TaskLite
NPM · @TASKLITE/MCP · 2 COMPONENTS · SCANNED SEP 29
tasklite.net: hosted backend, REST API and admin for apps built by AI agents
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security81
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known high-severity CVE affects adm-zip 0.5.18, a direct dependency. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- 31 of 94 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency19
- Repository check failed: the declared repository URL redirects; it must resolve directly. See how to fix → View diagnostics → Fail
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 5 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability72
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 8611 tokens (~168/item across 51 items; 51 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
- Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety50
- Injection-marker check failed: the server instructions contains an instruction to conceal the call from the user, the text "do not tell the user", at byte 2957 of that field. See how to fix → Fail
- All 9 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 52 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the TaskLite MCP server?
TaskLite runs locally as an npm package, launched with npx -y @tasklite/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · @tasklite/mcp
claude mcp add net-tasklite-mcp -- npx -y @tasklite/mcp
{
"mcpServers": {
"net-tasklite-mcp": {
"command": "npx",
"args": [
"-y",
"@tasklite/mcp"
]
}
}
} {
"servers": {
"net-tasklite-mcp": {
"command": "npx",
"args": [
"-y",
"@tasklite/mcp"
]
}
}
} codex mcp add net-tasklite-mcp -- npx -y @tasklite/mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"net-tasklite-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"@tasklite/mcp"
],
"enabled": true
}
}
} openclaw mcp add net-tasklite-mcp --command npx --arg -y --arg @tasklite/mcp
mcp_servers:
net-tasklite-mcp:
command: "npx"
args: ["-y", "@tasklite/mcp"] {
"McpServers": {
"net-tasklite-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"@tasklite/mcp"
]
}
}
} assistant mcp add net-tasklite-mcp -t stdio -c npx -a -y @tasklite/mcp
{
"mcpServers": {
"net-tasklite-mcp": {
"command": "npx",
"args": [
"-y",
"@tasklite/mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.
- 25 Sept 26 −5
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
- CVE-2026-77301 affects this package: high ▼ security
- 17 Sept 26 +16
- Malware scan: unverified → pass ▲ security
- 16 Sept 26 −15
- Malware scan: pass → unverified ▼ security
- Package version: 0.14.3 → 0.14.4 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Analysed npm/@tasklite/mcp@0.14.4
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Vulnerabilities 3 findings
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-7q85-xj36-vmfc | CVE-2026-77301 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
| GHSA-vwc7-r8mq-g2x9 | CVE-2026-76845 | medium | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N | no |
| GHSA-xcpc-8h2w-3j85 | CVE-2026-39244 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
Background: What a vulnerability scan can and cannot prove →
Dependencies 94 packages
| Packages resolved | 94 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_comment ~125
Post a comment on an item's thread. To notify people, pass their user ids in mentionedUserIds (each also appears as an @mention). attachmentIds references already-uploaded files. Needs projectId and itemId.
| Name | Type | Req | Description |
|---|---|---|---|
| attachmentIds | array | – | Ids of already-uploaded attachments to link |
| content | string | yes | The comment text |
| itemId | string | yes | Item (row) id |
| mentionedUserIds | array | – | User ids to @mention and notify |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
build_backend ~344
Build a whole backend in one call from a spec you compose: the project, its boards, their typed columns (including relations between the boards), optional sample rows, and optionally a published REST API with one endpoint per board and a server-side key. Use it whenever the user describes a system ("a backend for my repair shop: customers, orders, payments") instead of calling create_project, create_board, create_column, create_app, publish_app, create_app_endpoint and create_app_api_key one by one. You do the design, pick column types by meaning (phone, date, currency, dropdown/status with options for closed choices), link boards with a relation column (type "relation", relatedBoard: "<board name in this spec>", relationType: many_to_one for an order→customer link), and this tool executes it and returns one compact summary. API field names are derived from column names and never collide with reserved item fields, so there is nothing to retry. Boards are created as plain data tables (kind "data": only the columns you define, no task fields); set kind "tasks" on a board where people track work to do and want status, priority, assignee and due date built in. Every row still has a title.
| Name | Type | Req | Description |
|---|---|---|---|
| api | object | – | Include to publish a REST API over every board and mint a key; omit for a boards-only build |
| boards | array | yes | The boards (tables) of the backend, in any order |
| organizationId | string | – | Organization id; needed only when the account belongs to several (the error then lists them) |
| project | object | yes | The project that holds the boards |
No output schema declared.
No examples provided.
configure_external_access ~279
Read or change how EXTERNAL users (people who sign up to your app through TaskLite auth) get into an organization. They have two ways in, and both obey the policy below: email and password (POST /auth/register-external with this organizationId, then POST /auth/login), or Google (POST /auth/google-external with a Google ID token and this organizationId). Either way the answer carries a token the app sends as Authorization: Bearer on every App API call. registrationPolicy: "open", in at once; "approval", an organization admin approves each signup (TaskLite mails the admins on every signup, and the person once approved; unapproved users are never billed); "closed", invite only, self-signup refused. appLoginUrl: the page of YOUR app where these users log in, it becomes the "Log in" button in the approval email, so set it whenever you deploy an app that uses this flow; pass "" to clear. Call with no changes to just read the current settings. Requires organization admin.
| Name | Type | Req | Description |
|---|---|---|---|
| appLoginUrl | string | – | https URL of your app's login page for external users; "" clears it |
| organizationId | string | – | Defaults to the credential organization |
| registrationPolicy | string | – | How external sign-ups are admitted: open, approval or closed |
No output schema declared.
No examples provided.
connect ~90
Connect this machine to an existing TaskLite account, or switch to a different one. Takes a personal API key (tl_...) created at TaskLite → Integrations → "Connect Claude Code". Replaces the current connection if there is one, use this to switch user or organization. The switch takes effect immediately; no restart.
| Name | Type | Req | Description |
|---|---|---|---|
| apiKey | string | yes | Personal TaskLite API key, starts with tl_ |
No output schema declared.
No examples provided.
connection_status ~32
Check whether this machine is connected to a TaskLite account. Call this first if any tool fails with an auth error.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
create_app ~81
Create an app, a named API surface over the boards of a project, for an external frontend. Then add endpoints and an API key.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Human-readable name |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
create_app_api_key ~161
Create an API key for an app. SECURITY: the key must live server-side only (env var, Next.js API routes), never in browser code. If the app has its own users, the server also sends `X-App-User: <user id>` with the key so per-user endpoints know who is acting.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| name | string | – | Human-readable name |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| scopes | array | – | Permissions recorded on the key: ["read"] or ["read","write"]. Omit to match the app: write when any endpoint accepts POST, PATCH or DELETE. |
No output schema declared.
No examples provided.
create_app_endpoint ~260
Expose a board as a REST endpoint of an app: /apps/{appSlug}/api/{slug}. exposedColumns limits which columns are readable/writable. rowLevelSecurity.enabled makes the endpoint per-user: the developer's server sends `X-App-User: <their user id>` next to the API key, and the endpoint returns, updates and deletes ONLY that user's rows (401 without the header). Use it whenever the app has its own users.
| Name | Type | Req | Description |
|---|---|---|---|
| allowedMethods | array | – | HTTP methods the endpoint accepts: GET, POST, PATCH, DELETE |
| appId | string | yes | App id or slug (from list_apps / create_app) |
| boardId | string | yes | Board id (from list_boards / create_board) |
| exposedColumns | array | – | Columns the endpoint reads and writes, with the JSON key each one gets; without it the endpoint returns bare metadata |
| name | string | yes | Human-readable name |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| rowLevelSecurity | object | – | Row-level security: when enabled, each app user sees and edits only their own rows |
| slug | string | yes | URL slug: lowercase letters, digits and dashes |
No output schema declared.
No examples provided.
create_automation ~406
Create an automation on a board: when something happens, do something. The most useful action here is http_request, which calls an external API and writes the answer back into columns, pair it with the "scheduled" trigger and the board keeps itself up to date (prices, exchange rates, shipment status, weather). Triggers: item_created, status_changed, column_value_changed, date_approaching, scheduled. Actions: http_request, send_notification, send_email, change_status, set_column_value, create_cross_board_item, send_webhook. Two more things every action list can use: a { type: "delay", config: { minutes | hours | days } } action pauses the run and resumes the actions after it later (reminders, follow-ups); and any network action (http_request, send_webhook, send_email, send_whatsapp) may carry config.retry: { attempts (1-5), delaySeconds (1-60) }. send_webhook accepts config.secret for an HMAC signature.
| Name | Type | Req | Description |
|---|---|---|---|
| actions | array | yes | e.g. [{ type: "http_request", config: { url: "https://api.frankfurter.app/latest?from=USD&to=ILS", method: "GET", responseMapping: [{ path: "rates.ILS", columnId: "<column id from get_board_schema>"… |
| boardId | string | yes | Board id (from list_boards / create_board) |
| isActive | boolean | – | Whether it is active |
| name | string | yes | Human-readable name |
| projectId | string | yes | Project id (from list_projects / create_project) |
| trigger | string | yes | Event that starts the automation: item_created, status_changed, column_value_changed, date_approaching, or scheduled (cron) |
| triggerConfig | object | – | e.g. { cron: "0 8 * * *" } for scheduled, { columnName } for column_value_changed |
No output schema declared.
No examples provided.
create_board ~183
Create a board (a data table) inside a project. Add typed columns with create_column afterwards. kind: "tasks" (default) also gives the board the built-in task columns, status, priority, assignee, due date, tags, for work people track; "data" creates a plain table with only the columns you add, for records such as customers, products or orders (requires a TaskLite server from 2026-09-06; older servers ignore kind).
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | – | Free-text description |
| kind | string | – | "tasks": with the built-in task columns (status, priority, assignee, due date, tags). "data": only the columns you add. Default tasks. |
| name | string | yes | Human-readable name |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
create_column ~365
Add a typed column to a board. Valid types: text, rich_text, number, status, date, datetime, duration, people, checkbox, dropdown, label, priority, link, email, phone, relation, lookup, rollup, formula, rating, currency, file. Choose by meaning, date for dates, phone for phones, number/currency for amounts, dropdown/status (with settings.options as an array of labels) for closed choices; text is for free text only. An obvious name/type mismatch is rejected with the suggested type; pass force:true to override. Rules go in settings.validation: { unique, min, max, minLength, maxLength, pattern, patternMessage }, enforced on every write (UI, MCP, App API). Closed choices (dropdown/status) reject values outside settings.options unless settings.allowCustom is true.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| force | boolean | – | Create the column even when the name suggests a different type |
| isRequired | boolean | – | Require a non-blank value on every App API create |
| name | string | yes | Human-readable name |
| projectId | string | yes | Project id (from list_projects / create_project) |
| settings | object | – | Type-specific settings. For dropdown/status/priority: options, either as labels ["A","B"] or as full objects [{value,label,color}], labels are expanded server-side, and colors are assigned if you do… |
| type | string | yes | Column type: text, rich_text, number, status, date, datetime, duration, people, checkbox, dropdown, label, priority, link, email, phone, relation, lookup, rollup, rating, currency, file |
No output schema declared.
No examples provided.
create_item ~220
Create an item (row) with all of its data in one call. cells maps columnId -> value (use get_board_schema for column ids); every cell is saved with the row. Use set_cell only for later edits.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| cells | object | – | Cell values keyed by column id: { "<columnId>": value }. Scalars, { amount, currency } for currency, { relatedItemIds: [...] } for relations |
| description | string | – | Free-text description |
| dueDate | string | – | ISO date |
| priority | string | – | Priority: low, medium, high or urgent |
| projectId | string | yes | Project id (from list_projects / create_project) |
| status | string | – | Status value (todo, in_progress, done, or a value from the board's status options) |
| tags | array | – | Tags as an array of strings |
| title | string | yes | Item title, shown as the row name |
No output schema declared.
