Kaiten MCP (tyunn)
Kaiten MCP
An MCP server and CLI for Kaiten with per-project settings and access limited to chosen spaces and boards
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- The access token is stored in a plain config file on disk
- Without KAITEN_ALLOWED_SPACE_IDS the agent sees every space the token can reach
Install
Manual install
git clone https://github.com/tyunn/kaiten-mcp.git
cd kaiten-mcpThen create ~/.kaiten/config with KAITEN_API_URL and KAITEN_API_TOKEN.
This is third-party code. Review the repository files before installing.
What it does
The project wraps the Kaiten API in an MCP server and a matching CLI. A shared token and API address live in the global ~/.kaiten/config file, while project-specific settings such as the default space and board go into .kaiten.env in the project folder. Access can be restricted to listed spaces and boards via KAITEN_ALLOWED_SPACE_IDS and KAITEN_ALLOWED_BOARD_IDS, with adjustable log verbosity and an API client covering cards, comments, subtasks and files.
Who it is for. For teams running several Kaiten projects who want to restrict an agent to specific spaces and boards.
Good fit when
- You want one shared token but need to limit access per project
- You also want a CLI, not just an MCP server
- You need to control the verbosity of Kaiten request logging
Not a fit when
- You want a simple setup without a global config and per-project env variables
- You need a published npm package instead of cloning the repository
Example request
Show overdue cards in the default space, limited to the allowed boardsLimitations
The project has no stars or license and installs only via git clone; there is no published npm package. The ~/.kaiten/config file stores the token in plain text and must not be committed.
How to disable. Remove the server from your MCP client configuration and delete the ~/.kaiten/config file with the token.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| KAITEN_API_URL required | API URL of your Kaiten space |
| KAITEN_API_TOKEN required, secret | Kaiten access token |
| KAITEN_ALLOWED_SPACE_IDS | List of space IDs the agent may access |
| KAITEN_ALLOWED_BOARD_IDS | List of board IDs the agent may access |
Security check
- The access token is stored in a plain config file on disk
- Without KAITEN_ALLOWED_SPACE_IDS the agent sees every space the token can reach
README in short
The extensive Russian README covers installing from the repository, the mandatory global access config, an optional project config with space and board restrictions, response token optimization, and a separate section of instructions for AI assistants on using the tools.
FAQ
What order are settings read in?
The global ~/.kaiten/config first, then the project's .kaiten.env on top of it.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything