application-tracker
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@application-trackershow my recent job applications"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Application Tracker
Application Tracker is a self-hosted workspace for recording job applications, documents, follow-up actions, contacts, and outcomes. It combines a responsive web interface with optional local and authenticated remote Model Context Protocol (MCP) access.
The application stores its data in SQLite and sends no workspace content to a hosted service. A fresh installation contains no account, sample data, or default password.
Features
Dashboard metrics, searchable applications, sortable tables, detail drawers, modal editing, contacts, links, due actions, and immutable history
Configurable statuses, sources, role types, and document types
Local administrator and member accounts with revocable sessions
Original document storage, SHA-256 deduplication, application associations, inline PDF viewing, bounded DOCX and email previews, and safe downloads
Bounded email-link extraction without server-side network requests or stored email bodies
Local stdio MCP and authenticated Streamable HTTP MCP with bounded application and document transfer, explicit actor binding, website-controlled write access, and immutable audit events
Built-in remote MCP OAuth using local accounts, plus administrator-managed client IDs and one-time bearer tokens and optional external token verification
Online SQLite backup, verification, non-overwriting restore, and forward migrations
Application Tracker does not yet provide OpenID Connect browser login. Local password login always remains available.
Security model
First-run setup requires an operator-generated one-time token.
The project never creates
admin/adminor another known credential.Passwords use salted, memory-hard scrypt hashes; random session and MCP tokens are stored only as hashes.
Every application, document, user, and MCP operation preserves workspace and role checks in shared application services.
Runtime secrets, databases, backups, and machine configuration remain outside Git and container images.
Read the product contract, architecture, and security model for the complete boundary.
Requirements
Node.js 22.12 or newer for a direct installation
Docker Engine with the Compose plugin for a container installation
A trusted HTTPS reverse proxy for Internet access
Quick start for development
cp .env.example .env
npm ci
npm run devOpen http://<server-ip>:5173, replacing <server-ip> with an address assigned
to the host. The development server and backend listen on all interfaces for
LAN and container access. Restrict both ports with the host firewall, and never
use Vite as a public reverse proxy.
Generate a setup token with openssl rand -hex 32, place it in .env, and
follow the initial administrator setup. Remove the token
and restart the service after setup succeeds.
Run every local quality gate with:
npm run checkDeploy
Choose one supported path:
Both guides keep data and secrets outside the checkout. The container example publishes port 3333 on loopback by default; LAN exposure requires an explicit override. Internet exposure requires HTTPS at a trusted reverse proxy.
Before upgrades, create an online backup and follow the backup and restore runbook. Copying a live WAL database file is not a valid backup.
MCP
Local clients should follow the stdio guide. Remote clients should follow the authenticated HTTPS guide.
Settings → MCP provides copyable templates for Claude.ai, remote Codex, local Codex, and Claude Desktop. Remote interactive clients use the built-in OAuth flow and the same local username and password as the website; no Authentik or other external identity provider is required.
Fresh workspaces are read-only through MCP. An administrator can enable Read and write under Settings → MCP. The server rechecks this policy on every mutation, including calls made through existing sessions.
Job-email agent skill
The repository includes the installable Application Tracker Job Email skill. It teaches compatible AI clients how to reconcile messages from an Outlook Jobs folder with Application Tracker through the server's deterministic match and idempotent email-upsert tools, while stopping when evidence is ambiguous or conflicting.
Codex discovers the skill from .agents/skills while working in this checkout.
Other clients that support SKILL.md skills can install the
.agents/skills/application-tracker-job-email directory using their normal
skill installation flow. Connect both the Application Tracker MCP server and an
email provider before invoking $application-tracker-job-email.
Documentation
Contributing and security
Contributions are welcome through pull requests. Read the contribution guide before submitting code. Report suspected vulnerabilities through the private process in the security policy, not a public issue.
License
Application Tracker is source-available under the Elastic License 2.0. You may use, modify, and redistribute it, but you may not provide the software to third parties as a hosted or managed service that exposes a substantial set of its features.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/romprod/application-tracker'
If you have feedback or need assistance with the MCP directory API, please join our Discord server