No examples provided.
create_project ~62
Create a project (a business process container). Boards with data live inside projects.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | – | Free-text description |
| name | string | yes | Human-readable name |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
delete_board ~78
Delete a board with every item on it. Destructive and not undoable, confirm with the user first, and prefer delete_column when only part of the model is wrong.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
delete_column ~95
Delete a column and every value stored in it. Destructive, confirm with the user first. Use update_column when the column is right but its name, type or options are wrong.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| columnId | string | yes | Column id (from get_board_schema) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
delete_comment ~88
Delete a comment from an item thread. Destructive, confirm with the user before calling. Needs projectId, itemId and the commentId.
| Name | Type | Req | Description |
|---|---|---|---|
| commentId | string | yes | Comment id (from list_comments / add_comment) |
| itemId | string | yes | Item id (from query_items / create_item) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
delete_item ~74
Delete an item. Destructive, confirm with the user before calling.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| itemId | string | yes | Item id (from query_items / create_item) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
delete_project ~95
Delete a project with every board, column and row inside it. Destructive: confirm with the user first, and name the project in the confirmation. The project goes to the organization recycle bin, so it can be restored from the admin until it is emptied.
| Name | Type | Req | Description |
|---|---|---|---|
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
deploy_frontend ~379
Deploy a static frontend to TaskLite hosting and get a live URL https://{slug}.tasklite.dev (HTTPS, auto-published on first deploy, versions kept for rollback_deployment). Hand over the frontend in ONE of three ways: `files`, the files inline (path + content), the way to go from ChatGPT or any hosted client: write index.html and its assets, then deploy in the same turn; `zipUrl`, a public https URL of a zip (a Lovable/Bolt export, a GitHub release asset); `dir`, a build output folder on this machine (only when the MCP runs locally next to the files). A real build that already exists on the person's machine fits none of these from a hosted server: tell them to drop the zip on the app's Versions screen (the adminUrl of the app, then Versions), which deploys the same way and keeps the same version history. In the frontend, call the app API via relative /api/{endpoint}, the hosting proxy injects the app identity, so no key ships to the browser.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App UUID or slug (app-xxxxxx), see list_apps |
| dir | string | – | Local path to the BUILD OUTPUT directory (the one containing index.html), not the project root. Only where the MCP runs on the same machine as the files |
| files | array | – | The site files inline. Must include index.html. Up to 500 files / 8MB decoded, right for a frontend written in the conversation |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| zipUrl | string | – | Public https URL of a zip of the BUILD OUTPUT (index.html at the root, or inside a single top-level folder). Up to 50MB |
No output schema declared.
No examples provided.
disconnect ~49
Disconnect this machine from TaskLite by forgetting the stored credential. Use before connecting a different account, or to revoke local access. Does not delete anything in TaskLite itself and does not revoke the key server-side.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
export_project ~113
The whole project as JSON, boards, columns with settings, items with their cells keyed by column id. For migrations, backups and reading a system back. Items are capped per board for the model's sake; the REST endpoint GET /organizations/{orgId}/projects/{projectId}/export.json returns everything.
| Name | Type | Req | Description |
|---|---|---|---|
| maxItemsPerBoard | integer | – | Default 200 |
| organizationId | string | – | Defaults to the credential organization |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
fetch ~134
One project, board or item in full, by the id search returned (project:<id>, board:<projectId>:<boardId>, item:<projectId>:<boardId>:<itemId>) or by an app URL path. Returns { id, title, text, url, metadata }, the ChatGPT fetch contract; text is the record as JSON.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | An id from search, or an app URL path such as /projects/…/boards/…/items/… |
| organizationId | string | – | Only needed for project ids when the credential has no default organization; otherwise resolved automatically |
No output schema declared.
