basecamp-mcp-server
Provides tools for managing Basecamp projects, messages, to-dos, recordings, and Card Tables, including reading and writing capabilities with safety controls.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@basecamp-mcp-serverList all projects in my Basecamp account."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Basecamp MCP Server
An open-source Model Context Protocol server for Basecamp projects, messages, to-dos, recordings, and Card Tables. It is designed for operational workflows where an AI assistant needs to retrieve context, prepare changes, and keep sensitive card mutations behind explicit, preview-bound approval.
This is an independent community project. It is not affiliated with, sponsored by, or endorsed by 37signals or Basecamp.
Highlights
Discover projects and enabled project tools.
Search to-dos and Card Table cards by title or assignee.
Follow Basecamp pagination automatically.
Keep mutation tools disabled by default.
Preview sensitive card updates before writing.
Bind card comments, due-date changes, and investigation reports to short-lived, single-use confirmation tokens.
Refuse ambiguous title-based writes when multiple items match.
Support OAuth authorization and token refresh.
Run linting, typing, tests, and dependency auditing in CI.
Related MCP server: Basecamp MCP Server
How preview-bound confirmation works
Sensitive Card Table workflows use a two-step protocol:
Call a preview tool.
Show the preview to the user.
The preview returns a short-lived
confirmation_idbound to the exact card and payload.After explicit approval, call the matching write tool with that
confirmation_id.The server verifies that the requested write exactly matches the approved preview and consumes the token.
A confirmation token cannot be reused and cannot authorize a changed payload.
The server enforces preview-before-write and exact payload binding. The MCP host is responsible for forwarding theconfirmation_id only after the user has actually approved the preview.
Requirements
Python 3.11 or newer.
A Basecamp OAuth application or valid access token.
An MCP-compatible stdio client such as Kiro, Claude Desktop, or another MCP host.
Install from GitHub
uv tool install git+https://github.com/thiagorchaves/basecamp-mcp-server.gitFor development:
git clone https://github.com/thiagorchaves/basecamp-mcp-server.git
cd basecamp-mcp-server
uv sync --extra devConfigure Basecamp OAuth
Register an application in the 37signals integrations console and use this redirect URI:
http://localhost:8000/callbackCreate your local environment file:
cp .env.example .env
chmod 600 .envSet at least:
BASECAMP_CLIENT_ID=your_oauth_client_id
BASECAMP_CLIENT_SECRET=your_oauth_client_secret
BASECAMP_REDIRECT_URI=http://localhost:8000/callback
BASECAMP_USER_AGENT=Basecamp MCP Server (you@example.com)Authorize the application:
basecamp-oauthRefresh an expired access token with:
basecamp-oauth --refreshTest the connection:
basecamp-testWrite safety
Mutation tools are not registered unless this variable is enabled:
BASECAMP_ENABLE_WRITE_TOOLS=trueKeep it false for read-only usage. Even when writes are enabled, do not add mutation tools to an MCP client's automatic approval list.
Preview-bound confirmation tokens default to five minutes:
BASECAMP_CONFIRMATION_TTL_SECONDS=300The following Card Table writes require a valid preview token:
add_card_updatefrompreview_card_updateupdate_card_due_datefrompreview_card_due_dateadd_investigation_report_to_cardfrompreview_investigation_report_to_card
Other optional mutation tools still rely on BASECAMP_ENABLE_WRITE_TOOLS=true and the MCP host's approval controls.
Kiro configuration
{
"mcpServers": {
"basecamp": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/thiagorchaves/basecamp-mcp-server.git",
"basecamp-mcp"
],
"env": {
"BASECAMP_ACCOUNT_ID": "${BASECAMP_ACCOUNT_ID}",
"BASECAMP_ACCESS_TOKEN": "${BASECAMP_ACCESS_TOKEN}",
"BASECAMP_USER_AGENT": "${BASECAMP_USER_AGENT}",
"BASECAMP_ENABLE_WRITE_TOOLS": "false",
"BASECAMP_CONFIRMATION_TTL_SECONDS": "300"
},
"autoApprove": []
}
}
}Tools
Read-only and preview
healthchecklist_projects,find_projects,find_project_by_name,get_projectget_project_toolslist_messageslist_todolists,list_project_todolists,list_todoslist_project_todos,find_todos_by_titleget_recordinglist_project_card_tables,get_card_table,list_cardsfind_cards_by_title,find_cards_by_assignee,get_my_cardspreview_card_updatepreview_card_due_datepreview_investigation_report_to_card
Write-enabled
create_message,create_project_messagecreate_project_message_from_markdowncreate_todo,create_todo_from_markdownupdate_card_by_titleadd_comment,comment_recording_from_markdownadd_card_update(preview token required)update_card_due_date(preview token required)add_investigation_report_to_card(preview token required)
Recommended card workflow
Find the project and target card.
Display its title, column, URL, and current state.
Call the appropriate preview tool.
Show the preview and ask the user for explicit confirmation.
Pass the returned
confirmation_idto the matching write tool.Read the resource again and report the final state.
Development
uv sync --extra dev
uv run ruff format --check .
uv run ruff check .
uv run mypy basecamp_mcp
uv run pytestCI tests Python 3.11, 3.12, and 3.13 and runs a scheduled dependency audit.
Security
Never commit .env, OAuth tokens, account IDs from private environments, or real API responses containing people and project data. See SECURITY.md for vulnerability reporting.
License
MIT. See LICENSE.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables AI assistants to interact with Basecamp projects through natural language commands. Supports managing projects, to-do lists, messages, and creating tasks with full content rendering capabilities.660ISC
- AlicenseBqualityDmaintenanceConnects Basecamp workspaces to AI tools, enabling management of projects, messages, todos, and schedules through natural language interactions. Features persistent caching and supports both reading workspace data and performing actions like creating messages and updating todos.10MIT
- Alicense-qualityBmaintenanceEnables AI assistants to interact with your Productboard workspace, allowing features, products, notes, objectives, key results, and releases management.20MIT
- Alicense-qualityDmaintenanceEnables Claude to interact with Basecamp API for project and to-do management via OAuth authentication.60MIT
Related MCP Connectors
Connect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language.
Connect AI assistants to Stellary projects, boards, documents, and governed agent workflows.
Give AI agents access to form submissions — read, search, update, and process file attachments.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/thiagorchaves/basecamp-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server