yadisk-mcp
A Yandex Disk MCP server with 22 tools covering files, public links and trash, background uploads for large files, and a read-only mode
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- By default it can delete, move and publish files on Yandex Disk
- It can upload arbitrary local files unless folders are restricted via an environment variable
- Start with the --read-only flag until write access is actually needed
Install
Manual install
pip install yadisk-mcpInstall the package from PyPI.
This is third-party code. Review the repository files before installing.
What it does
The server covers the Yandex Disk API asynchronously with 22 tools: quota and disk info, listing and searching files, creating, copying, moving, renaming and deleting, uploading a local file (synchronously up to about 100 MB, or in the background with a job_id and progress tracking for larger ones), uploading from a URL, publishing files with a link and unpublishing, and trash operations. A --read-only flag, environment variable or programmatic setting blocks every write operation and leaves only browsing. A separate variable restricts which local folders uploads may read from and blocks symlinks that point outside them.
Who it is for. For people who want full Yandex Disk management through an agent, from uploading large files to publishing links.
Good fit when
- You need to upload large files in the background with progress tracking
- You want to publish a file and get a public link right from a conversation with an agent
- You need a safe read-only mode for demos or browsing someone else's disk
Not a fit when
- You want a minimal server with no write operations at all: writes are on by default here, read-only mode must be turned on separately
- You do not want to issue a token with write access to the whole disk
Example request
Find all PDF files on Yandex Disk from the last month and publish the most recent oneLimitations
It needs a Yandex OAuth token with cloud_api:disk.read, disk.write, disk.app_folder and disk.info scopes, obtained through your own application at oauth.yandex.ru. The token is valid for a year and needs manual renewal. By default upload_local_file can read any local file unless YADISK_MCP_UPLOAD_ALLOWED_DIRS is set. Emptying the trash is irreversible.
How to disable. Remove the server with claude mcp remove yadisk or manually from your client config, and revoke the OAuth token at oauth.yandex.ru.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| YANDEX_DISK_TOKEN required, secret | Yandex OAuth token with cloud_api:disk.read, disk.write, disk.app_folder, disk.info scopes |
| YADISK_MCP_READ_ONLY | Enables read-only mode and blocks every write tool |
| YADISK_MCP_UPLOAD_ALLOWED_DIRS | List of local folders that uploads to the disk are allowed to read from |
Security check
- By default it can delete, move and publish files on Yandex Disk
- It can upload arbitrary local files unless folders are restricted via an environment variable
- Start with the --read-only flag until write access is actually needed
README in short
The Russian README, with an English version as a separate file, describes the server as fully async, with background uploads for large files and progress tracking. It gives a table of 22 tools by category: info and search, file operations, upload and download, publishing, trash. It details getting an OAuth token through your own application at oauth.yandex.ru with the needed scopes, installing via pip install yadisk-mcp or from source, wiring it into Claude Code and Claude Desktop, the --read-only mode with a list of blocked and available tools, and the upload-directory restriction variable. It has CI and a PyPI release.
FAQ
Can the agent be prevented from changing files?
Yes, the --read-only flag, the YADISK_MCP_READ_ONLY=true variable, or a configure(read_only=True) call block every write, publish and trash-clearing operation.
How do I restrict which local files can be uploaded?
With the YADISK_MCP_UPLOAD_ALLOWED_DIRS variable listing allowed folders; symlinks pointing outside them are blocked automatically.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI