Integrations
LiveTaskcenter MCP
Connect an external agent to governed Taskcenter tools
Overview
Taskcenter provides a live remote MCP endpoint at https://taskcenter.co/api/mcp. It exposes registered runtime tools through the same RBAC, guarded D1, audit, and capability rules as the product. MCP is the supported agent integration surface; it does not grant blanket database access.
Prepare access
Create an API token with mcp:execute and only the additional scopes required by the tools the client will call. The MCP-only preset adds agents:read. Tool-specific permission checks still run after MCP admission, so mcp:execute by itself does not authorize issue writes, project reads, runs, or artifacts.
Connect Codex
The repository helper registers the remote endpoint, stores the token in the named environment variable for new Codex sessions on macOS, and sends a JSON-RPC initialize request. It is intended for operators with a Taskcenter source checkout. Other MCP clients should configure the same URL and bearer token directly.
export TASKCENTER_MCP_TOKEN="tc_..."./scripts/setup-taskcenter-mcp.shcodex mcp add taskcenter \ --url https://taskcenter.co/api/mcp \ --bearer-token-env-var TASKCENTER_MCP_TOKENExecution contract
Status
Live.
Entry route
POST /api/mcp.
Required permissions
mcp:execute at transport admission plus the permission declared by the selected registered tool. Arguments are capped at 128,000 bytes and stored outputs at 192,000 bytes. Every call receives a durable tool-call id when D1 is available and returns the standard Taskcenter tool envelope.
Skill guidance
The repository includes .agents/skills/taskcenter-api/SKILL.md for agents working inside a Taskcenter checkout. It documents the safe project-loop workflow, idempotency, polling, and failure shapes. It is canonical internal guidance, not yet a separately versioned public skill package. External agents can operate Taskcenter today through MCP without installing that skill.
Failure state
An invalid or missing token is denied before tool execution. A missing tool name returns 400. An unavailable binding or tool runtime returns an explicit blocker; clients must not interpret it as successful work. Tool execution is audited, and RBAC failures return 403.