No examples provided.
get_app_spec ~216
Get the machine-readable spec of an app: base URL, endpoints, methods, fields, auth. Two formats: "tasklite" (default), the compact shape the frontend prompts are built from, and "openapi", a standard OpenAPI 3.1 document for developers and other tools. When the user asks for the OpenAPI spec, or wants to hand the API to a developer, pass format "openapi". appId accepts either the app UUID or its slug (app-xxxxxx); list_apps shows both. The returned baseUrl is absolute, use it verbatim, do not rebuild it from the admin URL.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| format | string | – | "tasklite" (default): compact endpoint list. "openapi": OpenAPI 3.1 document, every endpoint with typed fields, filter grammar, auth and errors |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
get_board_schema ~69
Get a board with its full column schema (ids, names, types, settings). Call this before creating items with cells.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
get_frontend_prompt ~110
Get a ready-made prompt describing the app backend, for pasting into a frontend generator (v0/bolt/lovable/cursor). appId accepts the app UUID or its slug (app-xxxxxx), use list_apps to find it.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| tool | string | yes | Target tool the prompt is written for |
No output schema declared.
No examples provided.
list_app_endpoints ~88
List an app's REST endpoints, slug, board, allowed methods, and how many columns each exposes. An endpoint exposing 0 columns is broken: it returns only item metadata and silently discards writes.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
list_apps ~80
List the apps in the organization, id, slug, status. Call this first when you need an app id: the slug (app-xxxxxx) is what shows up in URLs and in generated code, and this is how you map it back to the app.
| Name | Type | Req | Description |
|---|---|---|---|
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
list_automations ~64
List the automations on a board, so you can see what already runs before adding another.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
list_boards ~89
List the boards inside a project, id, name, description. Every other board tool needs a boardId, and this is the only way to discover one without being handed a URL.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Defaults to 50 |
| page | number | – | 1-based; defaults to 1 |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
list_comments ~105
List the comments (the correspondence thread) on an item, oldest first. Each comment includes its author and any @mentions. Needs projectId and itemId (get itemId from query_items).
| Name | Type | Req | Description |
|---|---|---|---|
| itemId | string | yes | Item (row) id |
| limit | integer | – | Page size, default 20 |
| page | integer | – | 1-based page, default 1 |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
list_deployments ~69
List the hosted-frontend deployments of an app, versions, which one is live, and the public URL.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
list_organizations ~29
List the organizations the authenticated user belongs to. Use the returned id as organizationId in other tools.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_projects ~87
List projects in an organization. The API returns 50 per page, an organization with more than that needs page 2 and beyond, so check the returned total before assuming a project does not exist.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Defaults to 50 |
| organizationId | string | – | Defaults to the credential organization |
| page | number | – | 1-based; defaults to 1 |
No output schema declared.
No examples provided.
list_uploaded_files ~108
The files attached to an item, including everything that came in through a request_file_upload link, each with a download URL that is signed and short lived (mint a fresh one by calling again). Also lists the upload links on the item and how many files each has taken, which is how to tell whether the person you asked has delivered.
| Name | Type | Req | Description |
|---|---|---|---|
| itemId | string | yes | Item (row) id |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
login ~104
Connect this machine to an existing TaskLite account with email + password, or switch to a different account. Creates a personal API key named "claude-code" on that account and stores it, so the password is used once and never saved. Replaces the current connection if there is one. Prefer connect when the user already has a tl_ key.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | Email address | |
| password | string | yes | Used once to mint an API key; never stored |
No output schema declared.
No examples provided.
publish_app ~58
Publish an app, required before its API endpoints accept external calls.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
push_status ~96
Whether an app can send push notifications to phones, and how many devices are registered. Push goes out through the customer's OWN Firebase project, so it has to be configured once per app before send_push automations do anything. This tool never returns the key.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
query_items ~397
List items (rows) of a board, including their cell values. Returns all items unless limit/page are given (the API defaults to 50 per page when unpaged, so the tool pages through and concatenates). Narrow the result with search, status, priority and sort instead of fetching everything. This is the admin view; the REST endpoints of a published app take a fuller grammar, filter[column][gte], relation filters, per-field search, see get_app_spec.
| Name | Type | Req | Description |
|---|---|---|---|
| archived | string | – | Which rows to include. Default active |
| boardId | string | yes | Board id (from list_boards / create_board) |
| excludeStatus | string | – | Only rows whose status is NOT one of these, comma separated, resolved like status. The way to ask for everything that is not done: excludeStatus "done" (task board) or "Completed" (a data board with… |
| limit | integer | – | Page size; omit to fetch all items |
| page | integer | – | 1-based page, only with limit |
| priority | string | – | Only rows with one of these priorities, comma separated (task boards only) |
| projectId | string | yes | Project id (from list_projects / create_project) |
| search | string | – | Free text; matches the row title and its text cells |
| sort | string | – | Sort by title, createdAt, updatedAt or status; prefix with "-" for descending, e.g. "-createdAt" for newest first. Anything else keeps the board order |
| status | string | – | Only rows whose status is one of these, comma separated. Matched against the board's status column by option value or label, case-insensitive: "todo,in_progress" on a task board, "Received,In Repair"… |
No output schema declared.
No examples provided.
reorder_columns ~88
Set the display order of a board's columns. Pass every column id in the wanted order (get_board_schema lists them).
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| columnIds | array | yes | Column ids in the new order (every column of the board) |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
request_file_upload ~339
Create a link that puts files onto an item from outside TaskLite: the customer's photos, a signed contract, a logo, a build zip. Returns an address like https://app.tasklite.net/upload/<token> that anyone you hand it to can use with no account, no login and no API key; pass clientEmail and TaskLite emails the link for you. What arrives lands as attachments on that item, and list_uploaded_files reads them back with a download URL. This is the answer when the person has the file and the model does not: a hosted client cannot read a folder on someone's machine. The link is public for as long as it lasts, so keep expiryDays short and maxFiles tight, and revoke_upload_link when the material is in.
| Name | Type | Req | Description |
|---|---|---|---|
| clientEmail | string | – | Send the link to this address. Omit to get the link back and pass it on yourself |
| clientName | string | – | Who is being asked, shown on the upload page |
| clientPhone | string | – | Recorded with the request |
| expiryDays | integer | – | How long the link lives. Default 7 days |
| itemId | string | yes | Item (row) the files belong to, from query_items / create_item. Make the row first if the material has no home yet |
| maxFiles | integer | – | How many files the link accepts before it stops. Default 10 |
| message | string | – | What to upload, in the words the recipient will read: "the four room photos and the price list" |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
No output schema declared.
No examples provided.
revoke_upload_link ~90
Close an upload link before it expires, so the address stops accepting files. The files already uploaded stay on the item. Use it as soon as the material is in, because until then anyone holding the link can add more.
| Name | Type | Req | Description |
|---|---|---|---|
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| tokenId | string | yes | Link id (the tokenId from request_file_upload) |
No output schema declared.
No examples provided.
rollback_deployment ~82
Point the live URL back at a previous deployment version (see list_deployments for available versions).
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| version | integer | yes | Deployment version number (from list_deployments) |
No output schema declared.
No examples provided.
search ~104
Full-text search across the projects, boards and items of the organization. Returns { results: [{ id, title, url }] }, the shape ChatGPT connectors and deep research expect; pass a result id to fetch for the full record. When you already know the board, query_items is cheaper and complete.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max results, default 20 |
| projectId | string | – | Limit the search to one project |
| query | string | yes | Search text |
No output schema declared.
No examples provided.
send_test_push ~125
Send one real push notification to the given app users, to prove the chain works before an automation depends on it. Confirm with the user first: this reaches actual phones.
| Name | Type | Req | Description |
|---|---|---|---|
| appId | string | yes | App id or slug (from list_apps / create_app) |
| body | string | – | Notification body |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| title | string | – | Notification title; defaults to "TaskLite" |
| userIds | array | yes | App user ids to notify (the same ids row-level security uses) |
No output schema declared.
No examples provided.
set_cell ~99
Set a single cell value on an item by columnId.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| columnId | string | yes | Column id (from get_board_schema) |
| itemId | string | yes | Item (row) id |
| projectId | string | yes | Project id (from list_projects / create_project) |
| value | – | yes | The new cell value; shape depends on the column type |
No output schema declared.
No examples provided.
sign_up ~103
Create a brand-new TaskLite account + organization and connect this machine, no website visit needed. A strong random password is generated locally and never shown or stored; for web access the user later uses "forgot password" with this email. Ask the user for email, their name, and a business name before calling.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | Email address | |
| name | string | yes | The user's full name |
| organizationName | string | yes | Business/organization name |
No output schema declared.
No examples provided.
update_app_endpoint ~179
Change an existing endpoint, most often to set exposedColumns on one that was created without them. Get the endpoint id from list_app_endpoints and the column ids from get_board_schema.
| Name | Type | Req | Description |
|---|---|---|---|
| allowedMethods | array | – | HTTP methods the endpoint accepts: GET, POST, PATCH, DELETE |
| appId | string | yes | App id or slug (from list_apps / create_app) |
| endpointId | string | yes | Endpoint id (from list_app_endpoints) |
| exposedColumns | array | – | Replacement list of exposed columns (same shape as create_app_endpoint) |
| isActive | boolean | – | Whether it is active |
| name | string | – | Human-readable name |
| organizationId | string | – | Organization id; defaults to the credential organization when omitted |
| slug | string | – | URL slug: lowercase letters, digits and dashes |
No output schema declared.
No examples provided.
update_board ~87
Rename a board or change its description. Structure (columns) is changed with update_column / delete_column / reorder_columns.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| description | string | – | Free-text description |
| name | string | – | Human-readable name |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
update_column ~249
Change a column after the fact: rename it, change its type (e.g. number -> currency), replace settings (dropdown options), or set isRequired / isHidden. A type change converts existing values (number↔currency, text→number/date/checkbox, anything→text) and clears the ones that cannot convert; the response carries conversion: { converted, cleared }. settings.validation rules apply here too.
| Name | Type | Req | Description |
|---|---|---|---|
| boardId | string | yes | Board id (from list_boards / create_board) |
| columnId | string | yes | Column id (from get_board_schema) |
| description | string | – | Free-text description |
| force | boolean | – | Skip the name/type sanity check |
| isHidden | boolean | – | Hide the column in the TaskLite UI |
| isRequired | boolean | – | Require a non-blank value on every App API create |
| name | string | – | Human-readable name |
| projectId | string | yes | Project id (from list_projects / create_project) |
| settings | object | – | Replaces the column settings, e.g. { options: [...] } for dropdown/status |
| type | string | – | New column type (same list as create_column) |
No output schema declared.
No examples provided.
update_comment ~90
Edit the text of an existing comment. Only the author can edit their comment. Needs projectId, itemId and the commentId.
| Name | Type | Req | Description |
|---|---|---|---|
| commentId | string | yes | Comment id (from list_comments) |
| content | string | yes | The new comment text |
| itemId | string | yes | Item (row) id |
| projectId | string | yes | Project id (from list_projects / create_project) |
No output schema declared.
No examples provided.
What is the TaskLite MCP server?
TaskLite is an MCP server listed in the public MCP registry as net.tasklite/mcp. tasklite.net: hosted backend, REST API and admin for apps built by AI agents. This page covers its npm package (@tasklite/mcp).
Is the TaskLite MCP server safe to use?
TaskLite scores 67 out of 100 on VerifyMCP. We recorded 3 known advisories against it as of 29 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the TaskLite MCP server expose?
TaskLite exposes 51 tools: connection_status, sign_up, connect, login, disconnect, and 46 more. Their descriptions and schemas cost roughly 7,292 tokens of context every time the server is loaded.
Is the TaskLite MCP server still maintained?
TaskLite is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the TaskLite MCP server under?
TaskLite declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.