Yandex Disk MCP server for Claude
Yandex Disk MCP Server
A Yandex Disk MCP server with a full operation set: file listing, upload by URL, folders, public links and deletion
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Allows permanently deleting files from the Disk
- Uploads arbitrary files from external URLs to the user's Disk
- The server's only protection is a URL secret with no expiry
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/irikrafikov-ai-yandex-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport http 'Yandex Disk MCP Server' 'https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>' --header 'Authorization: Bearer <your YANDEX_DISK_TOKEN>'Or add to the file .mcp.json, in the project
{
"mcpServers": {
"Yandex Disk MCP Server": {
"type": "http",
"url": "https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>",
"headers": {
"Authorization": "Bearer <your YANDEX_DISK_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
YANDEX_DISK_TOKENsecret, required- OAuth-токен Яндекс.Диска
CONNECTOR_SECRETsecret, required- Секрет для защиты MCP-сервера
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"Yandex Disk MCP Server": {
"url": "https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>",
"headers": {
"Authorization": "Bearer <your YANDEX_DISK_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
YANDEX_DISK_TOKENsecret, required- OAuth-токен Яндекс.Диска
CONNECTOR_SECRETsecret, required- Секрет для защиты MCP-сервера
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"Yandex Disk MCP Server","type":"http","url":"https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>","headers":{"Authorization":"Bearer <your YANDEX_DISK_TOKEN>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"Yandex Disk MCP Server": {
"type": "http",
"url": "https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>",
"headers": {
"Authorization": "Bearer <your YANDEX_DISK_TOKEN>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
YANDEX_DISK_TOKENsecret, required- OAuth-токен Яндекс.Диска
CONNECTOR_SECRETsecret, required- Секрет для защиты MCP-сервера
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.codex/config.toml, for all projects
[mcp_servers."Yandex Disk MCP Server"]
url = "https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>"
http_headers = { Authorization = "Bearer <your YANDEX_DISK_TOKEN>" }If the file already exists, append the block to the end.
Keys and settings
YANDEX_DISK_TOKENsecret, required- OAuth-токен Яндекс.Диска
CONNECTOR_SECRETsecret, required- Секрет для защиты MCP-сервера
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"Yandex Disk MCP Server": {
"httpUrl": "https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>",
"headers": {
"Authorization": "Bearer <your YANDEX_DISK_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
YANDEX_DISK_TOKENsecret, required- OAuth-токен Яндекс.Диска
CONNECTOR_SECRETsecret, required- Секрет для защиты MCP-сервера
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"Yandex Disk MCP Server": {
"serverUrl": "https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>",
"headers": {
"Authorization": "Bearer <your YANDEX_DISK_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
YANDEX_DISK_TOKENsecret, required- OAuth-токен Яндекс.Диска
CONNECTOR_SECRETsecret, required- Секрет для защиты MCP-сервера
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"Yandex Disk MCP Server": {
"type": "streamableHttp",
"url": "https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>",
"headers": {
"Authorization": "Bearer <your YANDEX_DISK_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
YANDEX_DISK_TOKENsecret, required- OAuth-токен Яндекс.Диска
CONNECTOR_SECRETsecret, required- Секрет для защиты MCP-сервера
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"Yandex Disk MCP Server": {
"type": "streamable-http",
"url": "https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>",
"headers": {
"Authorization": "Bearer <your YANDEX_DISK_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
YANDEX_DISK_TOKENsecret, required- OAuth-токен Яндекс.Диска
CONNECTOR_SECRETsecret, required- Секрет для защиты MCP-сервера
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"Yandex Disk MCP Server": {
"type": "remote",
"url": "https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>",
"headers": {
"Authorization": "Bearer <your YANDEX_DISK_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
YANDEX_DISK_TOKENsecret, required- OAuth-токен Яндекс.Диска
CONNECTOR_SECRETsecret, required- Секрет для защиты MCP-сервера
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"Yandex Disk MCP Server": {
"url": "https://твой-адрес-на-render.onrender.com/mcp/<your CONNECTOR_SECRET>",
"headers": {
"Authorization": "Bearer <your YANDEX_DISK_TOKEN>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
YANDEX_DISK_TOKENsecret, required- OAuth-токен Яндекс.Диска
CONNECTOR_SECRETsecret, required- Секрет для защиты MCP-сервера
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Deploy index.js on Render with YANDEX_DISK_TOKEN and CONNECTOR_SECRET set, then add a custom connector in Claude.ai at https://<your-app>.onrender.com/mcp/<CONNECTOR_SECRET>.
This is third-party code. Review the repository files before installing.
What it does
The Node.js server gives Claude access to Yandex Disk via an OAuth token: listing files and folders, file metadata, a temporary download link, uploading a file to the Disk from an external URL, creating folders, deleting resources to trash or permanently, and publishing a file to get a public link. The README is written as a step-by-step guide for someone with no deployment experience: push the code to GitHub, spin up a free service on Render, and connect it as a custom connector in Claude.ai at an address with a secret in the path.
Who it is for. For people who want to give Claude full read and write access to their Yandex Disk without deployment experience.
Good fit when
- You want the agent to upload files by URL to the Disk and organize them into folders
- You need public links for Disk files generated by the agent
- You have no deployment experience but do have GitHub and Render accounts
Not a fit when
- You need read-only isolation: the server grants delete and upload from the start
- You are not ready to keep the connector secret safe: it is equivalent to full Disk access
Example request
Upload the file at this URL to the Disk into the Projects folder and give me a public linkLimitations
The free Render plan sleeps after inactivity and takes 20 to 30 seconds to wake on the first request. The CONNECTOR_SECRET in the URL grants full Disk access and must be rotated at the slightest suspicion of a leak. The author recommends keeping the repository private. No license file.
How to disable. Remove the connector in Claude.ai (Settings, Connectors) and stop the service in Render.
MCP
- Transport
- http
- Authentication
- API key
| Environment variables | |
|---|---|
| YANDEX_DISK_TOKEN required, secret | Yandex Disk OAuth token |
| CONNECTOR_SECRET required, secret | Path secret protecting the server from unauthorized requests |
Security check
- Allows permanently deleting files from the Disk
- Uploads arbitrary files from external URLs to the user's Disk
- The server's only protection is a URL secret with no expiry
README in short
The README is written as a beginner's guide: get an OAuth token via the Yandex Disk playground, push the code to a private repo, deploy on Render with two environment variables, connect it in Claude.ai, and a list of seven tools with brief descriptions. It ends with a separate warning about keeping the secret safe.
FAQ
Can the agent permanently delete files?
Yes, the delete_resource tool supports both moving to trash and permanent deletion.
What protects the server from unauthorized access?
Only the CONNECTOR_SECRET in the URL path: requests without it are rejected, but the secret has no expiry or scope limit.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI