YouGile MCP with security policies

YouGile MCP

A YouGile MCP server with access profiles, read-only by default, OpenAPI payload validation, audit logging, and secrets in Vault or protected files

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • The write profile can create and change tasks, chats, projects and boards
  • Optional webhooks accept external requests, though protected by secrets and replay guards
All reasons and checks
Russian stack

cvtmysxul/yougile-mcp

Install

Manual install

sh scripts/bootstrap.sh

Automatically downloads the needed Node.js and pnpm versions with no admin rights and starts the setup assistant.

This is third-party code. Review the repository files before installing.

What it does

The server offers a named, policy-controlled toolset for YouGile instead of a generic HTTP proxy to the API. It supports local stdio and a bearer-protected Streamable HTTP transport, with separate profiles, scopes, policies, caches, rate limits and audit records per tenant. Access is read-only by default; writes to tasks, chats, projects and boards need a separate profile that must be named explicitly. Secrets live in environment variables, protected files or HashiCorp Vault and are never accepted through MCP tools. Mutating requests are validated against the OpenAPI schema, with response-size limits, sensitive-data redaction and untrusted-content marking. Optional inbound webhooks use tenant-bound secrets with replay protection, and file uploads are checked against a path allowlist, size, MIME type and file signature. A local browser setup assistant helps get an organization id and create an API key through YouGile's official methods with no manual config editing.

Who it is for. For YouGile teams who care about integration security: separating read and write rights, audit logging, and secrets kept out of config files.

Good fit when

  • You want the agent to be read-only by default with no ability to change YouGile data
  • You want per-tenant audit logging and rate limits
  • You want mutating requests validated against the OpenAPI schema before they reach YouGile

Not a fit when

  • You want the simplest possible proxy with no policies or profiles: this one deliberately adds more configuration for security
  • You lack Node.js 20 and pnpm 11, or do not want to use the bootstrap script

Example request

Show my open YouGile tasks on the development board

Limitations

The project is unofficial and not affiliated with YouGile. A full manual install needs Node.js 20+ and pnpm 11, or you can use the bootstrap script, which downloads the right versions itself from nodejs.org and registry.npmjs.org. The API key cannot be passed via YAML, command-line arguments or prompts, only through a secret provider. Writes are available only through a separate, explicitly named profile.

How to disable. Remove the yougile block from your MCP client config and stop the server process.

MCP

Transport
stdio, http
Authentication
API key
Environment variables
Environment variables
YOUGILE_ACME_API_KEY
required, secret
YouGile API key for the read-only profile
YOUGILE_ACME_WRITER_API_KEY
secret
API key for the write-enabled profile

Security check

  • The write profile can create and change tasks, chats, projects and boards
  • Optional webhooks accept external requests, though protected by secrets and replay guards

README in short

The English and Russian README presents the project as an unofficial, security-focused MCP server for YouGile with a named toolset instead of a generic proxy. It lists key features: separate per-tenant profiles and limits, read-only by default, secrets kept out of MCP tools, OpenAPI validation, replay-protected webhooks, upload checks. It covers requirements, a bootstrap script for install with no admin rights, a quick start with environment variables, desktop client configuration, and a local browser setup assistant.

FAQ

Can the agent change tasks right away?

No, access is read-only by default; writes require a separate, explicitly named profile.

Where is the API key stored?

In environment variables, protected files or HashiCorp Vault, but never in the YAML config or through MCP tools.

Official

Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent

MCP serverHigh risk483Repository stars
Official

Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex

PluginHigh riskRussian stackNo VPN needed28Repository stars
Editors’ pick

Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit

MCP serverHigh riskRussian stackNo VPN needed

Bitrix24 portal MCP server

MCP-сервер портала Битрикс24

Official

Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail

MCP serverHigh riskRussian stackNo VPN needed
Foxx AIYouGile MCP with security policies

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.