *" } for scheduled, { columnName } for column_value_changed |
No output schema declared.
No examples provided.
create_board ~183
Create a board (a data table) inside a project. Add typed columns with create_column afterwards. kind: "tasks" (default) also gives the board the built-in task columns, status, priority, assignee, due date, tags, for work people track; "data" creates a plain table with only the columns you add, for records such as customers, products or orders (requires a TaskLite server from 2026-09-06; older servers ignore kind).
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | – | Free-text description |
| kind | string | – | "tasks": with the built-in task columns (status, priority, assignee, due date, tags). "data": only the columns you add. Default tasks. |
| name | string | yes | Human-readable name |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
create_column ~352
Add a typed column to a board. Valid types: text, rich_text, number, status, date, datetime, duration, people, checkbox, dropdown, label, priority, link, email, phone, relation, lookup, rollup, formula, rating, currency, file. Choose by meaning, date for dates, phone for phones, number/currency for amounts, dropdown/status (with settings.options as an array of labels) for closed choices; text is for free text only. An obvious name/type mismatch is rejected with the suggested type; pass force:true to override. Rules go in settings.validation: { unique, min, max, minLength, maxLength, pattern, patternMessage }, enforced on every write (UI, MCP, App API). Closed choices (dropdown/status) reject values outside settings.options unless settings.allowCustom is true.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| force | boolean | – | Create the column even when the name suggests a different type |
| isRequired | boolean | – | Require a non-blank value on every App API create |
| name | string | yes | Human-readable name |
| projectId | string | yes | Project id (from list_projects / create_project) |
| settings | object | – | Type-specific settings. For dropdown/status/priority: options, either as labels ["A","B"] or as full objects [{value,label,color}], labels are expanded server-side, and colors are assigned if you do… |
| type | string | yes | Action type: http_request, send_notification, send_email, send_whatsapp, change_status, set_column_value, create_cross_board_item, send_webhook or delay |
No output schema declared.
No examples provided.
create_item ~220
Create an item (row) with all of its data in one call. cells maps columnId -> value (use get_board_schema for column ids); every cell is saved with the row. Use set_cell only for later edits.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| cells | object | – | Cell values keyed by column id: { "<columnId>": value }. Scalars, { amount, currency } for currency, { relatedItemIds: [...] } for relations |
| description | string | – | Free-text description |
| dueDate | string | – | ISO date |
| priority | string | – | Priority: low, medium, high or urgent |
| projectId | string | yes | Project id (from list_projects / create_project) |
| status | string | – | Status value (todo, in_progress, done, or a value from the board's status options) |
| tags | array | – | Tags as an array of strings |
| title | string | yes | Item title, shown as the row name |
No output schema declared.
No examples provided.
create_project ~62
Create a project (a business process container). Boards with data live inside projects.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | – | Free-text description |
| name | string | yes | Human-readable name |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
delete_board ~78
Delete a board with every item on it. Destructive and not undoable, confirm with the user first, and prefer delete_column when only part of the model is wrong.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
delete_column ~95
Delete a column and every value stored in it. Destructive, confirm with the user first. Use update_column when the column is right but its name, type or options are wrong.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| columnId | string | yes | Column id (from get_board_schema) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
delete_comment ~88
Delete a comment from an item thread. Destructive, confirm with the user before calling. Needs projectId, itemId and the commentId.
| Name | Type | Req | Description |
|---|---|---|---|
| commentId | string | yes | Comment id (from list_comments / add_comment) |
| itemId | string | yes | Item id (from query_items / create_item) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
delete_item ~74
Delete an item. Destructive, confirm with the user before calling.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| itemId | string | yes | Item id (from query_items / create_item) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
delete_project ~95
Delete a project with every board, column and row inside it. Destructive: confirm with the user first, and name the project in the confirmation. The project goes to the organization recycle bin, so it can be restored from the admin until it is emptied.
| Name | Type | Req | Description |
|---|---|---|---|
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
deploy_frontend ~517
Deploy a static frontend to TaskLite hosting and get a live URL https://{slug}.tasklite.dev (HTTPS, auto-published on first deploy, versions kept for rollback_deployment). Hand over the frontend in ONE of three ways: `files`, the files inline (path + content), the way to go from ChatGPT or any hosted client: write index.html and its assets, then deploy in the same turn; `zipUrl`, a public https URL of a zip (a Lovable/Bolt export, a GitHub release asset); `dir`, a build output folder on this machine (only when the MCP runs locally next to the files); `fromAppId`, a version already hosted in the same organization, copied on the server (start a new app from an existing site, or bring an old version back as a new one; get_deployment_files reads a version first). A real build that already exists on the person's machine fits none of these from a hosted server: tell them to drop the zip on the app's Versions screen (the adminUrl of the app, then Versions), which deploys the same way and keeps the same version history. In the frontend, call the app API via relative /api/{endpoint}, the hosting proxy injects the app identity, so no key ships to the browser.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App UUID or slug (app-xxxxxx), see list_apps |
| dir | string | – | Local path to the BUILD OUTPUT directory (the one containing index.html), not the project root. Only where the MCP runs on the same machine as the files |
| files | array | – | The site files inline. Must include index.html. Up to 500 files / 8MB decoded, right for a frontend written in the conversation |
| fromAppId | string | – | Deploy a version that is already hosted, copied on the server: another app in the same organization (start a new app from it), or this same app (bring an old version back as a new one). Nothing passe… |
| fromVersion | integer | – | With fromAppId: which version to copy (from list_deployments). Default: the live one |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| zipUrl | string | – | Public https URL of a zip of the BUILD OUTPUT (index.html at the root, or inside a single top-level folder). Up to 50MB |
No output schema declared.
No examples provided.
export_project ~113
The whole project as JSON, boards, columns with settings, items with their cells keyed by column id. For migrations, backups and reading a system back. Items are capped per board for the model's sake; the REST endpoint GET /organizations/{orgId}/projects/{projectId}/export.json returns everything.
| Name | Type | Req | Description |
|---|---|---|---|
| maxItemsPerBoard | integer | – | Default 200 |
| organizationId | string | – | Defaults to the credential organization |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
fetch ~134
One project, board or item in full, by the id search returned (project:<id>, board:<projectId>:<boardId>, item:<projectId>:<boardId>:<itemId>) or by an app URL path. Returns { id, title, text, url, metadata }, the ChatGPT fetch contract; text is the record as JSON.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | An id from search, or an app URL path such as /projects/…/boards/…/items/… |
| organizationId | string | – | Only needed for project ids when the credential has no default organization; otherwise resolved automatically |
No output schema declared.
No examples provided.
get_app_spec ~216
Get the machine-readable spec of an app: base URL, endpoints, methods, fields, auth. Two formats: "tasklite" (default), the compact shape the frontend prompts are built from, and "openapi", a standard OpenAPI 3.1 document for developers and other tools. When the user asks for the OpenAPI spec, or wants to hand the API to a developer, pass format "openapi". appId accepts either the app UUID or its slug (app-xxxxxx); list_apps shows both. The returned baseUrl is absolute, use it verbatim, do not rebuild it from the admin URL.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| format | string | – | "tasklite" (default): compact endpoint list. "openapi": OpenAPI 3.1 document, every endpoint with typed fields, filter grammar, auth and errors |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
get_board_schema ~69
Get a board with its full column schema (ids, names, types, settings). Call this before creating items with cells.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
get_deployment_files ~308
Read back what a hosted frontend version is made of: every file with its size and its URL on that version, and the full text of the text files (HTML, CSS, JS, JSON, SVG...). This is how a new conversation continues a site an earlier one built: "take my Krispool site and keep going" starts here, not from scratch. For a site written by hand the files ARE the source. For a bundled build (Vite, React) the JS is minified output: fine to inspect, not something to edit, so ask for the project's source instead. Images and other binaries come back as URLs only. Text is capped at 512KB per file and 4MB per call; narrow with `paths` for a big site. To start another app from this version, or bring an old version back as a new one, use deploy_frontend with fromAppId.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| includeContent | boolean | – | false lists the files without their text, a cheap first look at a large site. Default true |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| paths | array | – | Only these files, as listed by a previous call, e.g. ["index.html", "css/site.css"] |
| version | integer | – | Version to read (from list_deployments). Default: the live version |
No output schema declared.
No examples provided.
get_frontend_prompt ~110
Get a ready-made prompt describing the app backend, for pasting into a frontend generator (v0/bolt/lovable/cursor). appId accepts the app UUID or its slug (app-xxxxxx), use list_apps to find it.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| tool | string | yes | Target tool the prompt is written for |
No output schema declared.
No examples provided.
list_app_endpoints ~88
List an app's REST endpoints, slug, board, allowed methods, and how many columns each exposes. An endpoint exposing 0 columns is broken: it returns only item metadata and silently discards writes.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
list_apps ~80
List the apps in the organization, id, slug, status. Call this first when you need an app id: the slug (app-xxxxxx) is what shows up in URLs and in generated code, and this is how you map it back to the app.
| Name | Type | Req | Description |
|---|---|---|---|
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
list_automations ~64
List the automations on a board, so you can see what already runs before adding another.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
list_boards ~89
List the boards inside a project, id, name, description. Every other board tool needs a boardId, and this is the only way to discover one without being handed a URL.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Defaults to 50 |
| page | number | – | 1-based; defaults to 1 |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
list_comments ~105
List the comments (the correspondence thread) on an item, oldest first. Each comment includes its author and any @mentions. Needs projectId and itemId (get itemId from query_items).
| Name | Type | Req | Description |
|---|---|---|---|
| itemId | string | yes | Item (row) id |
| limit | integer | – | Page size, default 20 |
| page | integer | – | 1-based page, default 1 |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
list_deployments ~69
List the hosted-frontend deployments of an app, versions, which one is live, and the public URL.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
list_organizations ~29
List the organizations the authenticated user belongs to. Use the returned id as organizationId in other tools.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_projects ~87
List projects in an organization. The API returns 50 per page, an organization with more than that needs page 2 and beyond, so check the returned total before assuming a project does not exist.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Defaults to 50 |
| organizationId | string | – | Defaults to the credential organization |
| page | number | – | 1-based; defaults to 1 |
No output schema declared.
No examples provided.
list_uploaded_files ~108
The files attached to an item, including everything that came in through a request_file_upload link, each with a download URL that is signed and short lived (mint a fresh one by calling again). Also lists the upload links on the item and how many files each has taken, which is how to tell whether the person you asked has delivered.
| Name | Type | Req | Description |
|---|---|---|---|
| itemId | string | yes | Item (row) id |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
publish_app ~58
Publish an app, required before its API endpoints accept external calls.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
push_status ~96
Whether an app can send push notifications to phones, and how many devices are registered. Push goes out through the customer's OWN Firebase project, so it has to be configured once per app before send_push automations do anything. This tool never returns the key.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
query_items ~397
List items (rows) of a board, including their cell values. Returns all items unless limit/page are given (the API defaults to 50 per page when unpaged, so the tool pages through and concatenates). Narrow the result with search, status, priority and sort instead of fetching everything. This is the admin view; the REST endpoints of a published app take a fuller grammar, filter[column][gte], relation filters, per-field search, see get_app_spec.
| Name | Type | Req | Description |
|---|---|---|---|
| archived | string | – | Which rows to include. Default active |
| boardId | string | yes | Board id (from list_boards / create_board) |
| excludeStatus | string | – | Only rows whose status is NOT one of these, comma separated, resolved like status. The way to ask for everything that is not done: excludeStatus "done" (task board) or "Completed" (a data board with… |
| limit | integer | – | Page size; omit to fetch all items |
| page | integer | – | 1-based page, only with limit |
| priority | string | – | Only rows with one of these priorities, comma separated (task boards only) |
| projectId | string | yes | Project id (from list_projects / create_project) |
| search | string | – | Free text; matches the row title and its text cells |
| sort | string | – | Sort by title, createdAt, updatedAt or status; prefix with "-" for descending, e.g. "-createdAt" for newest first. Anything else keeps the board order |
| status | string | – | Only rows whose status is one of these, comma separated. Matched against the board's status column by option value or label, case-insensitive: "todo,in_progress" on a task board, "Received,In Repair"… |
No output schema declared.
No examples provided.
reorder_columns ~88
Set the display order of a board's columns. Pass every column id in the wanted order (get_board_schema lists them).
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| columnIds | array | yes | Column ids in the new order (every column of the board) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
request_file_upload ~339
Create a link that puts files onto an item from outside TaskLite: the customer's photos, a signed contract, a logo, a build zip. Returns an address like https://app.tasklite.net/upload/<token> that anyone you hand it to can use with no account, no login and no API key; pass clientEmail and TaskLite emails the link for you. What arrives lands as attachments on that item, and list_uploaded_files reads them back with a download URL. This is the answer when the person has the file and the model does not: a hosted client cannot read a folder on someone's machine. The link is public for as long as it lasts, so keep expiryDays short and maxFiles tight, and revoke_upload_link when the material is in.
| Name | Type | Req | Description |
|---|---|---|---|
| clientEmail | string | – | Send the link to this address. Omit to get the link back and pass it on yourself |
| clientName | string | – | Who is being asked, shown on the upload page |
| clientPhone | string | – | Recorded with the request |
| expiryDays | integer | – | How long the link lives. Default 7 days |
| itemId | string | yes | Item (row) the files belong to, from query_items / create_item. Make the row first if the material has no home yet |
| maxFiles | integer | – | How many files the link accepts before it stops. Default 10 |
| message | string | – | What to upload, in the words the recipient will read: "the four room photos and the price list" |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
revoke_upload_link ~90
Close an upload link before it expires, so the address stops accepting files. The files already uploaded stay on the item. Use it as soon as the material is in, because until then anyone holding the link can add more.
| Name | Type | Req | Description |
|---|---|---|---|
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| tokenId | string | yes | Link id (the tokenId from request_file_upload) |
No output schema declared.
No examples provided.
rollback_deployment ~82
Point the live URL back at a previous deployment version (see list_deployments for available versions).
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| version | integer | yes | Deployment version number (from list_deployments) |
No output schema declared.
No examples provided.
search ~104
Full-text search across the projects, boards and items of the organization. Returns { results: [{ id, title, url }] }, the shape ChatGPT connectors and deep research expect; pass a result id to fetch for the full record. When you already know the board, query_items is cheaper and complete.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max results, default 20 |
| projectId | string | – | Limit the search to one project |
| query | string | yes | Search text |
No output schema declared.
No examples provided.
send_test_push ~125
Send one real push notification to the given app users, to prove the chain works before an automation depends on it. Confirm with the user first: this reaches actual phones.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| body | string | – | Notification body |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| title | string | – | Notification title; defaults to "TaskLite" |
| userIds | array | yes | App user ids to notify (the same ids row-level security uses) |
No output schema declared.
No examples provided.
set_cell ~99
Set a single cell value on an item by columnId.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| columnId | string | yes | Column id (from get_board_schema) |
| itemId | string | yes | Item (row) id |
| projectId | string | yes | Project id (from list_projects / create_project) |
| value | – | yes | The new cell value; shape depends on the column type |
No output schema declared.
No examples provided.
update_app_endpoint ~202
Change an existing endpoint, most often to set exposedColumns on one that was created without them. Get the endpoint id from list_app_endpoints and the column ids from get_board_schema.
| Name | Type | Req | Description |
|---|---|---|---|
| allowedMethods | array | – | HTTP methods the endpoint accepts: GET, POST, PATCH, DELETE |
| appId | string | yes | App id or slug (from list_apps / create_app) |
| endpointId | string | yes | Endpoint id (from list_app_endpoints) |
| exposedColumns | array | – | Replacement list of exposed columns (same shape as create_app_endpoint) |
| isActive | boolean | – | Whether it is active |
| name | string | – | Human-readable name |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| rowLevelSecurity | – | – | Replacement row-level security (same shape as create_app_endpoint); null turns it off |
| slug | string | – | URL slug: lowercase letters, digits and dashes |
No output schema declared.
No examples provided.
update_automation ~214
Change an existing automation: its actions, conditions, trigger config or name, or switch it off with isActive false. Fields left out stay as they are; actions and conditions, when given, replace the whole list. Use it to fix an automation instead of creating a second one next to it. Get the id from list_automations.
| Name | Type | Req | Description |
|---|---|---|---|
| actions | array | – | The full new list of actions (replaces the old one) |
| automationId | string | yes | Automation id (from list_automations) |
| boardId | string | yes | Board id the automation belongs to |
| conditions | array | – | Run only for rows that match, e.g. [{ field: "<column id>", operator: "equals", value: "New seller" }] |
| isActive | boolean | – | false switches it off, true on |
| name | string | – | New name |
| projectId | string | yes | Project id (from list_projects / create_project) |
| triggerConfig | object | – | New trigger config |
No output schema declared.
No examples provided.
update_board ~87
Rename a board or change its description. Structure (columns) is changed with update_column / delete_column / reorder_columns.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| description | string | – | Free-text description |
| name | string | – | Human-readable name |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
update_column ~249
Change a column after the fact: rename it, change its type (e.g. number -> currency), replace settings (dropdown options), or set isRequired / isHidden. A type change converts existing values (number↔currency, text→number/date/checkbox, anything→text) and clears the ones that cannot convert; the response carries conversion: { converted, cleared }. settings.validation rules apply here too.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| columnId | string | yes | Column id (from get_board_schema) |
| description | string | – | Free-text description |
| force | boolean | – | Skip the name/type sanity check |
| isHidden | boolean | – | Hide the column in the TaskLite UI |
| isRequired | boolean | – | Require a non-blank value on every App API create |
| name | string | – | Human-readable name |
| projectId | string | yes | Project id (from list_projects / create_project) |
| settings | object | – | Replaces the column settings, e.g. { options: [...] } for dropdown/status |
| type | string | – | New column type (same list as create_column) |
No output schema declared.
No examples provided.
update_comment ~90
Edit the text of an existing comment. Only the author can edit their comment. Needs projectId, itemId and the commentId.
| Name | Type | Req | Description |
|---|---|---|---|
| commentId | string | yes | Comment id (from list_comments) |
| content | string | yes | The new comment text |
| itemId | string | yes | Item (row) id |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
update_item ~175
Update item fields (title, description, status, priority, dueDate, tags).
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| description | string | – | Free-text description |
| dueDate | string | – | Due date, ISO 8601 (YYYY-MM-DD or full timestamp) |
| itemId | string | yes | Item (row) id |
| priority | string | – | Priority: low, medium, high or urgent |
| projectId | string | yes | Project id (from list_projects / create_project) |
| status | string | – | Status value (todo, in_progress, done, or a value from the board's status options) |
| tags | array | – | Tags as an array of strings |
| title | string | – | Item title, shown as the row name |
No output schema declared.
No examples provided.
What is the TaskLite MCP server?
TaskLite is an MCP server listed in the public MCP registry as net.tasklite/mcp. tasklite.net: hosted backend, REST API and admin for apps built by AI agents. This page covers its hosted endpoint (https://mcp.tasklite.net/mcp).
Is the TaskLite MCP server safe to use?
TaskLite scores 86 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the TaskLite MCP server expose?
TaskLite exposes 48 tools: list_organizations, configure_external_access, list_projects, list_boards, create_project, and 43 more. Their descriptions and schemas cost roughly 7,762 tokens of context every time the server is loaded.
Does the TaskLite MCP server require authentication?
Yes. TaskLite asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the TaskLite MCP server still maintained?
TaskLite is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.