linear-codemode-mcp
Provides read-only (or optionally mutation-enabled) access to Linear's GraphQL API via agent-written JavaScript. Agents can inspect the Linear schema (queries, types, and optionally mutations), then issue arbitrary queries or mutations against Linear to fetch and manage issues, projects, teams, and other workspace data.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@linear-codemode-mcpshow me all open issues assigned to me"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
linear-codemode-mcp
A local MCP server for Linear in the code mode pattern. The agent writes JavaScript, the server runs it in a throwaway worker, and only the return value comes back. Two tools instead of ninety in linear-mcp, under 1K tokens of tool descriptions instead of tens of thousands.
Read-only by default. Mutations are refused on the host before any request leaves the process, whatever the API key can do.
Tools
Tool | What the agent's code gets | Network |
|
| none |
|
| Linear only, via the host |
Results over about 6,000 tokens are cut structurally so they stay valid JSON (Cloudflare's truncate.ts, Apache-2.0, see LICENSE-cloudflare-mcp).
Related MCP server: Read-only Analytics MCP Server
Run
Requires Bun.
bun install # also fetches schema/linear.graphql
cp .env.example .env.local # then put your key in it
bun test
bun start # speaks MCP on stdioThe MCP host spawns the server from its own working directory, so Bun needs an absolute path to the env file. For Claude Code, user scope:
claude mcp add --scope user linear-code -- bun --env-file=/ABS/PATH/linear-codemode-mcp/.env.local /ABS/PATH/linear-codemode-mcp/src/index.tsFor a project-level .mcp.json, or any other host that takes a JSON server block, copy .mcp.json.example and fix the paths.
Configuration
Variable | Default | Meaning |
| required | Personal API key, sent as a bare |
| unset |
|
|
|
|
|
| Wall-clock budget per call; the worker is terminated when it expires |
| unset |
|
| unset |
|
| unset |
|
| unset |
|
|
|
Files
The point of code mode is that big payloads never pass through the model. A comment body that lives in a file, or a thousand issues the model wants to grep later, should go straight between disk and Linear:
async () => {
const body = await files.read("/abs/path/docs/ENG-123-comment.md");
const { commentCreate } = await linear.request({
query: `mutation($issueId: String!, $body: String!) { commentCreate(input: { issueId: $issueId, body: $body }) { success } }`,
variables: { issueId: "...", body },
});
return commentCreate.success;
}Paths are absolute. Symlinks are resolved before the directory check, so a link inside the project pointing elsewhere counts as elsewhere. .env* files are refused on both sides whatever the flags say. The host does every read and write; the worker only ever sees the text.
How a call runs
The tool handler spawns a fresh Bun
Workerfrom a blob URL withenv: {}andsmol: true.The agent's code is compiled with
new Functionwhose parameters shadowfetch,process,Bun,require,postMessageand the other globals that reach outside the worker, then awaited.linear.request()posts to the host thread. The host parses the document withgraphql, refuses anything that is not aquery(ormutationwhen enabled), then fetches with the key. The key never enters the worker.files.read()andfiles.write()take the same route; the worker has no file handles.The return value is JSON-serialised in the worker, truncated on the host, and sent back as text.
The worker is terminated. A loop that never yields dies with the timer.
This is a guardrail, not a security boundary against a hostile author. The author owns the key.
Updating the schema
bun run update-schema pulls packages/sdk/src/schema.graphql from linear/linear. The file is gitignored; the server refuses to start without it.
Credits
@cloudflare for cloudflare/mcp inspiration.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Scoped agent execution. Server-side credentials, policy, budgets and verifiable receipts.
Call third-party APIs from agents without leaking secrets. SSRF blocked, per-key quotas.
The governed runtime for agent skills. Search the catalog and inspect a skill before running it.
- mcp-serverOAuthai.cdbx
Build Apps and run code in 30 languages — sandboxed, with persistent sessions for agent loops.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceProvides a sandboxed environment for AI coding agents to execute TypeScript AWS SDK queries securely, with cross-account aggregation and no host credential exposure.33 npm7Apache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables analytics agents to run validated read-only SQL against a warehouse API with enforced row limits, required JSON responses, and secret-safe audit metadata.MIT
- FlicenseAqualityCmaintenanceEnables running read-only SQL queries against Increff Webget database replicas using an authenticated browser session, with mandatory human approval for every query.2-
- AlicenseAqualityCmaintenanceEnables querying PostHog with HogQL, retrieving event and property definitions, session replays, and project lists, plus optional REST API access with safeguards against accidental writes and API key leakage.67 npmMIT