Productboard MCP — Curve & Flex
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Productboard MCP — Curve & Flexlist features in the 'Q4 Planning' workspace"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Productboard MCP — Curve & Flex
Custom MCP server exposing read/write tools over the Productboard v2 API, with Google-OAuth 2.1 login, a per-email allowlist, and per-user workspace binding (Curve + Flex served from one Cloud Run service).
This is the canonical source. Baseline captured from the source of the
May 26 2026 production deploy and committed as v1 (July 2026). Earlier local
prototypes live in ../_Archive/ — do not edit those; they are pre-OAuth and
out of date.
Layout
src/server.py— the MCP tools (the tool surface Claude sees)src/productboard.py— Productboard v2 API client (auth, retries, pagination, notes)src/auth.py— the MCP's own OAuth 2.1 (Google IDP + JWT). NOT Productboard auth.src/allowlist.py— who may use the MCP + their workspace bindingDockerfile,requirements.txt,deploy.sh— build & deployROADMAP.md— forward plan
Related MCP server: mcp-google-multi
Deploy
./deploy.sh # READ_ONLY=true (write tools disabled) — default
READ_ONLY=false ./deploy.sh # enable write toolsTarget: project productboard-mcp, region us-central1, service
productboard-mcp (gcloud run deploy --source=.). Secrets — the per-workspace
Productboard API tokens, the OAuth client secret, and the JWT signing key — are
mounted from Secret Manager. Never store them here.
Rules
No secrets in the repo. Tokens live in Secret Manager;
src/allowlist.pyis the only access config in-tree, and git history is its audit trail.Safe surface by design: no create-feature tool, no permanent delete (soft-delete via
archived). Keep it that way.Write access is per-user: only allowlist entries with
writer: Truecan call the write tools, even when the service runsREAD_ONLY=false(the env var stays as the global kill switch). Currently: Luke only.
Revocation
One user, immediately: set
tokens_valid_afteron their allowlist entry (or remove the entry), commit, redeploy. Takes effect on their next request — permissions are re-derived from the allowlist on every call, not frozen into tokens.Everyone at once (break-glass): bump the
TOKEN_VERSIONenv var (gcloud run services update productboard-mcp --region=us-central1 --update-env-vars=TOKEN_VERSION=<n+1>). All outstanding tokens die instantly; users re-auth via Google. No code change, no key rotation.Refresh tokens live 7 days; offboarding must still remove the allowlist entry (leaver-checklist item — disabling the Google account alone does NOT cut existing sessions).
This server cannot be deployed
Maintenance
Related MCP Connectors
Governed MCP gateway: one endpoint for your tools, with credential custody and audit log.
Hosted MCP server with managed OAuth for 15+ toolkits: Google Workspace, Fitbit, Oura, Kalshi, etc.
Read and edit GA4, Search Console and Google Tag Manager from any MCP client. 29 tools.
Paid remote MCP for AI Studio Workspace approval gate MCP, structured receipts, audit logs, and revi
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables management of Google Cloud services including BigQuery, Cloud Logging, Cloud Storage, and Compute Engine via MCP tools.MIT
- AlicenseAqualityAmaintenanceGives MCP clients access to Google Workspace (Gmail, Drive, Calendar, Sheets, Docs, etc.) across multiple Google accounts simultaneously.13230 npm10MIT
- FlicenseNot gradedqualityBmaintenanceProvides read/write access to Google Sheets and Google Docs through MCP tools, enabling operations like reading sheets, appending rows, and editing documents.-
- FlicenseNot gradedqualityDmaintenanceEnables interaction with Google Workspace (Drive, Docs, Sheets, Gmail) via MCP tools, using OAuth credentials stored locally or inline.-