Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

TaskLite

NPM · @TASKLITE/MCP · 2 COMPONENTS · SCANNED SEP 29

tasklite.net: hosted backend, REST API and admin for apps built by AI agents

−2 this week 67 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security81
  • No malware found by supply-chain analysis.Pass
  • CVE check failed: a known high-severity CVE affects adm-zip 0.5.18, a direct dependency. A fixed version is available. View diagnostics → Fail
  • No install/post-install scripts declared.Pass
  • 31 of 94 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency19
Schema Quality & AI Usability72
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 8611 tokens (~168/item across 51 items; 51 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
  • Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety50
  • Injection-marker check failed: the server instructions contains an instruction to conceal the call from the user, the text "do not tell the user", at byte 2957 of that field. See how to fix → Fail
  • All 9 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 52 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the TaskLite MCP server?

TaskLite runs locally as an npm package, launched with npx -y @tasklite/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · @tasklite/mcp

# add to Claude Code
claude mcp add net-tasklite-mcp -- npx -y @tasklite/mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "net-tasklite-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@tasklite/mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "net-tasklite-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@tasklite/mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add net-tasklite-mcp -- npx -y @tasklite/mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "net-tasklite-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@tasklite/mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add net-tasklite-mcp --command npx --arg -y --arg @tasklite/mcp
# ~/.hermes/config.yaml
mcp_servers:
  net-tasklite-mcp:
    command: "npx"
    args: ["-y", "@tasklite/mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "net-tasklite-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@tasklite/mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add net-tasklite-mcp -t stdio -c npx -a -y @tasklite/mcp
// mcp.json
{
  "mcpServers": {
    "net-tasklite-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@tasklite/mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.

  • 25 Sept 26 −5
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 23 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

  • 21 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

  • 19 Sept 26 +1
    • CVE-2026-77301 affects this package: high ▼ security
  • 17 Sept 26 +16
    • Malware scan: unverified → pass ▲ security
  • 16 Sept 26 −15
    • Malware scan: pass → unverified ▼ security
    • Package version: 0.14.3 → 0.14.4 functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Analysed npm/@tasklite/mcp@0.14.4

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm

Background: How many MCP packages publish verified provenance →

Vulnerabilities 3 findings
ID CVE Severity Vector Fix available
GHSA-7q85-xj36-vmfc CVE-2026-77301 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H yes
GHSA-vwc7-r8mq-g2x9 CVE-2026-76845 medium CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N no
GHSA-xcpc-8h2w-3j85 CVE-2026-39244 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H yes

Background: What a vulnerability scan can and cannot prove →

Dependencies 94 packages
Packages resolved 94
Stale 31
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 51 exposed · ~7,292 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
add_comment ~125

Post a comment on an item's thread. To notify people, pass their user ids in mentionedUserIds (each also appears as an @mention). attachmentIds references already-uploaded files. Needs projectId and itemId.

NameTypeReqDescription
attachmentIdsarray–Ids of already-uploaded attachments to link
contentstringyesThe comment text
itemIdstringyesItem (row) id
mentionedUserIdsarray–User ids to @mention and notify
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

build_backend ~344

Build a whole backend in one call from a spec you compose: the project, its boards, their typed columns (including relations between the boards), optional sample rows, and optionally a published REST API with one endpoint per board and a server-side key. Use it whenever the user describes a system ("a backend for my repair shop: customers, orders, payments") instead of calling create_project, create_board, create_column, create_app, publish_app, create_app_endpoint and create_app_api_key one by one. You do the design, pick column types by meaning (phone, date, currency, dropdown/status with options for closed choices), link boards with a relation column (type "relation", relatedBoard: "<board name in this spec>", relationType: many_to_one for an order→customer link), and this tool executes it and returns one compact summary. API field names are derived from column names and never collide with reserved item fields, so there is nothing to retry. Boards are created as plain data tables (kind "data": only the columns you define, no task fields); set kind "tasks" on a board where people track work to do and want status, priority, assignee and due date built in. Every row still has a title.

NameTypeReqDescription
apiobject–Include to publish a REST API over every board and mint a key; omit for a boards-only build
boardsarrayyesThe boards (tables) of the backend, in any order
organizationIdstring–Organization id; needed only when the account belongs to several (the error then lists them)
projectobjectyesThe project that holds the boards

No output schema declared.

No examples provided.

configure_external_access ~279

Read or change how EXTERNAL users (people who sign up to your app through TaskLite auth) get into an organization. They have two ways in, and both obey the policy below: email and password (POST /auth/register-external with this organizationId, then POST /auth/login), or Google (POST /auth/google-external with a Google ID token and this organizationId). Either way the answer carries a token the app sends as Authorization: Bearer on every App API call. registrationPolicy: "open", in at once; "approval", an organization admin approves each signup (TaskLite mails the admins on every signup, and the person once approved; unapproved users are never billed); "closed", invite only, self-signup refused. appLoginUrl: the page of YOUR app where these users log in, it becomes the "Log in" button in the approval email, so set it whenever you deploy an app that uses this flow; pass "" to clear. Call with no changes to just read the current settings. Requires organization admin.

NameTypeReqDescription
appLoginUrlstring–https URL of your app's login page for external users; "" clears it
organizationIdstring–Defaults to the credential organization
registrationPolicystring–How external sign-ups are admitted: open, approval or closed

No output schema declared.

No examples provided.

connect ~90

Connect this machine to an existing TaskLite account, or switch to a different one. Takes a personal API key (tl_...) created at TaskLite → Integrations → "Connect Claude Code". Replaces the current connection if there is one, use this to switch user or organization. The switch takes effect immediately; no restart.

NameTypeReqDescription
apiKeystringyesPersonal TaskLite API key, starts with tl_

No output schema declared.

No examples provided.

connection_status ~32

Check whether this machine is connected to a TaskLite account. Call this first if any tool fails with an auth error.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

create_app ~81

Create an app, a named API surface over the boards of a project, for an external frontend. Then add endpoints and an API key.

NameTypeReqDescription
namestringyesHuman-readable name
organizationIdstring–Organization id; defaults to the credential organization when omitted
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

create_app_api_key ~161

Create an API key for an app. SECURITY: the key must live server-side only (env var, Next.js API routes), never in browser code. If the app has its own users, the server also sends `X-App-User: <user id>` with the key so per-user endpoints know who is acting.

NameTypeReqDescription
appIdstringyesApp id or slug (from list_apps / create_app)
namestring–Human-readable name
organizationIdstring–Organization id; defaults to the credential organization when omitted
scopesarray–Permissions recorded on the key: ["read"] or ["read","write"]. Omit to match the app: write when any endpoint accepts POST, PATCH or DELETE.

No output schema declared.

No examples provided.

create_app_endpoint ~260

Expose a board as a REST endpoint of an app: /apps/{appSlug}/api/{slug}. exposedColumns limits which columns are readable/writable. rowLevelSecurity.enabled makes the endpoint per-user: the developer's server sends `X-App-User: <their user id>` next to the API key, and the endpoint returns, updates and deletes ONLY that user's rows (401 without the header). Use it whenever the app has its own users.

NameTypeReqDescription
allowedMethodsarray–HTTP methods the endpoint accepts: GET, POST, PATCH, DELETE
appIdstringyesApp id or slug (from list_apps / create_app)
boardIdstringyesBoard id (from list_boards / create_board)
exposedColumnsarray–Columns the endpoint reads and writes, with the JSON key each one gets; without it the endpoint returns bare metadata
namestringyesHuman-readable name
organizationIdstring–Organization id; defaults to the credential organization when omitted
rowLevelSecurityobject–Row-level security: when enabled, each app user sees and edits only their own rows
slugstringyesURL slug: lowercase letters, digits and dashes

No output schema declared.

No examples provided.

create_automation ~406

Create an automation on a board: when something happens, do something. The most useful action here is http_request, which calls an external API and writes the answer back into columns, pair it with the "scheduled" trigger and the board keeps itself up to date (prices, exchange rates, shipment status, weather). Triggers: item_created, status_changed, column_value_changed, date_approaching, scheduled. Actions: http_request, send_notification, send_email, change_status, set_column_value, create_cross_board_item, send_webhook. Two more things every action list can use: a { type: "delay", config: { minutes | hours | days } } action pauses the run and resumes the actions after it later (reminders, follow-ups); and any network action (http_request, send_webhook, send_email, send_whatsapp) may carry config.retry: { attempts (1-5), delaySeconds (1-60) }. send_webhook accepts config.secret for an HMAC signature.

NameTypeReqDescription
actionsarrayyese.g. [{ type: "http_request", config: { url: "https://api.frankfurter.app/latest?from=USD&to=ILS", method: "GET", responseMapping: [{ path: "rates.ILS", columnId: "<column id from get_board_schema>"…
boardIdstringyesBoard id (from list_boards / create_board)
isActiveboolean–Whether it is active
namestringyesHuman-readable name
projectIdstringyesProject id (from list_projects / create_project)
triggerstringyesEvent that starts the automation: item_created, status_changed, column_value_changed, date_approaching, or scheduled (cron)
triggerConfigobject–e.g. { cron: "0 8 * * *" } for scheduled, { columnName } for column_value_changed

No output schema declared.

No examples provided.

create_board ~183

Create a board (a data table) inside a project. Add typed columns with create_column afterwards. kind: "tasks" (default) also gives the board the built-in task columns, status, priority, assignee, due date, tags, for work people track; "data" creates a plain table with only the columns you add, for records such as customers, products or orders (requires a TaskLite server from 2026-09-06; older servers ignore kind).

NameTypeReqDescription
descriptionstring–Free-text description
kindstring–"tasks": with the built-in task columns (status, priority, assignee, due date, tags). "data": only the columns you add. Default tasks.
namestringyesHuman-readable name
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

create_column ~365

Add a typed column to a board. Valid types: text, rich_text, number, status, date, datetime, duration, people, checkbox, dropdown, label, priority, link, email, phone, relation, lookup, rollup, formula, rating, currency, file. Choose by meaning, date for dates, phone for phones, number/currency for amounts, dropdown/status (with settings.options as an array of labels) for closed choices; text is for free text only. An obvious name/type mismatch is rejected with the suggested type; pass force:true to override. Rules go in settings.validation: { unique, min, max, minLength, maxLength, pattern, patternMessage }, enforced on every write (UI, MCP, App API). Closed choices (dropdown/status) reject values outside settings.options unless settings.allowCustom is true.

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
forceboolean–Create the column even when the name suggests a different type
isRequiredboolean–Require a non-blank value on every App API create
namestringyesHuman-readable name
projectIdstringyesProject id (from list_projects / create_project)
settingsobject–Type-specific settings. For dropdown/status/priority: options, either as labels ["A","B"] or as full objects [{value,label,color}], labels are expanded server-side, and colors are assigned if you do…
typestringyesColumn type: text, rich_text, number, status, date, datetime, duration, people, checkbox, dropdown, label, priority, link, email, phone, relation, lookup, rollup, rating, currency, file

No output schema declared.

No examples provided.

create_item ~220

Create an item (row) with all of its data in one call. cells maps columnId -> value (use get_board_schema for column ids); every cell is saved with the row. Use set_cell only for later edits.

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
cellsobject–Cell values keyed by column id: { "<columnId>": value }. Scalars, { amount, currency } for currency, { relatedItemIds: [...] } for relations
descriptionstring–Free-text description
dueDatestring–ISO date
prioritystring–Priority: low, medium, high or urgent
projectIdstringyesProject id (from list_projects / create_project)
statusstring–Status value (todo, in_progress, done, or a value from the board's status options)
tagsarray–Tags as an array of strings
titlestringyesItem title, shown as the row name

No output schema declared.

No examples provided.

create_project ~62

Create a project (a business process container). Boards with data live inside projects.

NameTypeReqDescription
descriptionstring–Free-text description
namestringyesHuman-readable name
organizationIdstring–Organization id; defaults to the credential organization when omitted

No output schema declared.

No examples provided.

delete_board ~78

Delete a board with every item on it. Destructive and not undoable, confirm with the user first, and prefer delete_column when only part of the model is wrong.

