Skip to content

rosscrispin/producer-dashboard

v1.1.15MIT

Connect The Library to Codex and ChatGPT for authorized music library workflows.

The Library Plugin for Codex, ChatGPT, and Claude Code

Use your The Library account to find tracks and manage authorized music workflows in Codex, ChatGPT, or Claude Code.

The plugin is published by Producer Dashboard Corp, a Delaware company. Its composer icon and listing logo use the existing The Library app icon, bundled at assets/app-icon.png from the app's build/icon-source.png.

Codex local install

Add this repository as a marketplace, then install the plugin:

codex plugin marketplace add rosscrispin/producer-dashboard-mcp-plugin
codex plugin add producer-dashboard@glimbr

The Codex package uses plugin.json and mcp.json. Sign in to the remote MCP server when Codex asks. For a read-only test, run codex mcp login the-library --scopes library.read and approve that scope in The Library.

Claude Code install

Run these two commands inside Claude Code:

/plugin marketplace add rosscrispin/producer-dashboard-mcp-plugin
/plugin install producer-dashboard@glimbr

On first use, Claude Code will open your browser to sign in with your The Library account.

What you can ask

  • "How many songs do I have in each stage?"
  • "Show me comments on my finished tracks from last week"
  • "Find tracks with no open to-dos"
  • "Show tracks with no comments in the past three days"
  • "Add Joshua as a collaborator on all my tree-stage songs with 50/50 splits"
  • "Create a share page for everything in my Releases bucket"
  • "What songs need mixing? Set their due date to end of month"
  • "Tag all songs in test 4 as Cinematic"

The server exposes 498 tools across tracks, private playlists, Buckets, Bucket properties, shared Bucket members, collaborators, sharing, Friend Track Offers, comments, To-Dos, search, and royalty earnings. Recipient, shared-Bucket member, Bucket property and full collaborator tools prepare exact plans for trusted app review. Named collaborator and publisher name/notes actions use the original songs.write grant and an exact direct execution contract. Playlist writes use prepare -> execute -> status under the authorized OAuth grant and do not require an extra app review; legacy playlist plans without the server-owned direct marker retain their approval flow. Inbox and Outbox readers keep direct assignments and Bucket paths separate. Direct invitation acceptance, decline, leave, resend and revoke use exact assignment and Track revisions. Recipient Connect grants a fixed browser-authorized context for safe reads, media handoffs and approval decisions. Offer bounce feedback uses an exact durable comment receipt. Connected app file actions use fresh device and session consent, signed commands and the existing file service. Native selectors use the trusted app chooser and return signed path-free opaque handles. Native device and pairing reads expose the server-owned client_instance_id, root_id, root_generation, session_id, and session_version binding tuple. Keep those values unchanged for follow-up actions. A missing field is unavailable, and a null client instance is an explicit unbound state that cannot authorize a paired action; never invent or reuse a binding. Versioned Track tools clear due dates, edit lyrics and notes, and add, remove or replace Bucket memberships. Single metadata writes use exact direct grant execution. Membership changes and the closed eight-field bulk metadata patch require their trusted review and current revisions. Partial results and pending delivery remain explicit. The published OAuth set contains 42 scopes. Existing grants do not expand. File preparation, inventory, import, metadata, backup, local playback and full Track Join require a current paired desktop capability. Public-share playback uses its separate recipient authority. Public Pages, definitions, automation, financial reads and account/provider handoffs retain their exact action contracts. Source tests, deployed services and installed-account acceptance are separate release evidence.

Package validation

Run the dependency-free package check before creating a ZIP or uploading a new version:

node scripts/validate-plugin.mjs

It checks the listing, review cases, icons, product wording, and the documented 498-tool reference.

Permissions

Toggle these in The Library → Settings → AI Agent Access:

PermissionDefaultNeeded for
Read libraryONBrowsing songs, tags, comments
Edit songsONUpdating metadata, stages, workflows
Comments & todosONCreating and editing comments and todos
Read collaboratorsONViewing collaborator info
SharingOFFCreating share pages, sharing with collaborators
Bulk operationsOFFBatch updating multiple songs
Destructive operationsOFFDeleting buckets, tags, collaborators
Read sharingOFFNew share status and public link readers; sharing.read consent
Manage bucketsOFFCreating and organizing Bucket hierarchy; projects.write consent
Manage Public Page visibilityOFFAdding or removing owned Buckets from the canonical Public Page collection; public_pages.write consent
Organize libraryOFFCreating and changing private playlists; organization.write consent
Edit collaboratorsOFFFriend designation; collaborators.write consent
Read rightsOFFOffer, bounce and feedback reads; rights.read consent
Manage rightsOFFOffer lifecycle; rights.write consent

Fresh consent is required for each new scope. Chat confirmation cannot approve a recipient or shared-Bucket member action. Review the exact server plan in the trusted app. Public links, direct collaborator delivery, shared-Bucket membership, credits, Friends and Offers remain separate actions. Revoking access, changing a Bucket role, or leaving a Bucket also requires destructive operations authority. The MCP reports remote child-share delivery separately from local file import and preserves independent access paths.

Private playlist creation also requires the Sharing permission and sharing.write consent because it publishes an unlisted stream-only live URL. Other private playlist edits use the Organize library permission unless linked-share effects require sharing authority. Prepare each exact playlist action, execute it with the returned plan ID and original idempotency UUID, then read operation status. Client confirmation policies remain client-controlled.

Requirements

  • Codex, ChatGPT, or Claude Code
  • The Library account
  • Application file-delivery and permission prerequisites for the chosen sharing action