Asana
Search and work with tasks, projects, and portfolios available to the Asana account on the workspace's shared Connector.
Official endpoint: https://mcp.asana.com/v2/mcp
Product docs: Using Asana's MCP Server
Tool reference: MCP Tools Reference
This is an independently authored Agent Plugins 1.0 package. It does not copy an OpenAI .mcp.json, .app.json, or embedded client secret. plugin.json declares workspace Connector OAuth for the asana server. mcp.json uses portable streamable-http. See upstream notes.
Installing the package does not authorize Asana. A workspace administrator authorizes one shared Connector connection; other members use that shared identity and should contact an administrator if it is missing. Tool calls run as the authorizing account, not as each chat user.
Do not configure https://mcp.asana.com/sse. Asana documents that beta URL as deprecated.
Connector setup
Checked on 2026-10-10, without a user token:
- Unauthenticated
initializereturned 401.WWW-Authenticatenamed protected-resource metadatahttps://mcp.asana.com/.well-known/oauth-protected-resource/v2. - That document's
resourceishttps://mcp.asana.com/v2/mcp, which matches the MCP URL. Its authorization server ishttps://app.asana.com.scopes_supportedisdefault. - Authorization-server metadata at
https://app.asana.com/.well-known/oauth-authorization-servernames issuerhttps://app.asana.com, authorizehttps://app.asana.com/-/oauth_authorize, and tokenhttps://app.asana.com/-/oauth_token. PKCES256is advertised. There is noregistration_endpoint. Token endpoint auth methods areclient_secret_postandclient_secret_basiconly. - Minimum OAuth scope:
default. That is the only scope advertised by the v2 protected-resource metadata. Asana's tool reference says MCP apps do not use a finer permission-scope list and that authorization follows the authorizing account's existing access. - A different document at
https://mcp.asana.com/.well-known/oauth-protected-resourcenamesresourcehttps://mcp.asana.comand authorization serverhttps://mcp.asana.com, which does advertise dynamic registration. That resource does not match the v2 MCP URL. Do not substitute it.
A workspace administrator must register an Asana app and enter its client id and client secret in the Connector form. Do not commit those values. The redirect URI must be the Xpert Connector callback. This package does not invent that URI. Write tools require an explicit user request and host approval.
Icon
The icon is the public PNG https://d3ki9tyy5l5ruj.cloudfront.net/obj/df5bcec7e9873dddebdd1328901c287f0f069750/asana-logo-favicon@3x.png, linked from Asana's own favicon host. The inspected Codex tree has no Asana package, so no Codex asset is bundled.
Skill
asana-workspace names tools from Asana's V2 tools reference. Live schemas win. An authenticated tools/list was not available while writing this package.
Usability test
Without a registered Asana OAuth app and a user authorization, tool calls against a real workspace cannot be verified. Do not write a client id, client secret, or token into the repository or the chat.
- Pack:
corepack pnpm quickstart --pack --output-dir /tmp/xpert-agent-plugins asana - Publish the ZIP, or install with platform parameters already configured:
corepack pnpm quickstart --install --platform-root "$XPERT_PLATFORM_ROOT" --api-url "$XPERT_API_URL" --org-id "$XPERT_ORG_ID" --workspace-id "$XPERT_WORKSPACE_ID" asana - An administrator registers an Asana app, puts the client id and client secret in the Connector form, and uses the callback URL shown on the form. Request the discovered scope
default. Do not point the server URL athttps://mcp.asana.com/sse. - A workspace administrator authorizes one shared Connector connection from workspace Connector settings and selects the Asana workspace the provider asks for. Other members use that shared identity and should contact an administrator if it is missing.
- After authorization, ask for the live tool names. Use only names present in that schema.
- Read-only smoke: ask for
get_mewhen that tool is listed, then ask for the authorizing account's incomplete tasks. Do not create, update, or delete tasks. - Skill smoke: ask to summarize tasks due this week in a project the authorizing account can already open. If tools are unavailable, an administrator authorizes the shared Connector; other members contact an administrator.
- Without credentials, or without an explicit user request and host approval, do not verify
create_tasks,update_tasks,delete_task,add_comment, orcreate_project.
Verification
Checked on 2026-10-10. corepack pnpm test in agent-plugins covers the manifest, Connector declaration, and ZIP allowlist. Live Asana consent was not run. On 2026-10-10, corepack pnpm test:lifecycle --platform-root "$XPERT_PLATFORM_ROOT" passed with XPERT_PLATFORM_ROOT set to the host checkout containing packages/server-ai/src/agent-plugin/agent-plugin-parser.ts (Node v22.14.0, pnpm 10.24.0). This package's result was PASS asana: distributed ZIP, production parser, digest, Skills and MCP binding.