Kaiten MCP Server
A remote Kaiten MCP server for Claude with full OAuth 2.1: read-only boards, cards, sprints and backlog analytics
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- The server reads live Kaiten data: cards, comments, time logs and team analytics
- The Kaiten token is stored on a third-party deployed instance, not with the vendor
Install
Manual install
npm install && npm run buildLocal dev run: ALLOW_UNAUTHENTICATED=1 KAITEN_HOST=... KAITEN_TOKEN=... npm start.
This is third-party code. Review the repository files before installing.
What it does
The server deploys to Railway or Render and connects to Claude as a remote connector via OAuth 2.1 with PKCE. Twelve tools are read-only: board lists and structure, cards with flexible filters and full detail, blockers, time logs, external links, sprints and backlog analytics by column, blockers and workload. The Kaiten token is kept only on the server, Claude never sees it. Access is gated by a separate owner password on the consent page, and the allowed redirect URIs are set manually. The server refuses to start without the auth environment variables, so it never ends up exposed unprotected.
Who it is for. For Kaiten teams who want to give Claude remote board access without handing out tokens, with careful connection security.
Good fit when
- You want a shared remote Kaiten connector for a team in Claude without a local process
- Read access is enough: boards, cards, sprints and backlog analytics
- You are ready to deploy your own instance on Railway or Render and configure OAuth
Not a fit when
- You need to create or edit cards and comments: the server is read-only
- You do not want to deploy and maintain your own instance with six required environment variables
Example request
Show backlog analytics for board 456: how many cards are overdue and where the bottleneck isLimitations
Tools are read-only; the server cannot write to Kaiten. You need your own deployed instance on Railway, Render or elsewhere, there is no ready-made cloud server. The in-memory token store is cleared on every redeploy, after which users must reconnect and re-enter the password. 0 stars, a single author, not community-vetted.
How to disable. In Claude, remove the Kaiten connector from integration settings and stop or delete the deployed instance on Railway or Render.
MCP
- Transport
- http
- Authentication
- OAuth
| Environment variables | |
|---|---|
| KAITEN_HOST required | Kaiten workspace domain |
| KAITEN_TOKEN required, secret | Kaiten API token |
| OAUTH_CLIENT_ID required | OAuth client ID for Claude |
| OAUTH_CLIENT_SECRET required, secret | OAuth client secret |
| OWNER_PASSWORD required, secret | Owner password that approves every OAuth sign-in |
| OAUTH_REDIRECT_URIS required | Comma-separated list of allowed redirect URIs |
Security check
- The server reads live Kaiten data: cards, comments, time logs and team analytics
- The Kaiten token is stored on a third-party deployed instance, not with the vendor
README in short
The README describes a remote MCP server for Kaiten deployable to Railway or Render, a table of twelve tools, and a detailed security section: OAuth 2.1 with PKCE, RFC 9728 and 8414 metadata discovery, rate limiting, Host header injection protection and constant-time secret comparison. It separately lists every environment variable and a local dev run with an explicit flag to disable authentication.
FAQ
Can the server create cards?
No, all twelve tools only read Kaiten data.
What protects the server from outside access?
OAuth 2.1 with PKCE, an owner password on the consent page, a redirect URI whitelist, and a refusal to start without all auth variables set.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI