Asana MCP With Claude: Setup, Tools and Permissions
How to connect Claude to Asana through Asana’s official MCP server, in the Claude app and in Claude Code: the two setup routes, the tools it exposes, whose permissions it uses, and the limits worth knowing first.
6 min read
Asana has an official MCP server at https://mcp.asana.com/v2/mcp, and there are two ways to connect Claude to it. In the Claude app on the web or desktop, add Asana from Claude’s connector directory, sign in, and choose the Asana workspace. In Claude Code, either use that same connector (it appears automatically when you sign in to Claude Code with your claude.ai account) or register your own Asana MCP app and add the server with its client ID. Either way Claude works with your own Asana permissions, in one workspace at a time. The rest of this guide covers both routes, the tools, and the limits.
One difference from many other MCP servers shapes the Claude Code setup: Asana does not support dynamic client registration, so a client cannot register itself on the fly. The Claude connector has that handled for you; a hand-added server in Claude Code needs an app you create in Asana’s developer console. If MCP itself is new, start with what MCP is.
Route 1: the Asana connector in Claude
- In Claude, open Customize, then Connectors, and browse the directory. You can also reach it from the + button in a chat, under Connectors, then Manage connectors.
- Choose Asana and select Connect.
- Sign in to Asana, pick the workspace you want Claude to use, and approve.
- Mention Asana in a conversation, for example “What Asana tasks do I have due this week?”
On Claude Team and Enterprise plans an owner may need to make a connector available to the organisation before members can connect it; each member then signs in with their own Asana account. On the Asana side, Enterprise+ and Legacy Enterprise customers can allow or block individual MCP clients through Asana’s app management. If Asana is blocked, sign-in offers to send your admin a request.
In the Claude app you also get per-tool controls. Under Customize, then Connectors, each Asana action can be set to Always allow, Needs approval or Blocked. Claude’s help centre (opens in a new tab) points out that allowing a write in Claude still needs the underlying permission in Asana.
Route 2: Claude Code
If you already connected Asana in the Claude app and you sign in to Claude Code with the same claude.ai subscription account, you are done: type /mcp and Asana is listed, marked as coming from claude.ai. Claude Code only fetches these connectors (opens in a new tab) under a claude.ai login, not when it runs on an API key or a cloud provider.
Otherwise, add the server yourself. This takes one extra step, because of the pre-registration requirement:
- In Asana’s developer console, choose Create new app, name it, and select MCP app as the type. Note the client ID and client secret.
- Under OAuth, add the redirect URL
http://localhost:8080/callback. It must match exactly. - Under Manage distribution, choose the workspaces the app may be used in. If you pick specific workspaces and select none, sign-in fails with “This app is not available to your Asana workspace or organization.”
- Run the command below. Claude Code prompts for the client secret with masked input and stores it outside your config.
- Start Claude Code, type
/mcp, chooseasanaand sign in in the browser.
claude mcp add --transport http \ --client-id YOUR_CLIENT_ID \ --client-secret \ --callback-port 8080 \ asana https://mcp.asana.com/v2/mcp
--callback-port 8080 fixes the port Claude Code listens on during sign-in so it matches the redirect URL you registered. Treat the client secret as a secret: Asana asks you never to commit it (opens in a new tab) and to use separate credentials per developer. If you find an older guide pointing at https://mcp.asana.com/sse, that was the beta V1 server, which Asana deprecated with a shutdown date of 5 August 2026. Use the V2 URL. What happens during the browser step is explained in how MCP sign-in works.
The tools
Asana publishes a tools reference (opens in a new tab) and asks clients to treat tools/list as the source of truth, since tools are added and changed. At the time of writing they fall into three groups:
- Read:
search_objects(the universal search for tasks, projects, portfolios, goals, teams, users and more),get_task,get_tasks,get_my_tasks,search_tasks,get_project,get_projects,get_portfolio,get_portfolios,get_items_for_portfolio,get_status_overview,get_attachments,get_me,get_user,get_users,get_teams, and two for Asana’s AI Teammates. - Write:
create_tasksandupdate_tasks(up to 50 tasks per call),create_project,add_comment,create_project_status_updateanddelete_task, which deletes permanently. - Interactive:
create_task_preview,create_project_previewandsearch_tasks_previewshow a confirmation card before anything is created. Asana says these work in Claude and ChatGPT; other clients, including Claude Code, use the plain write tools.
Two details save confusion. search_tasks, the full-text search, is available on Premium accounts only; on other plans Claude falls back to get_tasks with a filter. And there is no dedicated goals tool: ask for goals and Claude searches with search_objects.
Permissions: what Claude can do
Asana MCP access is user-based. Asana’s documentation (opens in a new tab) says everything done over MCP appears as the user who authorised it, and the token cannot reach any workspace, project or task that user cannot already see. It is also workspace-scoped: you pick one workspace at sign-in, and working in another means a separate connection.
What it does not have is scopes. Asana MCP apps do not use permission scopes, so an authorisation can use every available tool, including tools added later. You cannot sign in “read-only” on the Asana side. The controls you have are on the Claude side: the per-tool settings in the Claude app, and permission rules in Claude Code. In Claude Code, pre-approve reads and leave writes on ask:
{
"permissions": {
"allow": [
"mcp__asana__get_*",
"mcp__asana__search_objects"
],
"deny": [
"mcp__asana__delete_task"
]
}
}The deny rule removes delete_task from Claude Code’s view entirely, which is sensible until you have a reason to allow it. Tools from a claude.ai connector carry a different prefix (opens in a new tab) in Claude Code, of the form mcp__claude_ai_<server>__<tool>, so check the exact names in /mcp before writing rules for that route.
Limits to know
- One workspace per connection.
- No dynamic client registration. Hand-added clients need an Asana MCP app, and the redirect URL must match to the character.
- MCP tokens work only with the MCP server, not with Asana’s REST API. Access tokens last an hour and are refreshed by the client.
- Some tools depend on your Asana plan, such as
search_tasks. - Large results fill context. Claude Code warns when a tool result passes 10,000 tokens and caps it at 25,000 by default. Ask for one project or one assignee rather than everything.
Removing it
In the Claude app, disconnect Asana under Customize, then Connectors. In Claude Code, claude mcp logout asana clears the sign-in on your machine and claude mcp remove asana removes the server; to change a client secret you remove the server and add it again. On the Asana side, admins on the tiers above can block the client for everyone.
If Asana is more than you need
Asana is work management for organisations, with portfolios, goals and timelines, and its MCP server exposes that breadth under your own account. If what you want is one board with four lanes, where your assistant is a member with a role you chose rather than all of your rights, and every change it makes is signed with its name, that is what fenbs is for. The fair comparison is on fenbs vs Asana, and the setup is on connect Claude and connect Claude Code.
Related
What to check on any consent screen: how MCP sign-in works. The same kind of setup for Jira: Jira MCP with Claude Code. Habits for any MCP connection: MCP security best practices.