monday.com
Search and work with boards, items, and docs available to the monday.com account on the workspace's shared Connector.
Official endpoint: https://mcp.monday.com/mcp
Product docs: Platform MCP overview
Tool reference: Platform MCP tools
This is an independently authored Agent Plugins 1.0 package. It does not copy an OpenAI .mcp.json, .app.json, or embedded client secret. plugin.json declares workspace Connector OAuth for the monday server. mcp.json uses portable streamable-http. See upstream notes.
Installing the package does not authorize monday.com. A workspace administrator authorizes one shared Connector connection; other members use that shared identity and should contact an administrator if it is missing. Tool calls run as the authorizing account, not as each chat user.
monday.com documents Streamable HTTP only. Do not configure https://mcp.monday.com/sse.
Connector setup
Checked on 2026-10-10, without a user token:
- Unauthenticated
initializereturned 401.WWW-Authenticatenamed protected-resource metadatahttps://mcp.monday.com/.well-known/oauth-protected-resource/mcp. - That document's
resourceishttps://mcp.monday.com/mcp, which matches the MCP URL. Its authorization server ishttps://auth.monday.com/mcp. It has noscopes_supported. - Authorization-server metadata at
https://auth.monday.com/.well-known/oauth-authorization-server/mcpnames issuerhttps://auth.monday.com/mcp, authorizehttps://auth.monday.com/oauth2/authorize, tokenhttps://auth.monday.com/oauth_ms/oauth/token, and registrationhttps://auth.monday.com/oauth_ms/oauth/register. PKCES256is advertised. Token endpoint auth methods areclient_secret_postandclient_secret_basiconly. That document has noscopes_supported. - Minimum OAuth scope: TBD. Protected-resource metadata did not advertise scopes. The issuer
https://auth.monday.com(without/mcp) publishes a different scope list. Do not treat that list as this resource's required scopes. - Dynamic registration is advertised, but the token endpoint does not advertise public-client
none. A returned confidential client still needs its secret in the Connector form.
The redirect URI must be the Xpert Connector callback. This package does not invent that URI. Write tools require an explicit user request and host approval.
Icon
The icon is the public PNG https://cdn.monday.com/images/logos/monday_logo_icon.png. The Codex monday-com manifest at commit 1dc195897af4161d039b80d8471ec0a10c9bbc89 does not declare a license, so its brand files are not copied.
Skill
monday-workspace names a subset of tools from monday.com's Platform MCP tools page. Live schemas win. An authenticated tools/list was not available while writing this package.
Usability test
Without a monday.com OAuth client and a user authorization, tool calls against a real account cannot be verified. Do not write a client id, client secret, or token into the repository or the chat.
- Pack:
corepack pnpm quickstart --pack --output-dir /tmp/xpert-agent-plugins monday - Publish the ZIP, or install with platform parameters already configured:
corepack pnpm quickstart --install --platform-root "$XPERT_PLATFORM_ROOT" --api-url "$XPERT_API_URL" --org-id "$XPERT_ORG_ID" --workspace-id "$XPERT_WORKSPACE_ID" monday - An administrator creates a monday.com OAuth app with the new OAuth flow enabled, enters the client id and client secret in the Connector form, and uses the callback URL shown on the form. Choose the smallest scopes that app actually needs. This package cannot name that set from protected-resource metadata.
- A workspace administrator authorizes one shared Connector connection from workspace Connector settings. Other members use that shared identity and should contact an administrator if it is missing. Do not use the deprecated SSE URL.
- After authorization, ask for the live tool names. Use only names present in that schema.
- Read-only smoke: when listed, call
get_user_context, thensearchorget_board_infofor a board the tester can already open. Do not create items, change columns, or run a GraphQL mutation. - Skill smoke: ask to summarize items on a board the tester names. If tools are unavailable, an administrator authorizes the shared Connector; other members contact an administrator.
- Without credentials, or without an explicit user request and host approval, do not verify writes. That includes create and update tools, and also move, delete, automation, publish, and agent-management tools, plus
all_monday_apimutations.
Verification
Checked on 2026-10-10. corepack pnpm test in agent-plugins covers the manifest, Connector declaration, and ZIP allowlist. Live monday.com consent was not run. On 2026-10-10, corepack pnpm test:lifecycle --platform-root "$XPERT_PLATFORM_ROOT" passed with XPERT_PLATFORM_ROOT set to the host checkout containing packages/server-ai/src/agent-plugin/agent-plugin-parser.ts (Node v22.14.0, pnpm 10.24.0). This package's result was PASS monday: distributed ZIP, production parser, digest, Skills and MCP binding.