yadisk-mcp

A Yandex Disk MCP server with 22 tools covering files, public links and trash, background uploads for large files, and a read-only mode

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • By default it can delete, move and publish files on Yandex Disk
  • It can upload arbitrary local files unless folders are restricted via an environment variable
  • Start with the --read-only flag until write access is actually needed
All reasons and checks
Russian stack

patr56/yadisk-mcp

Install

Manual install

pip install yadisk-mcp

Install the package from PyPI.

This is third-party code. Review the repository files before installing.

What it does

The server covers the Yandex Disk API asynchronously with 22 tools: quota and disk info, listing and searching files, creating, copying, moving, renaming and deleting, uploading a local file (synchronously up to about 100 MB, or in the background with a job_id and progress tracking for larger ones), uploading from a URL, publishing files with a link and unpublishing, and trash operations. A --read-only flag, environment variable or programmatic setting blocks every write operation and leaves only browsing. A separate variable restricts which local folders uploads may read from and blocks symlinks that point outside them.

Who it is for. For people who want full Yandex Disk management through an agent, from uploading large files to publishing links.

Good fit when

  • You need to upload large files in the background with progress tracking
  • You want to publish a file and get a public link right from a conversation with an agent
  • You need a safe read-only mode for demos or browsing someone else's disk

Not a fit when

  • You want a minimal server with no write operations at all: writes are on by default here, read-only mode must be turned on separately
  • You do not want to issue a token with write access to the whole disk

Example request

Find all PDF files on Yandex Disk from the last month and publish the most recent one

Limitations

It needs a Yandex OAuth token with cloud_api:disk.read, disk.write, disk.app_folder and disk.info scopes, obtained through your own application at oauth.yandex.ru. The token is valid for a year and needs manual renewal. By default upload_local_file can read any local file unless YADISK_MCP_UPLOAD_ALLOWED_DIRS is set. Emptying the trash is irreversible.

How to disable. Remove the server with claude mcp remove yadisk or manually from your client config, and revoke the OAuth token at oauth.yandex.ru.

MCP

Transport
stdio
Authentication
API key
Environment variables
Environment variables
YANDEX_DISK_TOKEN
required, secret
Yandex OAuth token with cloud_api:disk.read, disk.write, disk.app_folder, disk.info scopes
YADISK_MCP_READ_ONLY
Enables read-only mode and blocks every write tool
YADISK_MCP_UPLOAD_ALLOWED_DIRS
List of local folders that uploads to the disk are allowed to read from

Security check

  • By default it can delete, move and publish files on Yandex Disk
  • It can upload arbitrary local files unless folders are restricted via an environment variable
  • Start with the --read-only flag until write access is actually needed

README in short

The Russian README, with an English version as a separate file, describes the server as fully async, with background uploads for large files and progress tracking. It gives a table of 22 tools by category: info and search, file operations, upload and download, publishing, trash. It details getting an OAuth token through your own application at oauth.yandex.ru with the needed scopes, installing via pip install yadisk-mcp or from source, wiring it into Claude Code and Claude Desktop, the --read-only mode with a list of blocked and available tools, and the upload-directory restriction variable. It has CI and a PyPI release.

FAQ

Can the agent be prevented from changing files?

Yes, the --read-only flag, the YADISK_MCP_READ_ONLY=true variable, or a configure(read_only=True) call block every write, publish and trash-clearing operation.

How do I restrict which local files can be uploaded?

With the YADISK_MCP_UPLOAD_ALLOWED_DIRS variable listing allowed folders; symlinks pointing outside them are blocked automatically.

Official

A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes

MCP serverMedium risk46.5KRepository stars
Editors’ pick

A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more

CLIHigh risk31.2KRepository stars
Editors’ pick

Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server

CLIMedium riskNo VPN needed30.1KRepository stars
Editors’ pick

A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI

MCP serverMedium risk28.1KRepository stars
Foxx AIyadisk-mcp

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.