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

delete_column ~95

Delete a column and every value stored in it. Destructive, confirm with the user first. Use update_column when the column is right but its name, type or options are wrong.

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
columnIdstringyesColumn id (from get_board_schema)
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

delete_comment ~88

Delete a comment from an item thread. Destructive, confirm with the user before calling. Needs projectId, itemId and the commentId.

NameTypeReqDescription
commentIdstringyesComment id (from list_comments / add_comment)
itemIdstringyesItem id (from query_items / create_item)
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

delete_item ~74

Delete an item. Destructive, confirm with the user before calling.

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
itemIdstringyesItem id (from query_items / create_item)
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

delete_project ~95

Delete a project with every board, column and row inside it. Destructive: confirm with the user first, and name the project in the confirmation. The project goes to the organization recycle bin, so it can be restored from the admin until it is emptied.

NameTypeReqDescription
organizationIdstring–Organization id; defaults to the credential organization when omitted
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

deploy_frontend ~379

Deploy a static frontend to TaskLite hosting and get a live URL https://{slug}.tasklite.dev (HTTPS, auto-published on first deploy, versions kept for rollback_deployment). Hand over the frontend in ONE of three ways: `files`, the files inline (path + content), the way to go from ChatGPT or any hosted client: write index.html and its assets, then deploy in the same turn; `zipUrl`, a public https URL of a zip (a Lovable/Bolt export, a GitHub release asset); `dir`, a build output folder on this machine (only when the MCP runs locally next to the files). A real build that already exists on the person's machine fits none of these from a hosted server: tell them to drop the zip on the app's Versions screen (the adminUrl of the app, then Versions), which deploys the same way and keeps the same version history. In the frontend, call the app API via relative /api/{endpoint}, the hosting proxy injects the app identity, so no key ships to the browser.

NameTypeReqDescription
appIdstringyesApp UUID or slug (app-xxxxxx), see list_apps
dirstring–Local path to the BUILD OUTPUT directory (the one containing index.html), not the project root. Only where the MCP runs on the same machine as the files
filesarray–The site files inline. Must include index.html. Up to 500 files / 8MB decoded, right for a frontend written in the conversation
organizationIdstring–Organization id; defaults to the credential organization when omitted
zipUrlstring–Public https URL of a zip of the BUILD OUTPUT (index.html at the root, or inside a single top-level folder). Up to 50MB

No output schema declared.

No examples provided.

disconnect ~49

Disconnect this machine from TaskLite by forgetting the stored credential. Use before connecting a different account, or to revoke local access. Does not delete anything in TaskLite itself and does not revoke the key server-side.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

export_project ~113

The whole project as JSON, boards, columns with settings, items with their cells keyed by column id. For migrations, backups and reading a system back. Items are capped per board for the model's sake; the REST endpoint GET /organizations/{orgId}/projects/{projectId}/export.json returns everything.

NameTypeReqDescription
maxItemsPerBoardinteger–Default 200
organizationIdstring–Defaults to the credential organization
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

fetch ~134

One project, board or item in full, by the id search returned (project:<id>, board:<projectId>:<boardId>, item:<projectId>:<boardId>:<itemId>) or by an app URL path. Returns { id, title, text, url, metadata }, the ChatGPT fetch contract; text is the record as JSON.

NameTypeReqDescription
idstringyesAn id from search, or an app URL path such as /projects/…/boards/…/items/…
organizationIdstring–Only needed for project ids when the credential has no default organization; otherwise resolved automatically

No output schema declared.

No examples provided.

get_app_spec ~216

Get the machine-readable spec of an app: base URL, endpoints, methods, fields, auth. Two formats: "tasklite" (default), the compact shape the frontend prompts are built from, and "openapi", a standard OpenAPI 3.1 document for developers and other tools. When the user asks for the OpenAPI spec, or wants to hand the API to a developer, pass format "openapi". appId accepts either the app UUID or its slug (app-xxxxxx); list_apps shows both. The returned baseUrl is absolute, use it verbatim, do not rebuild it from the admin URL.

NameTypeReqDescription
appIdstringyesApp id or slug (from list_apps / create_app)
formatstring–"tasklite" (default): compact endpoint list. "openapi": OpenAPI 3.1 document, every endpoint with typed fields, filter grammar, auth and errors
organizationIdstring–Organization id; defaults to the credential organization when omitted

No output schema declared.

No examples provided.

get_board_schema ~69

Get a board with its full column schema (ids, names, types, settings). Call this before creating items with cells.

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

get_frontend_prompt ~110

Get a ready-made prompt describing the app backend, for pasting into a frontend generator (v0/bolt/lovable/cursor). appId accepts the app UUID or its slug (app-xxxxxx), use list_apps to find it.

NameTypeReqDescription
appIdstringyesApp id or slug (from list_apps / create_app)
organizationIdstring–Organization id; defaults to the credential organization when omitted
toolstringyesTarget tool the prompt is written for

No output schema declared.

No examples provided.

list_app_endpoints ~88

List an app's REST endpoints, slug, board, allowed methods, and how many columns each exposes. An endpoint exposing 0 columns is broken: it returns only item metadata and silently discards writes.

NameTypeReqDescription
appIdstringyesApp id or slug (from list_apps / create_app)
organizationIdstring–Organization id; defaults to the credential organization when omitted

No output schema declared.

No examples provided.

list_apps ~80

List the apps in the organization, id, slug, status. Call this first when you need an app id: the slug (app-xxxxxx) is what shows up in URLs and in generated code, and this is how you map it back to the app.

NameTypeReqDescription
organizationIdstring–Organization id; defaults to the credential organization when omitted

No output schema declared.

No examples provided.

list_automations ~64

List the automations on a board, so you can see what already runs before adding another.

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

list_boards ~89

List the boards inside a project, id, name, description. Every other board tool needs a boardId, and this is the only way to discover one without being handed a URL.

NameTypeReqDescription
limitnumber–Defaults to 50
pagenumber–1-based; defaults to 1
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

list_comments ~105

List the comments (the correspondence thread) on an item, oldest first. Each comment includes its author and any @mentions. Needs projectId and itemId (get itemId from query_items).

NameTypeReqDescription
itemIdstringyesItem (row) id
limitinteger–Page size, default 20
pageinteger–1-based page, default 1
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

list_deployments ~69

List the hosted-frontend deployments of an app, versions, which one is live, and the public URL.

NameTypeReqDescription
appIdstringyesApp id or slug (from list_apps / create_app)
organizationIdstring–Organization id; defaults to the credential organization when omitted

No output schema declared.

No examples provided.

list_organizations ~29

List the organizations the authenticated user belongs to. Use the returned id as organizationId in other tools.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_projects ~87

List projects in an organization. The API returns 50 per page, an organization with more than that needs page 2 and beyond, so check the returned total before assuming a project does not exist.

NameTypeReqDescription
limitnumber–Defaults to 50
organizationIdstring–Defaults to the credential organization
pagenumber–1-based; defaults to 1

No output schema declared.

No examples provided.

list_uploaded_files ~108

The files attached to an item, including everything that came in through a request_file_upload link, each with a download URL that is signed and short lived (mint a fresh one by calling again). Also lists the upload links on the item and how many files each has taken, which is how to tell whether the person you asked has delivered.

NameTypeReqDescription
itemIdstringyesItem (row) id
organizationIdstring–Organization id; defaults to the credential organization when omitted

No output schema declared.

No examples provided.

login ~104

Connect this machine to an existing TaskLite account with email + password, or switch to a different account. Creates a personal API key named "claude-code" on that account and stores it, so the password is used once and never saved. Replaces the current connection if there is one. Prefer connect when the user already has a tl_ key.

NameTypeReqDescription
emailstringyesEmail address
passwordstringyesUsed once to mint an API key; never stored

No output schema declared.

No examples provided.

publish_app ~58

Publish an app, required before its API endpoints accept external calls.

NameTypeReqDescription
appIdstringyesApp id or slug (from list_apps / create_app)
organizationIdstring–Organization id; defaults to the credential organization when omitted

No output schema declared.

No examples provided.

push_status ~96

Whether an app can send push notifications to phones, and how many devices are registered. Push goes out through the customer's OWN Firebase project, so it has to be configured once per app before send_push automations do anything. This tool never returns the key.

NameTypeReqDescription
appIdstringyesApp id or slug (from list_apps / create_app)
organizationIdstring–Organization id; defaults to the credential organization when omitted

No output schema declared.

No examples provided.

query_items ~397

List items (rows) of a board, including their cell values. Returns all items unless limit/page are given (the API defaults to 50 per page when unpaged, so the tool pages through and concatenates). Narrow the result with search, status, priority and sort instead of fetching everything. This is the admin view; the REST endpoints of a published app take a fuller grammar, filter[column][gte], relation filters, per-field search, see get_app_spec.

NameTypeReqDescription
archivedstring–Which rows to include. Default active
boardIdstringyesBoard id (from list_boards / create_board)
excludeStatusstring–Only rows whose status is NOT one of these, comma separated, resolved like status. The way to ask for everything that is not done: excludeStatus "done" (task board) or "Completed" (a data board with…
limitinteger–Page size; omit to fetch all items
pageinteger–1-based page, only with limit
prioritystring–Only rows with one of these priorities, comma separated (task boards only)
projectIdstringyesProject id (from list_projects / create_project)
searchstring–Free text; matches the row title and its text cells
sortstring–Sort by title, createdAt, updatedAt or status; prefix with "-" for descending, e.g. "-createdAt" for newest first. Anything else keeps the board order
statusstring–Only rows whose status is one of these, comma separated. Matched against the board's status column by option value or label, case-insensitive: "todo,in_progress" on a task board, "Received,In Repair"…

No output schema declared.

No examples provided.

reorder_columns ~88

Set the display order of a board's columns. Pass every column id in the wanted order (get_board_schema lists them).

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
columnIdsarrayyesColumn ids in the new order (every column of the board)
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

request_file_upload ~339

Create a link that puts files onto an item from outside TaskLite: the customer's photos, a signed contract, a logo, a build zip. Returns an address like https://app.tasklite.net/upload/<token> that anyone you hand it to can use with no account, no login and no API key; pass clientEmail and TaskLite emails the link for you. What arrives lands as attachments on that item, and list_uploaded_files reads them back with a download URL. This is the answer when the person has the file and the model does not: a hosted client cannot read a folder on someone's machine. The link is public for as long as it lasts, so keep expiryDays short and maxFiles tight, and revoke_upload_link when the material is in.

NameTypeReqDescription
clientEmailstring–Send the link to this address. Omit to get the link back and pass it on yourself
clientNamestring–Who is being asked, shown on the upload page
clientPhonestring–Recorded with the request
expiryDaysinteger–How long the link lives. Default 7 days
itemIdstringyesItem (row) the files belong to, from query_items / create_item. Make the row first if the material has no home yet
maxFilesinteger–How many files the link accepts before it stops. Default 10
messagestring–What to upload, in the words the recipient will read: "the four room photos and the price list"
organizationIdstring–Organization id; defaults to the credential organization when omitted

No output schema declared.

No examples provided.

revoke_upload_link ~90

Close an upload link before it expires, so the address stops accepting files. The files already uploaded stay on the item. Use it as soon as the material is in, because until then anyone holding the link can add more.

NameTypeReqDescription
organizationIdstring–Organization id; defaults to the credential organization when omitted
tokenIdstringyesLink id (the tokenId from request_file_upload)

No output schema declared.

No examples provided.

rollback_deployment ~82

Point the live URL back at a previous deployment version (see list_deployments for available versions).

NameTypeReqDescription
appIdstringyesApp id or slug (from list_apps / create_app)
organizationIdstring–Organization id; defaults to the credential organization when omitted
versionintegeryesDeployment version number (from list_deployments)

No output schema declared.

No examples provided.

search ~104

Full-text search across the projects, boards and items of the organization. Returns { results: [{ id, title, url }] }, the shape ChatGPT connectors and deep research expect; pass a result id to fetch for the full record. When you already know the board, query_items is cheaper and complete.

NameTypeReqDescription
limitinteger–Max results, default 20
projectIdstring–Limit the search to one project
querystringyesSearch text

No output schema declared.

No examples provided.

send_test_push ~125

Send one real push notification to the given app users, to prove the chain works before an automation depends on it. Confirm with the user first: this reaches actual phones.

NameTypeReqDescription
appIdstringyesApp id or slug (from list_apps / create_app)
bodystring–Notification body
organizationIdstring–Organization id; defaults to the credential organization when omitted
titlestring–Notification title; defaults to "TaskLite"
userIdsarrayyesApp user ids to notify (the same ids row-level security uses)

No output schema declared.

No examples provided.

set_cell ~99

Set a single cell value on an item by columnId.

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
columnIdstringyesColumn id (from get_board_schema)
itemIdstringyesItem (row) id
projectIdstringyesProject id (from list_projects / create_project)
value–yesThe new cell value; shape depends on the column type

No output schema declared.

No examples provided.

sign_up ~103

Create a brand-new TaskLite account + organization and connect this machine, no website visit needed. A strong random password is generated locally and never shown or stored; for web access the user later uses "forgot password" with this email. Ask the user for email, their name, and a business name before calling.

NameTypeReqDescription
emailstringyesEmail address
namestringyesThe user's full name
organizationNamestringyesBusiness/organization name

No output schema declared.

No examples provided.

update_app_endpoint ~179

Change an existing endpoint, most often to set exposedColumns on one that was created without them. Get the endpoint id from list_app_endpoints and the column ids from get_board_schema.

NameTypeReqDescription
allowedMethodsarray–HTTP methods the endpoint accepts: GET, POST, PATCH, DELETE
appIdstringyesApp id or slug (from list_apps / create_app)
endpointIdstringyesEndpoint id (from list_app_endpoints)
exposedColumnsarray–Replacement list of exposed columns (same shape as create_app_endpoint)
isActiveboolean–Whether it is active
namestring–Human-readable name
organizationIdstring–Organization id; defaults to the credential organization when omitted
slugstring–URL slug: lowercase letters, digits and dashes

No output schema declared.

No examples provided.

update_board ~87

Rename a board or change its description. Structure (columns) is changed with update_column / delete_column / reorder_columns.

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
descriptionstring–Free-text description
namestring–Human-readable name
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

update_column ~249

Change a column after the fact: rename it, change its type (e.g. number -> currency), replace settings (dropdown options), or set isRequired / isHidden. A type change converts existing values (number↔currency, text→number/date/checkbox, anything→text) and clears the ones that cannot convert; the response carries conversion: { converted, cleared }. settings.validation rules apply here too.

NameTypeReqDescription
boardIdstringyesBoard id (from list_boards / create_board)
columnIdstringyesColumn id (from get_board_schema)
descriptionstring–Free-text description
forceboolean–Skip the name/type sanity check
isHiddenboolean–Hide the column in the TaskLite UI
isRequiredboolean–Require a non-blank value on every App API create
namestring–Human-readable name
projectIdstringyesProject id (from list_projects / create_project)
settingsobject–Replaces the column settings, e.g. { options: [...] } for dropdown/status
typestring–New column type (same list as create_column)

No output schema declared.

No examples provided.

update_comment ~90

Edit the text of an existing comment. Only the author can edit their comment. Needs projectId, itemId and the commentId.

NameTypeReqDescription
commentIdstringyesComment id (from list_comments)
contentstringyesThe new comment text
itemIdstringyesItem (row) id
projectIdstringyesProject id (from list_projects / create_project)

No output schema declared.

No examples provided.

Common questions

What is the TaskLite MCP server?

TaskLite is an MCP server listed in the public MCP registry as net.tasklite/mcp. tasklite.net: hosted backend, REST API and admin for apps built by AI agents. This page covers its npm package (@tasklite/mcp).

Is the TaskLite MCP server safe to use?

TaskLite scores 67 out of 100 on VerifyMCP. We recorded 3 known advisories against it as of 29 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the TaskLite MCP server expose?

TaskLite exposes 51 tools: connection_status, sign_up, connect, login, disconnect, and 46 more. Their descriptions and schemas cost roughly 7,292 tokens of context every time the server is loaded.

Is the TaskLite MCP server still maintained?

TaskLite is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the TaskLite MCP server under?

TaskLite declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.