Toggl 2.0
NPM · @TOGGLHQ/MCP · SCANNED SEP 26
Toggl 2.0 MCP server for tasks, projects, time entries, and workspace operations.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security95
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known medium-severity CVE affects @opentelemetry/core 2.6.1, reached via @sentry/node > @opentelemetry/instrumentation-http > @opentelemetry/core. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- 6 of 75 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency6
- Repository check failed: no source repository is declared. See how to fix → View diagnostics → Fail
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- License check failed: the license (UNLICENSED) isn't a recognized OSI-approved license. See how to fix → Fail
- Actively maintained (last published 0 days ago).Pass
- Security-disclosure policy not yet verified: we couldn't inspect the source repository.Unverified
Schema Quality & AI Usability43
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 21681 tokens (~481/item across 45 items; 45 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management94
- Stability check failed: the tool surface changed between 1.6.3 and 1.11.64: 1 tool removals, 0 breaking changes, 5 additions. See how to fix → Fail
Tool Coverage89
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 66% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 46 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the Toggl 2.0 MCP server?
Toggl 2.0 runs locally as an npm package, launched with npx -y @togglhq/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · @togglhq/mcp
claude mcp add toggl-toggl-mcp -- npx -y @togglhq/mcp
{
"mcpServers": {
"toggl-toggl-mcp": {
"command": "npx",
"args": [
"-y",
"@togglhq/mcp"
]
}
}
} {
"servers": {
"toggl-toggl-mcp": {
"command": "npx",
"args": [
"-y",
"@togglhq/mcp"
]
}
}
} codex mcp add toggl-toggl-mcp -- npx -y @togglhq/mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"toggl-toggl-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"@togglhq/mcp"
],
"enabled": true
}
}
} openclaw mcp add toggl-toggl-mcp --command npx --arg -y --arg @togglhq/mcp
mcp_servers:
toggl-toggl-mcp:
command: "npx"
args: ["-y", "@togglhq/mcp"] {
"McpServers": {
"toggl-toggl-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"@togglhq/mcp"
]
}
}
} assistant mcp add toggl-toggl-mcp -t stdio -c npx -a -y @togglhq/mcp
{
"mcpServers": {
"toggl-toggl-mcp": {
"command": "npx",
"args": [
"-y",
"@togglhq/mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Sept 26 +9
- Known CVEs: unverified → fail ▼ security
- Dependency health: unverified → 0.98 ▲ functional
- 25 Sept 26 +1
- Known CVEs: unverified → fail ▼ security
- Stability: fail → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Stability: fail → pass ▲ security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Dependency health: unverified → 0.98 ▲ functional
- Package version: 1.5.73 → 1.11.64 functional
- Package version: 1.11.57 → 1.11.61 functional
- Package version: 1.11.57 → 1.11.60 functional
- Package version: 1.11.57 → 1.11.59 functional
- Package version: 1.11.57 → 1.11.58 functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 −9
- Known CVEs: fail → unverified ▼ security
- Stability: fail → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Malware scan: pass → unverified ▼ security
- Dependency health: 0.98 → unverified ▼ functional
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Package version: 1.11.45 → 1.11.57 functional
- Package version: 1.11.45 → 1.11.56 functional
- Package version: 1.11.45 → 1.11.55 functional
- Package version: 1.11.45 → 1.11.54 functional
- Package version: 1.11.45 → 1.11.50 functional
- Package version: 1.11.45 → 1.11.49 functional
- 23 Sept 26 +10
- Known CVEs: unverified → fail ▼ security
- Stability: fail → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Dependency health: unverified → 0.98 ▲ functional
- Package version: 1.11.33 → 1.11.45 functional
- Package version: 1.11.33 → 1.11.42 functional
- Package version: 1.11.33 → 1.11.40 functional
- Package version: 1.5.73 → 1.11.40 functional
- Package version: 1.11.33 → 1.11.38 functional
- Package version: 1.5.73 → 1.11.38 functional
- Package version: 1.11.33 → 1.11.37 functional
- Package version: 1.11.33 → 1.11.34 functional
- 22 Sept 26 0
- Known CVEs: unverified → fail ▼ security
- Stability: fail → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Dependency health: unverified → 0.98 ▲ functional
- Package version: 1.11.18 → 1.11.33 functional
- Package version: 1.11.18 → 1.11.29 functional
- Package version: 1.11.18 → 1.11.28 functional
- Package version: 1.11.18 → 1.11.27 functional
- Package version: 1.11.18 → 1.11.25 functional
- Package version: 1.11.18 → 1.11.23 functional
- Package version: 1.11.18 → 1.11.22 functional
- Package version: 1.11.18 → 1.11.20 functional
- Package version: 1.11.18 → 1.11.19 functional
- 21 Sept 26 −12
- Malware scan: pass → unverified ▼ security
- Known CVEs: fail → unverified ▼ security
- Stability: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Stability: pass → fail ▼ security
- Schema quality: 18791 → 21839 ▼ functional
- Schema quality: 18791 → 21480 ▼ functional
- Schema quality: 18791 → 21831 ▼ functional
- Schema quality: 18791 → 21829 ▼ functional
- Schema quality: 18791 → 21478 ▼ functional
- Dependency health: 0.98 → unverified ▼ functional
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Package version: 1.8.2 → 1.11.18 functional
- Package version: 1.8.2 → 1.11.16 functional
- Package version: 1.8.2 → 1.11.14 functional
- Package version: 1.8.2 → 1.11.7 functional
- Package version: 1.8.2 → 1.11.5 functional
- Package version: 1.8.2 → 1.11.4 functional
- Package version: 1.8.2 → 1.11.3 functional
- Package version: 1.8.2 → 1.11.1 functional
- Package version: 1.5.73 → 1.11.1 functional
- 20 Sept 26 0
- Stability: 0.97 → pass security
- Package version: 1.5.73 → 1.8.2 functional
- 19 Sept 26 0
- Stability: pass → 0.97 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 26 Sept 2026 · Analysed npm/@togglhq/mcp@1.11.64
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Vulnerabilities 1 finding
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-8988-4f7v-96qf | CVE-2026-54285 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | yes |
Background: What a vulnerability scan can and cannot prove →
Dependencies 75 packages
| Packages resolved | 75 |
|---|---|
| Stale | 6 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
alerts Alerts ~270
Manage Focus alerts with the following actions: - **create**: Create Alerts. (data: payload*{config*, rule_type*, project_id, recipient_group_ids, recipient_roles, recipient_user_ids}) - **delete**: Delete Alerts. (data: alert_id*) - **get**: Get Alerts. (data: alert_id*) - **list**: List Alerts. (data: rule_type, project_id, scope) - **partial-update**: Partial Update Alerts. (data: alert_id*, payload*{config, recipient_group_ids, recipient_roles, recipient_user_ids, rule_type}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create, delete, get, list, partial-update |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
attachments Attachments ~137
Manage Focus attachments with the following actions: - **get-workspace-attachment-storage**: Get Workspace Attachment Storage Attachments. (data: none) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | – | yes | – |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | object | – | – |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
audit-log Audit-log ~232
Manage Focus audit-log with the following actions: - **get-organization**: Get Organization Audit Log. (data: action, entity_id, entity_type, export, export_, from*, page_number, page_size, to*, user_id, workspace_id) - **list**: List Audit Log. (data: action, entity_id, entity_type, export, export_, from*, page_number, page_size, to*, user_id) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: get-organization, list |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
auth Authenticate MCP ~90
Authenticate this MCP server with Toggl 2.0 via OAuth. Opens browser login and stores credentials locally. Optionally pass workspace_id to pick a specific workspace when multiple are available.
| Name | Type | Req | Description |
|---|---|---|---|
| accounts_api_url | string | – | Optional accounts API URL override (defaults from ENV or production) |
| focus_api_url | string | – | Optional focus API URL override (defaults from ENV or production) |
| workspace_id | – | – | – |
No output schema declared.
No examples provided.
capacities Capacities ~164
Manage Focus capacities with the following actions: - **get-computations**: Compute user or ghost capacity for a date range. (data: end_date*, group*, include_drafts*, include_task_estimates*, private_*, start_date*, task_source*, unit*, user_id*) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | – | yes | – |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | object | – | – |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
clients Clients ~273
Manage Focus clients with the following actions: - **create**: Create Clients. (data: name*, currency) - **delete**: Delete Clients. (data: client_id*) - **get**: Get Clients. (data: client_id*) - **list**: List Clients. Clients group billable work; projects can reference client_id. Filter projects with projects.list --client-id. (data: name, page, per_page) - **restore**: Restore Clients. (data: client_id*) - **update**: Update Clients. (data: client_id*, payload*{name, currency}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create, delete, get, list, restore, update |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
custom-fields Custom-fields ~649
Manage Focus custom-fields with the following actions: - **create**: Create Custom Fields. Requires workspace admin (403 otherwise). field_type is one of select, multi_select, text, number, date, checkbox, users; select/multi_select fields can be seeded with options inline. (data: payload*{entity_type*, field_type*, name*, description, options}) - **delete**: Delete Custom Fields. Requires workspace admin. Soft-deletes the field and removes it from entities; this also discards stored values. (data: custom_field_id*) - **get**: Get Custom Fields. (data: custom_field_id*) - **list**: List Custom Fields. Custom fields are workspace-level definitions attached to project or task entities. Reads work for all members; create/update/delete return 403 for non-admins. Reordering fields is not available through this tool yet. (data: entity_type, order_by, page, per_page) - **options-create**: Options Create Custom Fields. Requires workspace admin. Only valid for select and multi_select fields. (data: custom_field_id*, payload*{name*, color, description}) - **options-delete**: Options Delete Custom Fields. Requires workspace admin. Deleting an option clears it from entities that have it selected. (data: custom_field_id*, option_id*) - **options-list**: Options List Custom Fields. (data: custom_field_id*, name, order_by, page, per_page) - **options-update**: Options Update Custom Fields. Requires workspace admin. Full update (PUT) of the option's name/color/description. (data: custom_field_id*, option_id*, payload*{name*, color, description}) - **update**: Update Custom Fields. Requires workspace admin. Full update (PUT) of name/description only; field_type and entity_type are immutable. Manage options via the options-* actions. (data: custom_field_id*, payload*{name*, description}) - **update-options-order**: Update Options Order Custom Fields. (data: custom_field_id*, payload*{ordered_ids*}) - **update-order**: Update Order Custom Fields. (data: payload*{entity_type*, ordere…
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create, delete, get, list, options-create, options-delete, options-list, options-update, update, update-options-order, update-order, update-user-custom-field-values |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
goals Goals ~312
Manage Focus goals with the following actions: - **create**: Create Goals. (data: payload*{...}) - **delete**: Delete Goals. (data: goal_id*) - **get**: Get Goals. (data: goal_id*) - **list**: List Goals. (data: none) - **preview-goal-tracked-time**: Preview Goal Tracked Time Goals. (data: payload*{...}) - **reorder**: Reorder Goals. (data: payload*{goal_ids*}) - **update**: Update Goals. (data: goal_id*, payload*{active, client_ids, comparison, icon, name, project_ids, recurrence, start_date, tag_ids, target_seconds, task_ids, weekdays}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create, delete, get, list, preview-goal-tracked-time, reorder, update |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
logout Logout MCP ~24
Clear local MCP authentication state. Removes stored credentials so subsequent tool calls require auth again.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
milestones Milestones ~373
Manage Focus milestones with the following actions: - **create**: Create Milestones. (data: payload*{color*, due_date*, name*, completed_at, project_ids, team_ids}) - **delete**: Delete Milestones. (data: milestone_id*) - **get**: Get Milestones. (data: milestone_id*) - **get-classic**: Get Classic Milestones. (data: due_date_from, due_date_to, order_by, page, per_page, project_id, team_id) - **get-stream**: Get Stream Milestones. (data: due_date_from, due_date_to, order_by, project_id, team_id) - **partial-update**: Partial Update Milestones. (data: milestone_id*, payload*{due_date, name, project_ids, team_ids}) - **restore**: Restore Milestones. (data: milestone_id*) - **update**: Update Milestones. (data: milestone_id*, payload*{color*, due_date*, name*, completed_at, project_ids, team_ids}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create, delete, get, get-classic, get-stream, partial-update, restore, update |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
org-invitations Org-invitations ~246
Manage Focus org-invitations with the following actions: - **list**: List pending invitations for the current user account. (data: none) - **create**: Send organization invitations (uses organization ID from your workspace profile). (data: initiating_product*, invitations*, skip_email*) - **get**: Get an invitation by ID. (data: invitation_id*) - **resend**: Resend an invitation email for an organization user record. (data: organization_user_id*) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: list, create, get, resend |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
org-members Org-members ~240
Manage Focus org-members with the following actions: - **get**: Get an organization user by organization user ID. (data: organization_user_id*) - **update**: Replace organization user settings (roles, groups, tags, etc.). (data: organization_user_id*, payload*{accounts_role_id*, active*, groups*, name*, tags*, workspaces*}) - **set-active**: Activate or deactivate an organization member. (data: organization_user_id*, status*) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: get, update, set-active |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
org-time-off-me Org-time-off-me ~241
Manage Focus org-time-off-me with the following actions: - **list**: List your time off entries between two dates (YYYY-MM-DD). (data: from*, to*) - **update**: Update your time off entries (JSON array). (data: array payload) - **create**: Create your time off entries (JSON array). (data: array payload) - **delete**: Delete your time off entries by ID. (data: ids*) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: list, update, create, delete |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
org-workspaces Org-workspaces ~201
Manage Focus org-workspaces with the following actions: - **list**: List workspaces under the active organization. (data: none) - **my-roles**: Get your roles for a workspace (defaults to the CLI active workspace when omitted). (data: workspace_id) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: list, my-roles |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
organization Organization ~377
Manage Focus organization with the following actions: - **create-group**: Create an organization group. (data: payload*{emoji*, name*, organization_users*, workspaces*}) - **delete-group**: Delete an organization group. (data: group_id*) - **get-member-tags**: Get Member Tags Organization. (data: workspace_id*) - **get-my-groups**: List organization groups for the current user. (data: none) - **get-roles**: List organization roles. (data: none) - **get-teams**: List organization teams. (data: active_members_only*, filter*, group_ids*, organization_user_id*, page*, per_page*, query*, sort_dir*, workspace_id*) - **update-group**: Update an organization group. (data: group_id*, payload*{emoji*, name*, organization_users*, workspaces*}) - **update-group-user-role**: Update Group User Role Organization. (data: group_id*, payload*{organization_user_id*, workspace_id*}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create-group, delete-group, get-member-tags, get-my-groups, get-roles, get-teams, update-group, update-group-user-role |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
profile-list List MCP profiles ~47
List saved credential profiles from ~/.toggl/focus-tools.json. The row where active is true is the MCP active profile (active.mcp). Profiles may be shared with the Toggl CLI.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
profile-remove Remove saved profile ~124
Delete a profile row from ~/.toggl/focus-tools.json. If it was the MCP active profile, active.mcp moves to another remaining profile when possible. This affects both MCP and shared storage; removing a profile used by the CLI removes it for the CLI too. Destructive: call without confirm_token first to receive confirm_required + confirm_token, then repeat with the same profile_name and confirm_token (same pattern as entity mutations).
| Name | Type | Req | Description |
|---|---|---|---|
| confirm_token | string | – | Mutation confirmation token from previous call |
| profile_name | string | yes | Profile key as shown by profile-list |
No output schema declared.
No examples provided.
profile-switch Switch MCP profile ~41
Set active.mcp to an existing profile name so subsequent entity calls use that credential row.
| Name | Type | Req | Description |
|---|---|---|---|
| profile_name | string | yes | Profile key as shown by profile-list |
No output schema declared.
No examples provided.
projects Projects ~2,093
Manage Focus projects with the following actions: - **create-project**: Create a project with related data such as members, milestones, rates, and billable rates. Follow the create action's privacy and billable guidance. Project fields go under payload.project. Set rates through payload.billable_rates, not the legacy payload.rates (start_at/end_at). For payload.billable_rates: hourly_rate is in the currency's smallest unit, so it depends on the currency: two-decimal currencies like USD/EUR use cents (5000 = 50.00), zero-decimal ones like JPY/KRW use whole units (5000 = 5000), three-decimal ones like KWD/BHD use thousandths. Reads return the same unit. Omit end_date for an open-ended schedule; when set it must be on or after start_date. (data: payload*{project*, billable_rates, members, milestones, rates}) - **add-project-members**: Add Project Members Projects. (data: payload*{role_id*, group_ids, user_ids}, project_id*) - **archive**: Archive Projects. (data: project_id*) - **attachments-bulk-create**: Attachments Bulk Create Projects. Uploads several local files in one call. names and display_orders are optional parallel arrays; they default to the file basenames and array positions. (data: project_id*, file_paths*, names, display_orders) - **attachments-create**: Attachments Create Projects. Uploads a local file (file_path) as an attachment. The mime type is inferred from the extension and the API rejects disallowed types; uploads are capped at 20 MB. (data: project_id*, file_path*, name, display_order) - **attachments-delete**: Attachments Delete Projects. (data: attachment_id*, project_id*) - **attachments-list**: Attachments List Projects. Lists attachment metadata. Upload files with attachments-create (file_path), download with attachments-view (save_to). (data: order_by, project_id*) - **attachments-update**: Attachments Update Projects. Full update (PUT): both name and display_order are required; the response body is empty, verify via attachments-list. (d…
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create-project, add-project-members, archive, attachments-bulk-create, attachments-create, attachments-delete, attachments-list, attachments-update, attachments-view, bulk-archive, bulk-delet… |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
public-holidays Public-holidays ~148
Manage Focus public-holidays with the following actions: - **get-by-user-ids**: Get By User Ids Public Holidays. (data: end_date*, start_date*, user_id*) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | – | yes | – |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | object | – | – |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
rates Rates ~2,248
Manage Focus rates with the following actions: - **billable-check-project-billable-rate-conflicts**: Billable Check Project Billable Rate Conflicts Rates. (data: payload*{currency*, hourly_rate*, start_date*, end_date}, project_id*) - **billable-check-project-user-billable-rate-conflicts**: Billable Check Project User Billable Rate Conflicts Rates. (data: payload*{currency*, hourly_rate*, start_date*, end_date}, project_id*, user_id*) - **billable-check-workspace-billable-rate-conflicts**: Billable Check Workspace Billable Rate Conflicts Rates. (data: payload*{currency*, hourly_rate*, start_date*, end_date}) - **billable-check-workspace-user-billable-rate-conflicts**: Billable Check Workspace User Billable Rate Conflicts Rates. (data: payload*{currency*, hourly_rate*, start_date*, end_date}, user_id*) - **billable-delete-by-id**: Billable Delete By Id Rates. (data: rate_id*) - **billable-delete-project-billable-rate-range**: Billable Delete Project Billable Rate Range Rates. (data: from*, project_id*, to) - **billable-delete-project-user-billable-rate-range**: Billable Delete Project User Billable Rate Range Rates. (data: from*, project_id*, to, user_id*) - **billable-delete-workspace-billable-rate-range**: Billable Delete Workspace Billable Rate Range Rates. (data: from*, to) - **billable-delete-workspace-user-billable-rate-range**: Billable Delete Workspace User Billable Rate Range Rates. (data: from*, to, user_id*) - **billable-get-all-project-user**: Billable Get All Project User Rates. (data: date, order_by, project_id, user_id) - **billable-get-all-workspace-user**: Billable Get All Workspace User Rates. (data: order_by, user_id) - **billable-get-project**: Billable Get Project Rates. (data: order_by, project_id*) - **billable-get-project-user**: Billable Get Project User Rates. (data: order_by, project_id*, user_id*) - **billable-get-projects**: Billable Get Projects Rates. (data: date*, project_id*) - **billable-get-workspace**: Billable Get Workspace Rate…
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: billable-check-project-billable-rate-conflicts, billable-check-project-user-billable-rate-conflicts, billable-check-workspace-billable-rate-conflicts, billable-check-workspace-user-billable-r… |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
recurring-budget-suggestions Recurring-budget-suggestions ~382
Manage Focus recurring-budget-suggestions with the following actions: - **accept-arecurring-project-budget-suggestion**: Accept Arecurring Project Budget Suggestion Recurring Budget Suggestions. (data: project_id*) - **accept-atemplate-estimate-suggestion**: Accept Atemplate Estimate Suggestion Recurring Budget Suggestions. (data: project_id*) - **dismiss-arecurring-project-budget-suggestion**: Dismiss Arecurring Project Budget Suggestion Recurring Budget Suggestions. (data: project_id*) - **dismiss-atemplate-estimate-suggestion**: Dismiss Atemplate Estimate Suggestion Recurring Budget Suggestions. (data: project_id*) - **get-recurring-project-budget-suggestion**: Get Recurring Project Budget Suggestion Recurring Budget Suggestions. (data: project_id*, target_period_start*) - **get-template-estimate-suggestion**: Get Template Estimate Suggestion Recurring Budget Suggestions. (data: project_id*) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: accept-arecurring-project-budget-suggestion, accept-atemplate-estimate-suggestion, dismiss-arecurring-project-budget-suggestion, dismiss-atemplate-estimate-suggestion, get-recurring-project-b… |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
reports Reports ~320
Manage Focus reports with the following actions: - **get-flexq-data**: Get Flexq Data Reports. (data: payload*{...}, response_format) - **get-flexq-dictionary**: Get Flexq Dictionary Reports. (data: payload*) - **get-forecast-availability**: Get Forecast Availability Reports. (data: none) - **get-profitability**: Get Profitability Reports. (data: include_dicts, payload*{...}, response_format, xTogglReportExport) - **get-time-accounting**: Get Time Accounting Reports. (data: payload*{...}) - **get-workload**: Get Workload Reports. (data: payload*{...}, xTogglReportExport) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: get-flexq-data, get-flexq-dictionary, get-forecast-availability, get-profitability, get-time-accounting, get-workload |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
reportschedules Reportschedules ~283
Manage Focus reportschedules with the following actions: - **delete-shared-report-schedule**: Delete Shared Report Schedule Reportschedules. (data: id*) - **upsert-saved-view-schedule**: Upsert Saved View Schedule Reportschedules. (data: id*, payload*{cadence*, time*, day, recipient_team_ids, recipient_user_ids, recipient_workspace_ids}) - **upsert-shared-report-schedule**: Upsert Shared Report Schedule Reportschedules. (data: id*, payload*{cadence*, time*, day, recipient_team_ids, recipient_user_ids, recipient_workspace_ids}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: delete-shared-report-schedule, upsert-saved-view-schedule, upsert-shared-report-schedule |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
saved-views Saved-views ~443
Manage Focus saved-views with the following actions: - **create**: Create Saved Views. Required: name, type, pinned, and params (the view's filter/layout state as an object, e.g. { project_id, filters }). Project-scoped types (project, project.tasks, project.board, project.timeline) expect the project context inside params. (data: payload*{name*, params*, pinned*, type*, icon_name}) - **delete**: Delete Saved Views. Deletes the authenticated user's saved view; it cannot be restored. (data: id*) - **get**: Get Saved Views. id is the saved view ID (number) from saved-views list. (data: id*) - **list**: List Saved Views. Saved views are per-user, so results belong to the authenticated user. Filter by type (inbox, archive, board, timeline, project, project.tasks, project.board, project.timeline, projects) or by partial name match. pinned=true entries are the user's starred views. (data: name, order_by, type) - **update**: Update Saved Views. The payload requires the full updatable set (name, type, pinned, params), so fetch the view first and resend it with your changes to avoid clobbering params. Toggling pinned is how views are starred/unstarred. (data: id*, payload*{name*, params*, pinned*, type*, icon_name}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create, delete, get, list, update |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
search Search ~219
Manage Focus search with the following actions: - **mentions**: Mentions Search. (data: keyword, per_group) - **search**: Search across Toggl 2.0 entities. (data: keyword*, per_group, assignee_user_id, project_id, task_id, include_drafts, exclude_calendar_events, assignee_team_id, group_by_tags, only_me) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: mentions, search |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
shared-holidays Shared-holidays ~145
Manage Focus shared-holidays with the following actions: - **list**: List organization holiday calendar dates for a year (optional ISO country override). (data: year*, country) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | – | yes | – |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | object | – | – |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
shared-status Shared-status ~135
Manage Focus shared-status with the following actions: - **get**: Health check for the Shared Data API. (data: none) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | – | yes | – |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | object | – | – |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
shared-working-hours Shared-working-hours ~234
Manage Focus shared-working-hours with the following actions: - **list**: Get your working hours entries for the active organization. (data: none) - **put**: Replace working hours by ID (JSON array of updates). (data: array payload) - **create**: Create working hour rows (JSON array). (data: array payload) - **delete**: Delete working hour rows by ID. (data: ids*) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: list, put, create, delete |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
sharedreports Sharedreports ~433
Manage Focus sharedreports with the following actions: - **add-shared-report-grants**: Add Shared Report Grants Sharedreports. (data: id*, payload*{grantees*}) - **get-saved-view-shared-report**: Get Saved View Shared Report Sharedreports. (data: id*) - **get-shared-report-for-viewer**: Get Shared Report For Viewer Sharedreports. (data: id*) - **get-shared-reports-shared-by-me**: Get Shared Reports Shared By Me Sharedreports. (data: none) - **get-shared-reports-shared-with-me**: Get Shared Reports Shared With Me Sharedreports. (data: none) - **revoke-shared-report-grant**: Revoke Shared Report Grant Sharedreports. (data: grant_id*, id*) - **share-saved-view**: Share Saved View Sharedreports. (data: id*, payload*{charts*, period, team_id, user_id, workspace_id}) - **share-saved-view-many**: Share Saved View Many Sharedreports. (data: id*, payload*{charts*, grantees*, period}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: add-shared-report-grants, get-saved-view-shared-report, get-shared-report-for-viewer, get-shared-reports-shared-by-me, get-shared-reports-shared-with-me, revoke-shared-report-grant, share-sav… |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
statuses Statuses ~316
Manage Focus statuses with the following actions: - **create-status**: Create a task status. (data: payload*{emoji*, name*, position*}) - **delete-status**: Delete a task status. (data: status_id*) - **get-status**: List task statuses with generated API filters. (data: status_id*) - **list**: List Statuses. Lists all task status options for the workspace. Use returned status IDs when creating or updating tasks via status_id. Statuses have types: todo, in_progress, done, blocked. (data: page, per_page) - **restore**: Restore Statuses. (data: status_id*) - **update-status**: Update a task status. (data: payload*{emoji*, name*, position*}, status_id*) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create-status, delete-status, get-status, list, restore, update-status |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
subscriptions Subscriptions ~269
Manage Focus subscriptions with the following actions: - **get-current**: Get Current Subscriptions. (data: none) - **get-current-trial**: Get Current Trial Subscriptions. (data: none) - **get-features-upsell**: Get Features Upsell Subscriptions. (data: none) - **get-plans**: Get Plans Subscriptions. (data: none) - **upsert-forced-trial**: Upsert Forced Trial Subscriptions. (data: payload*{plan_workspace_id}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: get-current, get-current-trial, get-features-upsell, get-plans, upsert-forced-trial |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
tags Tags ~474
Manage Focus tags with the following actions: - **archive**: Archive Tags. (data: tag_id*) - **bulk-archive**: Bulk Archive Tags. (data: payload*{tag_ids*}) - **bulk-create**: Bulk Create Tags. (data: payload*{tags*}) - **bulk-delete**: Bulk Delete Tags. (data: ids*) - **bulk-restore**: Bulk Restore Tags. (data: payload*{tag_ids*}) - **bulk-unarchive**: Bulk Unarchive Tags. (data: payload*{tag_ids*}) - **create**: Create Tags. Both name and color are required by the API (hex color, e.g. #FF5733). (data: color*, name*) - **delete**: Delete Tags. (data: tag_id*) - **get**: Get Tags. (data: tag_id*) - **list**: List Tags. Workspace tags label tasks and projects. Use tag IDs with tasks (tag_ids) and organization user filters (tag_ids on users.list). (data: name, page, per_page) - **merge**: Merge Tags. (data: payload*{source_ids*, target_id*}) - **restore**: Restore Tags. (data: tag_id*) - **unarchive**: Unarchive Tags. (data: tag_id*) - **update**: Update Tags. (data: tag_id*, payload*{color, name}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: archive, bulk-archive, bulk-create, bulk-delete, bulk-restore, bulk-unarchive, create, delete, get, list, merge, restore, unarchive, update |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
tasks Tasks ~2,251
Manage Focus tasks with the following actions: - **create-task**: Create a task with related data such as subtasks, time blocks, and an initial time entry. (data: payload*{task*, estimate_allocations, subtasks, time_blocks, time_entry}) - **archive**: Archive Tasks. (data: from_recurring_task_id, task_id*) - **attachments-bulk-create**: Attachments Bulk Create Tasks. Uploads several local files in one call. names and display_orders are optional parallel arrays; they default to the file basenames and array positions. (data: task_id*, file_paths*, names, display_orders) - **attachments-create**: Attachments Create Tasks. Uploads a local file (file_path) as an attachment. The mime type is inferred from the extension and the API rejects disallowed types; uploads are capped at 20 MB. (data: task_id*, file_path*, name, display_order) - **attachments-delete**: Attachments Delete Tasks. (data: attachment_id*, task_id*) - **attachments-list**: Attachments List Tasks. Lists attachment metadata. Upload files with attachments-create (file_path), download with attachments-view (save_to). (data: order_by, task_id*) - **attachments-update**: Attachments Update Tasks. Full update (PUT): both name and display_order are required; the response body is empty, verify via attachments-list. (data: attachment_id*, payload*{display_order*, name*}, task_id*) - **attachments-view**: Attachments View Tasks. Downloads the attachment's binary content to a local path (save_to). Refuses to replace an existing file unless overwrite is true. (data: task_id*, attachment_id*, save_to*, overwrite) - **bulk-archive**: Bulk Archive Tasks. (data: task_ids*) - **bulk-create**: Bulk Create Tasks. (data: tasks*) - **bulk-delete**: Bulk Delete Tasks. Deletes all listed task IDs in one HTTP call. Requires confirm flow like single delete. (data: ids*, outbound_sync) - **bulk-duplicate**: Bulk Duplicate Tasks. (data: cascade_duplicate_children*, task_ids*, private) - **bulk-patch**: Bulk Patch Tasks. Prefer ov…
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create-task, archive, attachments-bulk-create, attachments-create, attachments-delete, attachments-list, attachments-update, attachments-view, bulk-archive, bulk-create, bulk-delete, bulk-dup… |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
time-blocks Time-blocks ~732
Manage Focus time-blocks with the following actions: - **archive**: Archive Time Blocks. (data: task_id*, time_block_id*) - **bulk-create**: Bulk Create Time Blocks. Body shape: { time_blocks: [{ task_id, start, duration?, completed? }, ...] }. Creates many blocks in one request. (data: time_blocks*) - **bulk-delete**: Bulk Delete Time Blocks. Deletes time blocks by numeric id list in one HTTP call (not task_id/time_block_id pairs). (data: ids*, outbound_sync) - **bulk-patch**: Bulk Patch Time Blocks. JSON array of { id: timeBlockId, ...partial fields }; same fields as single time-block update. (data: array payload) - **create**: Create Time Blocks. Required: task_id and payload.start (ISO 8601 datetime). Optionally set payload.duration (minutes) and payload.completed. (data: task_id*, payload*{start*, completed, duration, outbound_sync}) - **delete**: Delete Time Blocks. Permanently removes the scheduled time block from the task. (data: task_id*, time_block_id*) - **get**: Get Time Blocks. Fetch a single time block by task ID and time block ID. (data: task_id*, time_block_id*) - **get-range-stream**: Get Range Stream Time Blocks. (data: archived*, date_from*, date_to*, order_by*, status_id*, task_id*) - **get-task-time-blocks**: Get Task Time Blocks Time Blocks. (data: archived, order_by, page, per_page, task_id*) - **list**: List Time Blocks. Returns scheduled time blocks in a date range. Requires date_from and date_to. Accepts date-only strings (YYYY-MM-DD) or RFC3339 datetimes — date-only is automatically expanded: date_from to T00:00:00Z, date_to to T23:59:59Z. Results include associated task summaries. (data: date_from*, date_to*, task_id, page, per_page) - **restore**: Restore Time Blocks. (data: task_id*, time_block_id*) - **unarchive**: Unarchive Time Blocks. (data: task_id*, time_block_id*) - **update**: Update Time Blocks. Partial update — provide task_id, time_block_id, and fields to change in payload. (data: task_id*, time_block_id*, payload*{complete…
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: archive, bulk-create, bulk-delete, bulk-patch, create, delete, get, get-range-stream, get-task-time-blocks, list, restore, unarchive, update, update-with-org |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
time-entries Time-entries ~1,576
Manage Focus time-entries with the following actions: - **archive**: Archive Time Entries. (data: time_entry_id*) - **bulk-create**: Bulk Create Time Entries. JSON array of entries with task_id, start, duration, type ('activity'|'break'). One HTTP request for many creates. Datetime fields (start, planned_start, planned_at, tracked_at) must be RFC3339 with a timezone (e.g. 2026-04-01T09:00:00Z or 2026-04-01T11:00:00+02:00), not YYYY-MM-DDTHH:MM. (data: array payload) - **bulk-delete**: Bulk Delete Time Entries. Soft-delete multiple time entries by id in one request. (data: ids*) - **bulk-edit**: Bulk Edit Time Entries. (data: payload*{changes*, ids*}) - **bulk-patch**: Bulk Patch Time Entries. JSON array of { id: timeEntryId, ...partial fields } for bulk partial update. Datetime fields (start, planned_start, planned_at, tracked_at) must be RFC3339 with a timezone, or null to clear. (data: array payload) - **bulk-restore**: Bulk Restore Time Entries. Restore deleted time entries by id in one request. (data: ids*) - **bulk-set-day-duration**: Bulk Set Day Duration Time Entries. (data: payload*) - **constraints-list**: Constraints List Time Entries. (data: none) - **constraints-upsert**: Constraints Upsert Time Entries. (data: payload*{enabled*, required_fields*, disallow_billable_override}) - **create**: Create a completed task time entry. payload.type defaults to 'activity' when omitted. Logs a completed task time entry. payload.type defaults to 'activity' when omitted; pass 'break' explicitly for a break. provide payload.start and payload.duration for completed tracked time. payload.start must be RFC3339 with a timezone (e.g. 2026-04-01T09:00:00Z or 2026-04-01T11:00:00+02:00), not YYYY-MM-DDTHH:MM. (data: payload*{...}, task_id*) - **create-taskless**: Create a completed taskless time entry. payload.type defaults to 'activity' when omitted. Logs a completed taskless time entry. payload.type defaults to 'activity' when omitted; pass 'break' explicitly for a break. (…
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: archive, bulk-create, bulk-delete, bulk-edit, bulk-patch, bulk-restore, bulk-set-day-duration, constraints-list, constraints-upsert, create, create-taskless, delete, get, get-batch, get-strea… |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
time-off Time-off ~313
Manage Focus time-off with the following actions: - **create-timeoff-for-user**: Create Timeoff For User Time Off. (data: payload*, user_id*) - **delete-timeoff-for-user**: Delete Timeoff For User Time Off. (data: payload*, user_id*) - **get-timeoff-for-user**: Get Timeoff For User Time Off. (data: from*, to*, user_id*) - **get-timeoffs-by-user-ids**: Get Timeoffs By User Ids Time Off. (data: end_date*, start_date*, user_id*) - **update-timeoff-for-user**: Update Timeoff For User Time Off. (data: payload*, user_id*) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create-timeoff-for-user, delete-timeoff-for-user, get-timeoff-for-user, get-timeoffs-by-user-ids, update-timeoff-for-user |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
timesheets Timesheets ~1,049
Manage Focus timesheets with the following actions: - **add-timesheet-flag**: Add Timesheet Flag Timesheets. (data: payload*{comment*, time_entry_id*}, setup_id*, start_date*, user_account_id*) - **approve**: Approve Timesheets. (data: setup_id*, start_date*, user_account_id*) - **bulk-approve**: Bulk Approve Timesheets. (data: payload*{keys*}) - **bulk-request-changes**: Bulk Request Changes Timesheets. (data: payload*{keys*, comment}) - **bulk-withdraw**: Bulk Withdraw Timesheets. (data: payload*{keys*}) - **get**: Get Timesheets. (data: approver_user_account_ids*, current_layer_approver_user_account_id*, date_from*, date_to*, page*, per_page*, setup_id*, statuses*, team_ids*, user_account_ids*) - **get-approvers**: Get Approvers Timesheets. (data: none) - **get-details**: Get Details Timesheets. (data: setup_id*, start_date*, user_account_id*) - **get-flags**: Get Flags Timesheets. (data: setup_id*, start_date*, user_account_id*) - **get-history**: Get History Timesheets. (data: setup_id*, start_date*, user_account_id*) - **get-hours**: Get Hours Timesheets. (data: setup_id*, start_date*, user_account_id*) - **remove-timesheet-flag**: Remove Timesheet Flag Timesheets. (data: flag_id*) - **request-changes**: Request Changes Timesheets. (data: payload*{comment*}, setup_id*, start_date*, user_account_id*) - **resubmit**: Resubmit Timesheets. (data: payload*{comment*}, setup_id*, start_date*, user_account_id*) - **setups-add-timesheet-setup-member**: Setups Add Timesheet Setup Member Timesheets. (data: setup_id*, user_account_id*) - **setups-create**: Setups Create Timesheets. (data: payload*{approvers*, member_user_account_ids*, periodicity*, start_date*, email_reminder_enabled, period_days, reminder_day, reminder_time}) - **setups-delete**: Setups Delete Timesheets. (data: setup_id*) - **setups-delete-member**: Setups Delete Member Timesheets. (data: setup_id*, user_account_id*) - **setups-discontinue**: Setups Discontinue Timesheets. (data: payload*{end_date*},…
