ClickUp
Search and work with tasks, docs, and the workspace hierarchy available to the ClickUp account on the workspace's shared Connector.
Official endpoint: https://mcp.clickup.com/mcp
Product docs: ClickUp's MCP Server
Tool page: Supported tools
This is an independently authored Agent Plugins 1.0 package. It does not copy an OpenAI .mcp.json, .app.json, or embedded client secret. plugin.json declares workspace Connector OAuth for the clickup server. mcp.json uses portable streamable-http. See upstream notes.
Installing the package does not authorize ClickUp. A workspace administrator authorizes one shared Connector connection; other members use that shared identity and should contact an administrator if it is missing. Tool calls run as the authorizing account, not as each chat user.
ClickUp documents OAuth for this server. This package does not use an API key or personal token.
Connector setup
Checked on 2026-10-10, without a user token:
- Unauthenticated
initializereturned 401.WWW-Authenticatenamed protected-resource metadatahttps://mcp.clickup.com/.well-known/oauth-protected-resource/mcp. - That document's
resourceishttps://mcp.clickup.com/mcp, which matches the MCP URL. Its authorization server ishttps://mcp.clickup.com.scopes_supportedisreadandwrite. - Authorization-server metadata at
https://mcp.clickup.com/.well-known/oauth-authorization-servernames issuerhttps://mcp.clickup.com, authorizehttps://mcp.clickup.com/oauth/authorize, tokenhttps://mcp.clickup.com/oauth/token, and registrationhttps://mcp.clickup.com/oauth/register. PKCES256is advertised. The only token endpoint auth method isnone.grant_types_supportedlistsauthorization_codeand does not listrefresh_token. - Minimum OAuth scope:
readandwrite. Those are the scopes advertised by the protected-resource metadata and the authorization-server metadata. The documents do not name a smaller required subset. Do not add scopes outside that list. - Write tools require an explicit user request and host approval even when the
writescope is granted.
The redirect URI must be the Xpert Connector callback. This package does not invent that URI. Live refresh behavior was not verified.
Icon
assets/composer-icon.png is the MIT-licensed Codex composer icon. See assets/README.md.
Skill
clickup-workspace follows ClickUp's public tools page. That page uses display labels and does not publish machine tool names. Live schemas win. An authenticated tools/list was not available while writing this package.
Usability test
Without a completed ClickUp OAuth grant, tool calls against a real Workspace cannot be verified. Do not write a client id, client secret, or token into the repository or the chat.
- Pack:
corepack pnpm quickstart --pack --output-dir /tmp/xpert-agent-plugins clickup - Publish the ZIP, or install with platform parameters already configured:
corepack pnpm quickstart --install --platform-root "$XPERT_PLATFORM_ROOT" --api-url "$XPERT_API_URL" --org-id "$XPERT_ORG_ID" --workspace-id "$XPERT_WORKSPACE_ID" clickup - An administrator completes Connector OAuth with the callback URL shown on the form. Request the discovered scopes
readandwrite. Leave any client secret in the Connector form. - A workspace administrator authorizes one shared Connector connection from workspace Connector settings. Other members use that shared identity and should contact an administrator if it is missing.
- After authorization, ask for the live tool names. Use only names present in that schema. Do not turn a display label such as "Get Task" into a guessed identifier.
- Read-only smoke: ask to search or read a task the authorizing account can already open. Do not create, update, delete, comment, chat, or track time.
- Skill smoke: ask to summarize open work in a List the tester names. If tools are unavailable, an administrator authorizes the shared Connector; other members contact an administrator.
- Without credentials, or without an explicit user request and host approval, do not verify task creation, comments, chat messages, or time entries.
Verification
Checked on 2026-10-10. corepack pnpm test in agent-plugins covers the manifest, Connector declaration, and ZIP allowlist. Live ClickUp consent was not run. On 2026-10-10, corepack pnpm test:lifecycle --platform-root "$XPERT_PLATFORM_ROOT" passed with XPERT_PLATFORM_ROOT set to the host checkout containing packages/server-ai/src/agent-plugin/agent-plugin-parser.ts (Node v22.14.0, pnpm 10.24.0). This package's result was PASS clickup: distributed ZIP, production parser, digest, Skills and MCP binding.