
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@tasklite/mcp
Advanced tools
TaskLite MCP server: build a full backend (projects, boards, data, REST endpoints), deploy a frontend onto it, and get a ready-made admin, from Claude Code and other MCP clients
Documentation: https://tasklite.net/docs
TaskLite MCP server. Build a full backend from Claude Code (projects, boards, typed columns, data, REST endpoints with API keys), deploy a frontend onto it, and hand your client a ready-made admin.
Install the package (and Claude Code if you don't have it), then add the server
by its binary. That avoids a known Windows issue where claude mcp add
mis-parses npx -y.
npm install -g @anthropic-ai/claude-code @tasklite/mcp
claude mcp add tasklite -- tasklite-mcp
Add -s user to claude mcp add to make it available in every project
(claude mcp add -s user tasklite -- tasklite-mcp); the default scope is the
current project only.
Then tell Claude what you want to build. The sign_up tool creates your account, organization, and connection from the conversation (a strong random password is generated locally and never shown; use "forgot password" with your email for web access).
Already have an account? Create a key at TaskLite → Integrations → "Connect Claude Code" and use:
claude mcp add tasklite -e TASKLITE_API_KEY=tl_xxx -- tasklite-mcp
Point any MCP client at the hosted server; there is nothing to install locally:
claude mcp add --transport http tasklite https://mcp.tasklite.net/mcp \
--header "Authorization: Bearer tl_xxx"
The hosted server is stateless: every request carries its own credential, so one endpoint serves every account safely.
Simplest of all: the connector. In Claude (claude.ai or the desktop app), Settings → Connectors → add TaskLite, or add it by address using the URL above. You sign in once over OAuth; there is no key to create or store. Note that the tools appear in a new chat, not in the conversation you were already in.
Optional env: TASKLITE_API_URL (default https://api.tasklite.net), TASKLITE_APP_URL (default https://app.tasklite.net).
One hosted server, every MCP client. Full setup notes: https://tasklite.net/docs/guides/connector-from-cursor-codex-desktop
{"mcpServers":{"tasklite":{"url":"https://mcp.tasklite.net/mcp"}}} in .cursor/mcp.json..vscode/mcp.json with {"servers":{"tasklite":{"type":"http","url":"https://mcp.tasklite.net/mcp"}}}.https://mcp.tasklite.net/mcp. The server implements search and fetch.gemini extensions install https://github.com/shimon-ks/tasklite-mcp (this repo ships gemini-extension.json), or add httpUrl + oauth to ~/.gemini/settings.json.Authorization: Bearer tl_….create_project → create_board → create_column × N builds the schema.create_item / query_items seed and inspect data.create_app → create_app_endpoint (with exposedColumns + RLS) → create_app_api_key expose the REST surface for your frontend.get_app_spec / get_frontend_prompt generate the frontend against it.adminUrl, the ready-made admin for the end client.deploy_frontend puts a static frontend on https://{slug}.tasklite.dev.
No server, no hosting account, no CI to configure. Hand the site over in one
of three ways:
deploy_frontend(appId: "app-xxxxxx", files: [{ path: "index.html", content: "<!doctype html>…" }, { path: "app.js", content: "…" }])
deploy_frontend(appId: "app-xxxxxx", zipUrl: "https://github.com/you/site/releases/download/v1/dist.zip")
deploy_frontend(appId: "app-xxxxxx", dir: "./dist")
files is the path from ChatGPT or any hosted client: the assistant writes the
page and deploys it in the same turn. zipUrl takes an export from Lovable,
Bolt or a GitHub release. dir is for an MCP running on the machine with the
build output.
Hosted pages call the app API through the relative path /api/{endpoint}. The
hosting proxy attaches the app identity server-side, so the browser never
carries an API key. list_deployments shows the versions and
rollback_deployment points the live URL back at an earlier one.
tl_ key is exchanged for a short-lived JWT (POST /public/v1/auth/session); all calls run with the key owner's own permissions, never super-admin.tasklite.dev need no key at all.npm install
npm run build
TASKLITE_API_KEY=tl_xxx TASKLITE_API_URL=http://localhost:3333 node dist/index.js
MIT
FAQs
TaskLite MCP server: build a full backend (projects, boards, data, REST endpoints), deploy a frontend onto it, and get a ready-made admin, from Claude Code and other MCP clients
The npm package @tasklite/mcp receives a total of 104 weekly downloads. As such, @tasklite/mcp popularity was classified as not popular.
We found that @tasklite/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.