Yandex Tracker MCP with its own OAuth provider
yandex-tracker-mcp
A Python Tracker MCP server with a built-in OAuth Authorization Server for per-user authorization
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Without TRACKER_READ_ONLY it changes real Tracker issues on behalf of the authorized user
- Its own OAuth provider stores and encrypts user tokens on the server
- No README, which makes config review harder before production use
Install
Manual install
pip install -e .Install from a repo clone via pyproject.toml; you then need a .env based on deploy/dev.env.
This is third-party code. Review the repository files before installing.
What it does
The Python server implements Tracker issues, queues and users, and adds its own OAuth Authorization Server on top of the MCP SDK: each user authorizes through Yandex separately, and the server exchanges the code for a token on its own side without passing the token straight to the agent, with encryption and an in-memory store. It has a separate TRACKER_READ_ONLY mode that is on by default in the dev deployment config, plus ready-made configs for three environments via separate env files and Docker Compose for deployment.
Who it is for. For teams that need a shared Tracker MCP server for several users with separate authorization for each, rather than one shared token.
Good fit when
- The server needs to serve several employees, each with their own Tracker permissions
- You need a ready read-only mode for a dev environment with no risk to live issues
- You need Streamable HTTP transport with built-in OAuth instead of manually distributing tokens
Not a fit when
- You only need a personal single-user server: a full OAuth provider is overkill
- The repo has no README, and you do not want to work out the config from source and .env examples
Example request
Show my open issues in the SUPPORT queue without changing anythingLimitations
The repository has no README: capabilities and setup were reconstructed from pyproject.toml, the CLI entry point and the deploy/*.env examples. The default OAuth store is in-memory; production needs separate configuration. TRACKER_READ_ONLY should be explicitly checked in your environment; it is on by default in the dev config.
How to disable. Stop the container with docker compose down in the deploy directory, or remove the server from your MCP client config.
MCP
- Transport
- http
- Authentication
- OAuth
| Environment variables | |
|---|---|
| TRANSPORT required | Transport type, streamable-http in the example |
| OAUTH_ENABLED required | Enables the built-in OAuth Authorization Server |
| MCP_SERVER_PUBLIC_URL required | The server's public address for OAuth redirects |
| TRACKER_READ_ONLY | true blocks write calls; on by default in the dev config |
Security check
- Without TRACKER_READ_ONLY it changes real Tracker issues on behalf of the authorized user
- Its own OAuth provider stores and encrypts user tokens on the server
- No README, which makes config review harder before production use
README in short
The repository has no README. It builds via pyproject.toml with the yandex-tracker-mcp = mcp_tracker.__main__:main entry point, dependencies include aiohttp, cryptography and mcp[cli], and configuration is set via three example env files for dev, stage and prod with transport, OAuth and read-only mode settings.
FAQ
Why is there no README?
The repository has no README file; install and config were reconstructed from pyproject.toml, the CLI entry point and the deploy/*.env examples.
Can the server be limited to read-only?
Yes, TRACKER_READ_ONLY=true in dev.env blocks write calls; other environments need it set explicitly.
Related
An MCP server with n8n node and template knowledge: the agent picks nodes, validates configs and, with API access, creates workflows in your n8n
Zapier's official MCP plugin: the agent gets actions across thousands of apps through your Zapier account
Awesome Claude Skills by Composio
Awesome Claude Skills
A curated list of Claude skills and plugins, plus Composio's own automation skills for 78 SaaS apps
A plugin and CLI catalog for agents: generates command-line interfaces for GUI apps like GIMP and Blender and installs ready ones via CLI-Hub