ClickUp MCP in Cursor and VS Code

Connect ClickUp’s official MCP server to Cursor, VS Code and Codex: the one URL, the browser sign-in, where each editor keeps the entry, and how to stop any of them changing ClickUp without asking.

7 min read

To use ClickUp in Cursor, add ClickUp’s hosted MCP server, https://mcp.clickup.com/mcp, either from the ClickUp plugin on the Cursor Marketplace or as a url entry in .cursor/mcp.json. Cursor then opens ClickUp in your browser, you sign in and pick the Workspace, and the agent can search, read and change tasks, comments, time entries and Docs with your own ClickUp permissions. VS Code takes the same URL through code --add-mcp, and Codex takes it as an [mcp_servers.clickup] table in config.toml. The sign-in is OAuth in every case; ClickUp does not accept API keys on this server. What deserves your attention is the approval setting in each editor, because every call also counts against a daily allowance.

This guide covers the editors. The same server in the terminal, with Claude Code’s permission rules, is in ClickUp MCP with Claude Code, and this post does not repeat it. If MCP itself is new to you, start with what MCP is.

What you are connecting to

  • One remote server that ClickUp runs, so there is nothing to install. ClickUp’s overview (opens in a new tab) says it is in public beta and available on all plans.
  • OAuth only. ClickUp’s FAQ says you cannot authenticate with your own API keys or access tokens, and that a custom client needs OAuth 2.1 with PKCE. Cursor, VS Code and Codex all handle that for you.
  • Your rights, not a narrower set. The assistant can do what your ClickUp account can do in the Workspace you authorise.
  • A daily call budget. Without the Everything AI add-on, ClickUp documents 50 calls per rolling 24 hours on Free Forever and 300 on Unlimited and above. An agent in an editor can spend that fast, so the approval settings below also protect the budget.

Cursor: the plugin or mcp.json

The quick route is the ClickUp plugin on the Cursor Marketplace: select Add to Cursor and follow the sign-in. The manual route is the entry ClickUp gives in its setup instructions (opens in a new tab), in ~/.cursor/mcp.json for every project or .cursor/mcp.json for one:

.cursor/mcp.json
{
  "mcpServers": {
    "clickup": {
      "url": "https://mcp.clickup.com/mcp"
    }
  }
}
  1. Save the file and open Customize in Cursor’s sidebar. Find clickup under MCPs and switch it on.
  2. Cursor opens ClickUp in your browser. Sign in, choose the Workspace and approve. Check the Workspace name before you do; it is the boundary of everything the agent will see.
  3. Back in Cursor, the server shows its tools. If it does not, open the Output panel and choose MCP Logs, which is where Cursor’s MCP documentation sends you for connection and sign-in errors.

The file holds only the address, so a project copy can be committed: each person who opens the repository signs in with their own ClickUp account. There is no key to leave in it by mistake.

Approvals in Cursor

Cursor asks before each MCP tool call by default. Under Settings, Agents, Approvals & Execution, Cursor’s run modes (opens in a new tab) are Auto-review, Allowlist and Run Everything. Auto-review sends calls that are not on your allowlist to a classifier, and Cursor says plainly that the classifier is not a security boundary. For a connection that can move, reassign and delete tasks, Allowlist is the predictable choice, and Run Everything is not a sensible one.

The allowlist can live in .cursor/permissions.json for the project or ~/.cursor/permissions.json for you. Entries are server:tool, and * works inside a name. ClickUp documents its tools by description (Search Workspace, Get Task, Get Task Comments and so on) rather than by the names the server reports, so copy the exact names from the list Cursor shows in Customize:

.cursor/permissions.json (shape only; copy the real names from Customize)
{
  "mcpAllowlist": [
    "clickup:<search workspace tool>",
    "clickup:<get task tool>",
    "clickup:<get task comments tool>"
  ]
}

Allow searches and reads; leave everything that creates, updates, moves, posts to Chat or logs time on ask. Never add clickup:*. A list in the file replaces the one in Cursor’s settings for that type, so keep all your MCP entries in one place.

VS Code: add it, then use a Local session

ClickUp’s instructions for VS Code are one command. Run it in a terminal, then open the Extensions view, find ClickUp MCP among the installed MCP servers, choose Start Server from its cog menu and follow the sign-in links:

Terminal
code --add-mcp '{"type":"http","name":"clickup","url":"https://mcp.clickup.com/mcp"}'

That writes the server to your user profile. To share it with a repository instead, put the same values in .vscode/mcp.json under servers; the details of that file are in VS Code mcp.json.

The step people miss is the session target. VS Code now runs chat through agent harnesses, and VS Code’s harness documentation (opens in a new tab) says Copilot sessions can currently reach only local MCP servers that do not require authentication. ClickUp is remote and needs a sign-in, so in a Copilot session it simply is not there. Choose Local with the Session Target control, and the ClickUp tools appear.

When the agent calls a tool, VS Code shows the tool name and its input and lets you approve once, for the session, for the workspace or for always. Grant the longer approvals to read tools only. VS Code’s approvals page (opens in a new tab) describes “Chat: Manage Tool Approval” for adjusting them per tool and “Chat: Reset Tool Confirmations” for clearing them, and a permissions picker in the chat input whose Allow all level runs every call without asking. Leave it on the default while ClickUp is connected. Trust and secrets in VS Code more generally are covered in VS Code MCP security.

Codex: a config.toml table

ClickUp does not publish Codex instructions, but ClickUp’s server is a standard remote server with OAuth, and OpenAI’s Codex MCP documentation (opens in a new tab) covers that case. Add it from the shell, then sign in:

Terminal
codex mcp add clickup --url https://mcp.clickup.com/mcp
codex mcp login clickup

That writes a table to ~/.codex/config.toml, which the Codex CLI, the IDE extension and the ChatGPT desktop app share. You can also write it by hand, and add an approval rule while you are there:

~/.codex/config.toml
[mcp_servers.clickup]
url = "https://mcp.clickup.com/mcp"
default_tools_approval_mode = "prompt"
tool_timeout_sec = 60

default_tools_approval_mode accepts auto, prompt, writes and approve, with per-tool overrides under tools.<tool>.approval_mode. prompt asks before every call. writes asks only for tools the server does not mark as read-only, so it is only as good as the server’s annotations; start with prompt and look at what the server declares before relaxing it. enabled_tools and disabled_tools hide tools from the model altogether, which is the firmer control if there is a tool you never want used. Type /mcp in a session to check the server is connected.

Prompts that suit an editor

  • “Find the ClickUp task for the checkout timeout bug and summarise its comments.” A read, and a good first test.
  • “Create a task in the Bugs List for each failing test in this run, with the test name and error in the description.” Several calls; check the result.
  • “Move ‘Payment retries’ to In Review and comment with the commit hash and what changed.”
  • “Log 45 minutes on ‘Payment retries’ for today.” ClickUp’s tools include time entries and timers.

Name the List or Space in each prompt. A broad request makes the agent walk the Workspace hierarchy first, which costs calls against the daily limit and fills the context with names it did not need.

Two things to know before you trust it

  • Deletion. ClickUp’s FAQ says no deletion tools have been added, as a safety measure, while its tools page lists a Delete task tool. Believe the tool list your editor shows, and keep any delete tool on approval.
  • Beta limits can change. ClickUp says usage and rate limits may change as it assesses usage and costs, and that the server cannot search apps connected to ClickUp.

The same editors, a smaller board

The ClickUp server hands the agent all of your ClickUp rights in the Workspace. fenbs connects to Cursor, VS Code and Codex the same way, with https://fenbs.ai/api/mcp and a browser sign-in, but the approval screen lets you tick what the assistant may do, and it holds your role on the board narrowed by those scopes. Every change it makes is recorded under its own name. It is also far less: four lanes, To Do, Next Up, In Progress and Completed, no due dates, no sprints, no time tracking and no importer for ClickUp exports. One honest detail for the settings above: fenbs sets no tool annotations yet, so Codex’s writes mode treats every fenbs tool as a write and asks each time. The steps are on connecting Cursor, VS Code and Codex, and the fair comparison is fenbs vs ClickUp.

Related

ClickUp in the terminal: ClickUp MCP with Claude Code. The same editors with Trello: Trello MCP in Cursor and VS Code. What the browser step approves: how MCP sign-in works. Why approvals matter: MCP security risks.

Questions people ask.

What do I put in Cursor’s mcp.json for ClickUp?

A server named clickup with the url https://mcp.clickup.com/mcp, in .cursor/mcp.json or ~/.cursor/mcp.json. Switch it on under Customize and sign in to ClickUp in the browser. The ClickUp plugin on the Cursor Marketplace does the same for you.

Why can my Copilot session in VS Code not see ClickUp?

VS Code says Copilot harness sessions can currently reach only local MCP servers that need no authentication. ClickUp is a remote server with an OAuth sign-in, so choose a Local session with the Session Target control.

Can I use a ClickUp API key instead of signing in?

No. ClickUp says its MCP server supports OAuth only, not personal API keys or your own access tokens, so each editor signs in through the browser.

Does ClickUp support Codex?

ClickUp does not publish Codex steps, but its server is a standard remote MCP server with OAuth. Run codex mcp add clickup with the url option set to https://mcp.clickup.com/mcp, then codex mcp login clickup.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.