Yandex MCP Workspace
Two Java servers for Yandex Tracker (84 tools) and Yandex Wiki (39), with an installer, OAuth device flow and a read-only mode
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- The 84 Tracker tools include deleting issues, comments, links and changing entity ACL permissions
- Without explicitly enabling YANDEX_READ_ONLY the server writes by default
Install
Manual install
curl -fsSL https://github.com/developerdevpav/yandex-mcp-workspace/releases/latest/download/install.sh | bashFor macOS and Linux, installs the chosen servers without sudo and walks through OAuth.
This is third-party code. Review the repository files before installing.
What it does
The project provides two independent MCP servers: yandex-mcp-tracker with 84 tools (references, issues, queues, comments, links, external applications, checklists, time tracking, plus projects, portfolios and goals through the Entities API) and yandex-mcp-wiki with 39 (pages, comments, attachments, dynamic tables). The install.sh script detects the OS and architecture, installs the needed servers without sudo, and walks through Yandex authorization in a browser. Authorization also works via OAuth device flow right from chat: an agent calls yandex_auth_start, shows the code, and yandex_auth_poll checks confirmation. The YANDEX_READ_ONLY=true variable unregisters every write tool, leaving only reads.
Who it is for. For teams that need the broadest possible Tracker and Wiki API coverage in one project, including projects, portfolios and OKRs.
Good fit when
- You need both Tracker and Wiki in one project with a shared install method
- You need projects, portfolios and OKR support through the Entities API
- A ready read-only mode matters for a safe connection without write risk
Not a fit when
- You want a lightweight server without Java, the installer needs JRE 21 or a separate JAR or Docker
- Basic issue operations are enough, 84 tools would be excessive
Example request
Show this quarter's Tracker goals (OKRs) and their key resultsLimitations
Requires JRE 21, or a separately downloaded archive bundling Java, or Docker. Authorization needs a separately registered OAuth app with a client_id and client_secret. Community project, with extensive documentation split across docs/, which makes a quick start without the installer harder.
How to disable. Remove the server blocks from your MCP client configs and delete ~/.config/yandex-mcp/config.properties along with the local token store.
MCP
- Transport
- stdio
- Authentication
- OAuth
| Environment variables | |
|---|---|
| YANDEX_ORG_ID required | Organization identifier |
| YANDEX_ORG_TYPE | YANDEX_360 (default) or YANDEX_CLOUD |
| YANDEX_READ_ONLY | true unregisters all write tools |
Security check
- The 84 Tracker tools include deleting issues, comments, links and changing entity ACL permissions
- Without explicitly enabling YANDEX_READ_ONLY the server writes by default
README in short
The Russian README describes one-command installation via install.sh, manual installation from separate archives or a JAR, OAuth app setup, a per-server tool table marked R (read) and W (write), the read-only mode, and links to detailed setup docs for Claude, ChatGPT Codex and Cursor.
FAQ
How do I enable read-only mode?
Set the YANDEX_READ_ONLY=true environment variable, then write tools are not registered in tools/list while read tools work without restriction.
Is the Yandex password entered anywhere besides Yandex's own site?
No, the README explicitly notes the account password is entered only on Yandex's own browser page, the installer never asks for it.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything