YouGile MCP with security policies
YouGile MCP
A YouGile MCP server with access profiles, read-only by default, OpenAPI payload validation, audit logging, and secrets in Vault or protected files
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- The write profile can create and change tasks, chats, projects and boards
- Optional webhooks accept external requests, though protected by secrets and replay guards
Install
Manual install
sh scripts/bootstrap.shAutomatically downloads the needed Node.js and pnpm versions with no admin rights and starts the setup assistant.
This is third-party code. Review the repository files before installing.
What it does
The server offers a named, policy-controlled toolset for YouGile instead of a generic HTTP proxy to the API. It supports local stdio and a bearer-protected Streamable HTTP transport, with separate profiles, scopes, policies, caches, rate limits and audit records per tenant. Access is read-only by default; writes to tasks, chats, projects and boards need a separate profile that must be named explicitly. Secrets live in environment variables, protected files or HashiCorp Vault and are never accepted through MCP tools. Mutating requests are validated against the OpenAPI schema, with response-size limits, sensitive-data redaction and untrusted-content marking. Optional inbound webhooks use tenant-bound secrets with replay protection, and file uploads are checked against a path allowlist, size, MIME type and file signature. A local browser setup assistant helps get an organization id and create an API key through YouGile's official methods with no manual config editing.
Who it is for. For YouGile teams who care about integration security: separating read and write rights, audit logging, and secrets kept out of config files.
Good fit when
- You want the agent to be read-only by default with no ability to change YouGile data
- You want per-tenant audit logging and rate limits
- You want mutating requests validated against the OpenAPI schema before they reach YouGile
Not a fit when
- You want the simplest possible proxy with no policies or profiles: this one deliberately adds more configuration for security
- You lack Node.js 20 and pnpm 11, or do not want to use the bootstrap script
Example request
Show my open YouGile tasks on the development boardLimitations
The project is unofficial and not affiliated with YouGile. A full manual install needs Node.js 20+ and pnpm 11, or you can use the bootstrap script, which downloads the right versions itself from nodejs.org and registry.npmjs.org. The API key cannot be passed via YAML, command-line arguments or prompts, only through a secret provider. Writes are available only through a separate, explicitly named profile.
How to disable. Remove the yougile block from your MCP client config and stop the server process.
MCP
- Transport
- stdio, http
- Authentication
- API key
| Environment variables | |
|---|---|
| YOUGILE_ACME_API_KEY required, secret | YouGile API key for the read-only profile |
| YOUGILE_ACME_WRITER_API_KEY secret | API key for the write-enabled profile |
Security check
- The write profile can create and change tasks, chats, projects and boards
- Optional webhooks accept external requests, though protected by secrets and replay guards
README in short
The English and Russian README presents the project as an unofficial, security-focused MCP server for YouGile with a named toolset instead of a generic proxy. It lists key features: separate per-tenant profiles and limits, read-only by default, secrets kept out of MCP tools, OpenAPI validation, replay-protected webhooks, upload checks. It covers requirements, a bootstrap script for install with no admin rights, a quick start with environment variables, desktop client configuration, and a local browser setup assistant.
FAQ
Can the agent change tasks right away?
No, access is read-only by default; writes require a separate, explicitly named profile.
Where is the API key stored?
In environment variables, protected files or HashiCorp Vault, but never in the YAML config or through MCP tools.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail