Kaiten connector for Cursor
Kaiten MCP Server — Cursor variant
A plugin and MCP connector for Kaiten built for Cursor: read boards and cards, create tasks and checklists, local stdio with no open ports
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Creates and updates cards and comments on a real board
- The remote mode, if misconfigured, can expose Kaiten access from outside
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add plugins/kaiten-mcp-server-cursor-variantDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run one by one in the Claude Code chat
/plugin marketplace add stillfrozen/kaiten-cursor-connector
/plugin install kaiten-connector@kaiten-pluginsClone the repository, run npm install && npm run build, get a token in Kaiten (Settings → API keys), and add the server to ~/.cursor/mcp.json with the command node dist/stdio-entry.js and the KAITEN_HOST, KAITEN_TOKEN variables.
Other ways from the author
cd kaiten-cursor-connector && npm install && npm run buildBuild from source, no ready package.
This is third-party code. Review the repository files before installing.
What it does
The package bundles a .claude-plugin with a kaiten-cursor-mcp skill and a matching Node.js MCP server. Read tools show boards, board structure, filtered cards (active only by default), a full card with description, comments and checklists, blockers, time logs, external links, sprints and backlog analytics. Write tools create a card, update its fields, add and edit comments, and create a checklist and its items. The recommended mode is local stdio: Cursor launches the built Node.js process and passes the token via environment variables in mcp.json, with no network port. There is also an optional remote mode with full OAuth 2.1, but the author explicitly advises against exposing it to the internet for team use.
Who it is for. For Cursor users on Kaiten who want a local connector with no network port and a ready skill guide.
Good fit when
- You work in Cursor and want to keep the Kaiten token only in mcp.json with no server
- You need backlog analytics and a default split between active and archived cards
- A ready skill with hints on conditions and token storage is useful
Not a fit when
- You need a server for Claude Code or another client: the README is Cursor-focused, though the MCP protocol itself is universal
- You need a shared team deployment: the author explicitly advises against the public remote mode for regular use
Example request
Show my Kaiten boards and backlog analytics for board 1390917Limitations
Requires building from source (npm install, npm run build), no npm package. It is a fork of an earlier Claude-oriented variant mentioned in the README without a link. Single author, no stars. The remote OAuth mode is harder to set up and not recommended by the author for regular use.
How to disable. Remove the kaiten entry from ~/.cursor/mcp.json and delete the skills/kaiten-cursor-mcp folder if the skill was installed.
Security check
- Creates and updates cards and comments on a real board
- The remote mode, if misconfigured, can expose Kaiten access from outside
README in short
The README recommends the local stdio mode as the main path for a Mac-based team and describes an optional remote Railway deployment with OAuth 2.1, PKCE, a preshared token and an owner password as a second factor. It lists read and write tools, the condition behavior for active versus archived cards, environment variables, and a detailed security section covering CSRF protection, constant-time comparisons and security headers.
SKILL.md
--- title: "Kaiten (Cursor MCP connector)" tags: - проект/workspace - подпроект/tools - тип/guide - область/tech --- # Kaiten (Cursor MCP connector) ## When to use this skill - Kaiten boards, cards, sprints, backlog, blockers, comments, acceptance criteria. - User asks to create, update, or read full content of a card. Prefer MCP tools when the kaiten server is connected. Do not curl the Kaiten API with KAITEN_TOKEN from the shell. ## Active vs archived (default: active) - condition: 1 — on the board (active). Default for list-cards, search-cards, get-sprint-cards. - condition: 2 — archived. Use only when the user asks for archive. - state (queued / inProgress / done) is separate from condition. ## API token Put KAITEN_HOST and KAITEN_TOKEN in ~/.cursor/mcp.json → mcpServers.kaiten.env. Never commit. Token needs write access for mutation tools.
FAQ
Does the local mode need an open port?
No, Cursor launches the process directly and talks to it over stdin/stdout, with no server or port.
Does it show archived cards?
Not by default, list tools use condition: 1 (active); pass condition: 2 explicitly for the archive.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI