Yandex MCP Workspace

Two Java servers for Yandex Tracker (84 tools) and Yandex Wiki (39), with an installer, OAuth device flow and a read-only mode

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • The 84 Tracker tools include deleting issues, comments, links and changing entity ACL permissions
  • Without explicitly enabling YANDEX_READ_ONLY the server writes by default
All reasons and checks
Russian stack

developerdevpav/yandex-mcp-workspace

Install

Manual install

curl -fsSL https://github.com/developerdevpav/yandex-mcp-workspace/releases/latest/download/install.sh | bash

For macOS and Linux, installs the chosen servers without sudo and walks through OAuth.

This is third-party code. Review the repository files before installing.

What it does

The project provides two independent MCP servers: yandex-mcp-tracker with 84 tools (references, issues, queues, comments, links, external applications, checklists, time tracking, plus projects, portfolios and goals through the Entities API) and yandex-mcp-wiki with 39 (pages, comments, attachments, dynamic tables). The install.sh script detects the OS and architecture, installs the needed servers without sudo, and walks through Yandex authorization in a browser. Authorization also works via OAuth device flow right from chat: an agent calls yandex_auth_start, shows the code, and yandex_auth_poll checks confirmation. The YANDEX_READ_ONLY=true variable unregisters every write tool, leaving only reads.

Who it is for. For teams that need the broadest possible Tracker and Wiki API coverage in one project, including projects, portfolios and OKRs.

Good fit when

  • You need both Tracker and Wiki in one project with a shared install method
  • You need projects, portfolios and OKR support through the Entities API
  • A ready read-only mode matters for a safe connection without write risk

Not a fit when

  • You want a lightweight server without Java, the installer needs JRE 21 or a separate JAR or Docker
  • Basic issue operations are enough, 84 tools would be excessive

Example request

Show this quarter's Tracker goals (OKRs) and their key results

Limitations

Requires JRE 21, or a separately downloaded archive bundling Java, or Docker. Authorization needs a separately registered OAuth app with a client_id and client_secret. Community project, with extensive documentation split across docs/, which makes a quick start without the installer harder.

How to disable. Remove the server blocks from your MCP client configs and delete ~/.config/yandex-mcp/config.properties along with the local token store.

MCP

Transport
stdio
Authentication
OAuth
Environment variables
Environment variables
YANDEX_ORG_ID
required
Organization identifier
YANDEX_ORG_TYPE
YANDEX_360 (default) or YANDEX_CLOUD
YANDEX_READ_ONLY
true unregisters all write tools

Security check

  • The 84 Tracker tools include deleting issues, comments, links and changing entity ACL permissions
  • Without explicitly enabling YANDEX_READ_ONLY the server writes by default

README in short

The Russian README describes one-command installation via install.sh, manual installation from separate archives or a JAR, OAuth app setup, a per-server tool table marked R (read) and W (write), the read-only mode, and links to detailed setup docs for Claude, ChatGPT Codex and Cursor.

FAQ

How do I enable read-only mode?

Set the YANDEX_READ_ONLY=true environment variable, then write tools are not registered in tools/list while read tools work without restriction.

Is the Yandex password entered anywhere besides Yandex's own site?

No, the README explicitly notes the account password is entered only on Yandex's own browser page, the installer never asks for it.

Editors’ pick

A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review

PluginMedium riskNo VPN needed292.5KRepository stars
Editors’ pick

Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture

SkillLow risk271.4KRepository stars
Editors’ pick

GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation

CLIMedium riskNo VPN needed139.3KRepository stars

Reference MCP servers

Model Context Protocol servers

Official

Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything

MCP serverMedium risk90.6KRepository stars
Foxx AIYandex MCP Workspace

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.