Weeek MCP server
weeek-mcp
A local MCP server for Weeek: projects, tasks and boards are read-only by default, writes are opt-in
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- With READ_ONLY=false the agent can create, edit and move tasks in the workspace
- The token grants access to everything its owner can see
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/weeek-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run in a terminal
claude mcp add --transport stdio --env 'WEEEK_ACCESS_TOKEN=<your WEEEK_ACCESS_TOKEN>' weeek-mcp -- npx -y weeek-mcp@1.0.1Or add to the file .mcp.json, in the project
{
"mcpServers": {
"weeek-mcp": {
"command": "npx",
"args": [
"-y",
"weeek-mcp@1.0.1"
],
"env": {
"WEEEK_ACCESS_TOKEN": "<your WEEEK_ACCESS_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"weeek-mcp": {
"command": "npx",
"args": [
"-y",
"weeek-mcp@1.0.1"
],
"env": {
"WEEEK_ACCESS_TOKEN": "<your WEEEK_ACCESS_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Run in a terminal
code --add-mcp '{"name":"weeek-mcp","type":"stdio","command":"npx","args":["-y","weeek-mcp@1.0.1"],"env":{"WEEEK_ACCESS_TOKEN":"<your WEEEK_ACCESS_TOKEN>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"weeek-mcp": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"weeek-mcp@1.0.1"
],
"env": {
"WEEEK_ACCESS_TOKEN": "<your WEEEK_ACCESS_TOKEN>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add weeek-mcp --env 'WEEEK_ACCESS_TOKEN=<your WEEEK_ACCESS_TOKEN>' -- npx -y weeek-mcp@1.0.1Or add to the file ~/.codex/config.toml, for all projects
[mcp_servers.weeek-mcp]
command = "npx"
args = ["-y", "weeek-mcp@1.0.1"]
env = { WEEEK_ACCESS_TOKEN = "<your WEEEK_ACCESS_TOKEN>" }If the file already exists, append the block to the end.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"weeek-mcp": {
"command": "npx",
"args": [
"-y",
"weeek-mcp@1.0.1"
],
"env": {
"WEEEK_ACCESS_TOKEN": "<your WEEEK_ACCESS_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"weeek-mcp": {
"command": "npx",
"args": [
"-y",
"weeek-mcp@1.0.1"
],
"env": {
"WEEEK_ACCESS_TOKEN": "<your WEEEK_ACCESS_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"weeek-mcp": {
"command": "npx",
"args": [
"-y",
"weeek-mcp@1.0.1"
],
"env": {
"WEEEK_ACCESS_TOKEN": "<your WEEEK_ACCESS_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"weeek-mcp": {
"command": "npx",
"args": [
"-y",
"weeek-mcp@1.0.1"
],
"env": {
"WEEEK_ACCESS_TOKEN": "<your WEEEK_ACCESS_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"weeek-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"weeek-mcp@1.0.1"
],
"environment": {
"WEEEK_ACCESS_TOKEN": "<your WEEEK_ACCESS_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"weeek-mcp": {
"command": "npx",
"args": [
"-y",
"weeek-mcp@1.0.1"
],
"env": {
"WEEEK_ACCESS_TOKEN": "<your WEEEK_ACCESS_TOKEN>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"weeek-mcp": {
"command": "npx",
"args": [
"-y",
"weeek-mcp@1.0.1"
],
"env": {
"WEEEK_ACCESS_TOKEN": "<your WEEEK_ACCESS_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
WEEEK_ACCESS_TOKENsecret, required- Weeek Public API v1 access token. Required — the server refuses to start without it.
READ_ONLYoptional- Gate for the write tools. Defaults to 'true': a fresh install exposes only the ten read tools. Set to 'false' to additionally expose the five write tools (create/update/move/complete a task, set an MR link) — an explicit operator opt-in, never the default.
ENABLED_TOOLSoptional- Optional comma-separated allowlist of tool names to register (still subject to READ_ONLY). Pair with READ_ONLY=false for a granular write rollout, e.g. 'weeek_complete_task'.
WEEEK_BASE_URLoptional- Override the Weeek API base URL. Defaults to the public v1 endpoint.
WEEEK_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
MAX_RESPONSE_CHARSoptional- Upper bound on the JSON length of a single tool response, protecting the agent's context window from unbounded list/detail payloads.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add the MCP server with npx -y weeek-mcp, pass a token via WEEEK_ACCESS_TOKEN, and leave READ_ONLY at its default unless you need writes.
Other ways from the author
{
"mcpServers": {
"weeek": {
"command": "npx",
"args": ["-y", "weeek-mcp"],
"env": {
"WEEEK_ACCESS_TOKEN": "YOUR_WEEEK_TOKEN_HERE"
}
}
}
}The README config for Claude Desktop; Cursor and Cline use the same mcpServers shape.
This is third-party code. Review the repository files before installing.
What it does
The server runs over stdio and uses a personal Weeek token to give an agent access to a workspace. Ten read tools are available by default: projects, tasks with filters and pagination, members, tags, boards and board columns. Five write tools, including creating and moving tasks, stay hidden until READ_ONLY is set to false, and can be narrowed further with an ENABLED_TOOLS allowlist. Responses are validated with zod, clipped to a character budget, and return distinct, agent-readable error codes.
Who it is for. For teams on Weeek who want an agent to see tasks and boards without risking changes by default.
Good fit when
- You want an agent to read Weeek tasks, boards and members
- You want a safe start with the option to enable specific writes later
- You want to install via npx without building from source
Not a fit when
- You need Weeek tools beyond tasks, projects and columns
- You want to work without a personal API token
Example request
Show my open Weeek tasks for the redesign projectLimitations
You need a personal Weeek API token. Beyond the READ_ONLY flag itself, writes have no server-side confirmation step: task creation cannot be undone through the server, and moves or edits must be reverted by hand. The server does not read a .env file itself, so variables must come from the client's config.
How to disable. Remove the weeek entry from your MCP client configuration.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| WEEEK_ACCESS_TOKEN required, secret | Personal Weeek API token |
| READ_ONLY | Hides the five write tools, defaults to true |
| ENABLED_TOOLS | Comma-separated allowlist of tool names |
Security check
- With READ_ONLY=false the agent can create, edit and move tasks in the workspace
- The token grants access to everything its owner can see
README in short
The README covers npx install, a table of ten read tools and five write tools with what each one changes and how to undo it. It lists the environment variables in detail: token, base URL, timeout, READ_ONLY, ENABLED_TOOLS, response character limit and log level. There is a table of common startup errors and a section on MCP Inspector and local debugging.
FAQ
Can the agent create tasks right after install?
No, the five write tools are not registered until READ_ONLY=false is set.
How do I limit the agent to one write action?
Set READ_ONLY=false and list the tool in ENABLED_TOOLS; the allowlist intersects with READ_ONLY rather than adding to it.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail