Secure Asana access for AI agents

Tasks, projects, portfolios, and status updates via Asana's official MCP server

Through Asana, agents can search and read tasks, projects, portfolios, status updates, and workspace members, and create or update them when you allow it. Every call runs through your policies and is logged for audit.

Server URL: https://mcp.asana.com/v2/mcp

Credential modes

Asana supports bring your own app only. It does not support dynamic client registration, so your organization registers its own OAuth app in Asana and supplies the client ID and secret. See Credential modes for how the modes compare.

Before you begin

  • An Asana account that can create apps in Asana's developer console.
  • Administrator access to your Agent Authority workspace, to add the resource.

Setup moves between two consoles. You copy a redirect URI in the Agent Authority console, register an OAuth app in Asana, then return to the console and paste the credentials. Keep both tabs open as you work.

Setup

1. Copy the redirect URI

In the Agent Authority console, go to Resources → Add Resource and select Asana. Asana is bring-your-own-app only, so the credentials form opens as soon as you select it, with no mode to pick.

Copy the Redirect URI shown on the form. It includes your tenant's region, so copy it rather than typing it. It takes the form https://oauth.aisecurity.services.<region>.connect.secureauth.com/auth/callback.

Leave this page open. You come back to it in step 3.

2. Register an OAuth app in Asana

Sign in at app.asana.com/0/my-apps, Asana's developer console, and click Create new app. Give the app a name your users will recognize on the consent screen, then open the app's OAuth section:

  • Under Redirect URLs, add the Redirect URI from the form in the Agent Authority console, using the Copy button next to it. It must use HTTPS.
  • Copy the Client ID and Client Secret from the app's basic information.

3. Finish in the console

Back on the Asana form in the Agent Authority console, paste the Client ID and Client Secret. Leave Token Endpoint Authentication on Auto-detect. Then click Add.

The gateway sends you to Asana to sign in, through your SSO if configured, and authorize the app. Review the requested access and click Allow. You return to the console with your Asana account connected.

Verify the connection

The gateway syncs the Asana tools automatically. To check the connection end to end, ask your agent to run a request:

Get my Asana user details

If your name and email come back, the connection is working.

How users connect

Access is per user. Each additional user connects their own Asana account the first time their agent calls an Asana tool: the gateway returns a sign-in link, the user authorizes once, and the tools work from then on. Go to Connections to manage linked accounts.

Sign-in goes through your SSO when configured. Asana issues user-level tokens, so each user reaches only the workspaces and objects their own Asana membership allows.

Available tools

ToolTagsDescription
get_meread-onlyGet the current authenticated user's details
get_userread-onlyGet user details by ID, email, or "me"
get_usersread-onlyList users, optionally filtered by team
get_teamsread-onlyList teams in the workspace
search_objectsread-onlyQuick search across Asana objects (tasks, projects, portfolios, etc.)
search_tasksread-onlyAdvanced task search with full-text and complex filters (Premium)
search_tasks_previewread-onlyTask search that renders a visual preview of the results
get_taskread-onlyGet full task details by ID
get_tasksread-onlyList tasks filtered by workspace, project, tag, section, or user list
get_my_tasksread-onlyGet the current user's assigned tasks
create_taskswriteCreate one or more tasks
create_task_preview_v4read-onlyPreview a single task and confirm before creating it
update_taskswriteUpdate one or more tasks
delete_taskdestructiveDelete a task
add_commentwriteAdd a comment to a task
get_attachmentsread-onlyList attachments for a project, project brief, or task
get_projectread-onlyGet detailed project data
get_projectsread-onlyList projects in a workspace
create_projectwriteCreate a project, optionally with sections and tasks
create_project_preview_v3read-onlyPreview a project structure before creating it
create_project_status_updatewritePost a status update to a project or portfolio
get_status_overviewread-onlyGet status overview and progress reports for initiatives/projects
get_portfoliosread-onlyList portfolios owned by the current user
get_portfolioread-onlyGet detailed portfolio data by ID
get_items_for_portfolioread-onlyList projects, goals, and other items in a portfolio
get_workspace_agentsread-onlyList the AI Teammate agents configured in a workspace
get_agentread-onlyGet the full record for a single AI Teammate agent

Required scopes

The catalog entry requests no scopes, so Asana issues a token with its default scope: full user-level API access, bounded by each user's own Asana permissions. You do not select scopes when you register the app, and the Asana resource page has no scope setting.

Narrow what agents can do with gateway policies instead. See the examples below.

Policy examples

Every org is created with a seeded Allow all rule at the bottom of the list, so any call your own rules don't match stays allowed. Express restrictions as deny rules above it. New rules are added at the top, so a fresh deny outranks it automatically. See Rule order.

  • Read-only access: deny create_*, update_*, delete_*, and add_comment. The wildcards matter: they also catch create_task_preview_v4 and create_project_preview_v3, the preview-then-create flows that naming the tools individually would miss.
  • Task work without project administration: deny create_project, create_project_preview_v3, and delete_task, leaving the task reads, add_comment, and task creation allowed.
  • Block destructive changes: deny delete_task
  • Block destructive tools: add a deny rule with the built-in destructive tag (Tools pill) for this resource (MCP pill).

Next steps

  • Create a policy – start from the read-only pattern in Policy examples above.
  • Connections – manage the Asana accounts your users have linked.

On this page