Vikunja MCP Cloudflare Access
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Vikunja MCP Cloudflare Accesslist my projects"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Vikunja MCP behind Cloudflare Access
A small, self-hosted Streamable HTTP MCP server that turns a narrow Vikunja REST API surface into tools for ChatGPT and other remote MCP clients. It is designed for an existing Cloudflare Tunnel and Cloudflare Access Managed OAuth deployment.
It exposes project and task reads, implements a tightly gated write path, and keeps the Vikunja API token on the server.
AI system overview
flowchart LR
Client["ChatGPT or another remote MCP client"]
Access["Cloudflare Access<br/>Managed OAuth and policy"]
Tunnel["Cloudflare Tunnel"]
JWKS["Cloudflare Access JWKS"]
subgraph Origin["Private origin"]
Adapter["Vikunja MCP adapter<br/>Streamable HTTP at /mcp"]
Guard["Origin guard<br/>signature, issuer, audience, email"]
Tools["Narrow MCP tools<br/>writes off by default"]
ClientLib["Vikunja client abstraction<br/>REST v1 today"]
Vikunja["Vikunja"]
end
Client -->|"OAuth 2.0 authorization code flow"| Access
Access -->|"Cf-Access-Jwt-Assertion"| Tunnel
Tunnel --> Adapter
Adapter --> Guard
Guard -.->|"fetches rotating signing keys"| JWKS
Guard --> Tools
Tools --> ClientLib
ClientLib -->|"Bearer token stays server-side"| Vikunja
classDef client fill:#e8f1ff,stroke:#2563eb,color:#172554
classDef edge fill:#ecfdf5,stroke:#059669,color:#064e3b
classDef origin fill:#f8fafc,stroke:#64748b,color:#0f172a
classDef data fill:#fff7ed,stroke:#ea580c,color:#7c2d12
class Client client
class Access,Tunnel,JWKS edge
class Adapter,Guard,Tools,ClientLib origin
class Vikunja dataThe public endpoint terminates at Cloudflare. The adapter accepts MCP traffic only after it validates the Access assertion with Cloudflare's rotating JWKS, expected issuer, application audience, and a local email allowlist. The separate Vikunja token never reaches the MCP client.
Related MCP server: Cloudflare Remote MCP Server (Authless)
Capabilities
Class | Tools | State |
Read | list_projects, list_tasks, get_task | Available |
Write | create_task, update_task, complete_task | Implemented, disabled by default |
Labels | Read and assign existing labels | Available with writes; never creates labels |
Excluded | Delete, sharing, teams, users, bulk changes, label creation | Intentionally unavailable |
The adapter has one Vikunja client abstraction. MCP tools never issue REST calls directly, so a future move away from the current /api/v1 backend is contained in one layer.
Security model
Cloudflare Access Managed OAuth authenticates the human user. Cloudflare documents a short Access-token lifetime together with a longer grant session as the normal configuration for non-browser clients.
The origin does not trust the tunnel alone. It validates the Cf-Access-Jwt-Assertion header's signature through JWKS, issuer, audience, and the authenticated email address.
Use a dedicated least-privilege Vikunja integration account and API token. Store the token only in the server runtime secret store.
The container does not publish a host port. It is read-only, drops Linux capabilities, uses no-new-privileges, and has a tmpfs for temporary files.
MCP_WRITE_ENABLED is false unless explicitly changed. Even when enabled, writes require an additional identity allowlist.
Deployment shape
The example Compose file expects three networks:
vikunja: an existing private network shared with the Vikunja service.
mcp-proxy: an internal network shared with the existing Cloudflare Tunnel connector.
mcp-egress: egress only for refreshing Cloudflare Access signing keys.
The tunnel hostname must route to http://vikunja-mcp:3000. Do not publish port 3000 on the host.
cp .env.example .env
# Populate only the empty secret and Access fields in your protected runtime copy.
docker compose -f compose.example.yml up -d --buildConfigure a Cloudflare Access application for the MCP hostname and enable Managed OAuth in its advanced settings. Give the Access application a narrow allow policy, set the issuer and Audience tag in the container environment, and use the same intended users in CF_ACCESS_ALLOWED_EMAILS.
Cloudflare's current guidance: Managed OAuth and origin JWT validation.
Configuration
Variable | Purpose |
VIKUNJA_BASE_URL | Private Vikunja service base URL, without /api/v1 |
VIKUNJA_MCP_API_TOKEN | Dedicated Vikunja integration token; secret |
VIKUNJA_ALLOWED_PROJECT_IDS | Comma-separated project allowlist, enforced for reads and writes |
CF_ACCESS_ISSUER | Cloudflare Access team domain |
CF_ACCESS_AUDIENCE | Access application Audience tag |
CF_ACCESS_ALLOWED_EMAILS | Comma-separated origin allowlist |
MCP_WRITE_ENABLED | Defaults to false |
MCP_WRITE_ALLOWED_EMAILS | Required in addition to the feature flag for writes |
PORT | Listener port, default 3000 |
Health and operations
GET /healthz checks that the Node process is live and needs no Access assertion.
GET /readyz checks Vikunja connectivity and returns 503 when it is unavailable.
POST /mcp is the only MCP endpoint. Other methods return 405.
Logs deliberately contain only event names and fixed identifiers. They never include assertions, API tokens, task descriptions, or Vikunja response bodies.
Development
Node.js 20 or newer is required.
npm ci
npm test
docker build --tag vikunja-mcp-cloudflare-access:test .The test suite covers Access assertion verification, unauthenticated rejection, stateless Streamable HTTP MCP discovery, read behavior, disabled writes, existing-label handling, and the REST-client boundary.
License
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityCmaintenanceEnables deploying and connecting to MCP servers on Cloudflare Workers with OAuth login, allowing remote access to tools via MCP clients like Claude Desktop.270MIT
- Flicense-qualityCmaintenanceEnables deployment of a remote MCP server on Cloudflare Workers without authentication, supporting custom tools and integration with clients like Claude Desktop.
- Flicense-qualityDmaintenanceEnables remote MCP connections with OAuth login, running on Cloudflare Workers for secure tool access.
- Flicense-qualityCmaintenanceEnables remote MCP connections with Cloudflare Access OAuth, providing tools like add and generateImage with user-based access control.
Related MCP Connectors
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Hosted remote MCP server for YNAB on Cloudflare Workers with OAuth
Self-hosted MCP gateway: turn any API, database or MCP server into AI connectors — no code.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/bmoor/vikunja-mcp-cloudflare-access'
If you have feedback or need assistance with the MCP directory API, please join our Discord server