Taskcenter DocsOpen app

Integrations

Live

Taskcenter MCP

Connect an external agent to governed Taskcenter tools

Overview

Taskcenter provides a live remote MCP endpoint at https://taskcenter.co/api/mcp. It exposes registered runtime tools through the same RBAC, guarded D1, audit, and capability rules as the product. MCP is the supported agent integration surface; it does not grant blanket database access.

01

Prepare access

Create an API token with mcp:execute and only the additional scopes required by the tools the client will call. The MCP-only preset adds agents:read. Tool-specific permission checks still run after MCP admission, so mcp:execute by itself does not authorize issue writes, project reads, runs, or artifacts.

02

Connect Codex

The repository helper registers the remote endpoint, stores the token in the named environment variable for new Codex sessions on macOS, and sends a JSON-RPC initialize request. It is intended for operators with a Taskcenter source checkout. Other MCP clients should configure the same URL and bearer token directly.

bash
export TASKCENTER_MCP_TOKEN="tc_..."./scripts/setup-taskcenter-mcp.sh
bash
codex mcp add taskcenter \  --url https://taskcenter.co/api/mcp \  --bearer-token-env-var TASKCENTER_MCP_TOKEN
03

Execution contract

Status

Live.

Entry route

POST /api/mcp.

Required permissions

mcp:execute at transport admission plus the permission declared by the selected registered tool. Arguments are capped at 128,000 bytes and stored outputs at 192,000 bytes. Every call receives a durable tool-call id when D1 is available and returns the standard Taskcenter tool envelope.

04

Skill guidance

The repository includes .agents/skills/taskcenter-api/SKILL.md for agents working inside a Taskcenter checkout. It documents the safe project-loop workflow, idempotency, polling, and failure shapes. It is canonical internal guidance, not yet a separately versioned public skill package. External agents can operate Taskcenter today through MCP without installing that skill.

05

Failure state

An invalid or missing token is denied before tool execution. A missing tool name returns 400. An unavailable binding or tool runtime returns an explicit blocker; clients must not interpret it as successful work. Tool execution is audited, and RBAC failures return 403.