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: add-timesheet-flag, approve, bulk-approve, bulk-request-changes, bulk-withdraw, get, get-approvers, get-details, get-flags, get-history, get-hours, remove-timesheet-flag, request-changes, res… |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
users Users ~289
Manage Focus users with the following actions: - **list**: List Users. Lists organization users (members). Use returned IDs for assignee_user_ids on tasks. Invite or provision new users from the Toggl Track/Focus web UI or billing admin — this API lists existing users only. (data: page, per_page, filter, sort_dir, only_admins, include_working_hours, include_rates, workspaces, tag_ids, roles, active_status, groups, pinned_ids, user_account_ids, org_user_ids) - **settings-list**: Settings List Users. (data: none) - **settings-partial-update**: Settings Partial Update Users. (data: payload*{...}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: list, settings-list, settings-partial-update |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
version Version ~183
Manage Focus version with the following actions: - **service**: MCP package version plus the Focus API service revision. mcp.package is this published MCP package version (e.g. 1.8.0). focus_api is the Focus API process revision (git SHA / build number) — it does not change when you update the npm MCP package. (data: none) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | – | yes | – |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | object | – | – |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
working-hours Working-hours ~244
Manage Focus working-hours with the following actions: - **create-for-user**: Create For User Working Hours. (data: payload*, user_id*) - **delete-for-user**: Delete For User Working Hours. (data: payload*, user_id*) - **get-for-user**: Get For User Working Hours. (data: user_id*) - **update-for-user**: Update For User Working Hours. (data: payload*, user_id*) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create-for-user, delete-for-user, get-for-user, update-for-user |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
workspace Workspace ~130
Manage Focus workspace with the following actions: - **get-context**: Get Context Workspace. (data: none) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | – | yes | – |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | object | – | – |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
workspace-list List Workspaces ~41
List workspaces for the active MCP profile. Pass refresh: true to refetch from Accounts when a workspace is missing from cache.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | – |
No output schema declared.
No examples provided.
workspace-settings Workspace-settings ~397
Manage Focus workspace-settings with the following actions: - **workspace-settings-list**: List user workspace settings. (data: none) - **workspace-settings-partial-update**: Update user workspace settings. (data: payload*) - **get-user-permissions**: Get User Permissions Workspace Settings. (data: none) - **get-workspace-currency**: Get Workspace Currency Workspace Settings. (data: none) - **get-workspace-export-branding**: Get Workspace Export Branding Workspace Settings. (data: none) - **get-workspace-watermark**: Get Workspace Watermark Workspace Settings. (data: none) - **list**: List Workspace Settings. (data: none) - **update**: Update Workspace Settings. (data: payload*{settings*}) - **update-workspace-currency**: Update Workspace Currency Workspace Settings. (data: payload*{currency*}) - **update-workspace-watermark**: Update Workspace Watermark Workspace Settings. (data: payload*{show_watermark*}) Pass the action-specific fields under `data` (required fields are marked with *). Mutations require a confirm_token handshake: call without confirm_token first to receive a token, then call again with the token to confirm. Optional dry_run: true validates input and returns { dry_run, operation, input } without calling the API.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: workspace-settings-list, workspace-settings-partial-update, get-user-permissions, get-workspace-currency, get-workspace-export-branding, get-workspace-watermark, list, update, update-workspac… |
| confirm_token | string | – | Mutation confirmation token from previous call |
| data | – | – | Action-specific payload. See each action's parameters in this tool's description; pass dry_run: true to validate it without calling the API. |
| dry_run | boolean | – | – |
No output schema declared.
No examples provided.
workspace-switch Switch Workspace ~44
Switch the active workspace by updating the stored configuration. The new workspace takes effect on the next tool call. Use workspace-list to see available workspace IDs.
| Name | Type | Req | Description |
|---|---|---|---|
| workspace_id | – | yes | – |
No output schema declared.
No examples provided.
What is the Toggl 2.0 MCP server?
Toggl 2.0 is an MCP server listed in the public MCP registry as io.github.toggl/toggl-mcp. Toggl 2.0 MCP server for tasks, projects, time entries, and workspace operations. This page covers its npm package (@togglhq/mcp).
Is the Toggl 2.0 MCP server safe to use?
Toggl 2.0 scores 68 out of 100 on VerifyMCP. We recorded 1 known advisory against it as of 26 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Toggl 2.0 MCP server expose?
Toggl 2.0 exposes 45 tools: workspace-list, workspace-switch, profile-list, profile-switch, profile-remove, and 40 more. Their descriptions and schemas cost roughly 19,432 tokens of context every time the server is loaded.
Is the Toggl 2.0 MCP server still maintained?
Toggl 2.0 is still listed as active in the MCP registry. We last reached this channel on 26 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Toggl 2.0 MCP server under?
Toggl 2.0 declares the UNLICENSED licence, which is not on the OSI-approved list. Read the terms before using it at work, and note this covers the source only, not the cost of any service it calls.