# @timesheet/mcp

Model Context Protocol server for Timesheet API

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 2.0.2
- **Author:** timesheet.io
- **License:** MIT
- **npm:** @timesheet/mcp
- **Endpoints:** streamable-http https://mcp.timesheet.io
- **Source:** https://github.com/timesheetIO/timesheet-mcp
- **Endpoint health:** reachable (last checked 2026-09-27T18:20:38.192Z, 1 sample) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-10-05T01:56:50.782Z
- **Version scanned:** 2.0.2
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `timer_start` — Use this when the user wants to begin tracking time on a specific project. The user can optionally specify a custom start time in the past, otherwise it default
- `timer_stop` — Use this when the user wants to stop the currently active timer and complete the time tracking session. The user can optionally specify when the timer should be
- `timer_pause` — Use this when the user wants to pause the timer to take a break. This temporarily stops time tracking while keeping the task active.
- `timer_resume` — Use this when the user wants to resume time tracking after a break or pause. This restarts the timer from its paused state.
- `timer_status` — Use this when the user wants to check the current state of their timer, including whether it's running, paused, or stopped, and details about the active task.
- `timer_update` — Use this when the user wants to modify details of the currently running timer task, such as description, location, billability, or mood rating.
- `task_add_note` — Use this when the user wants to add a text note or comment to the currently running task for future reference or documentation.
- `task_add_expense` — Use this when the user wants to record an expense or cost associated with the currently running task, such as travel, materials, or client entertainment.
- `task_add_pause` — Use this when the user wants to manually record a past break or pause period that was not tracked in real-time.
- `team_list` — Use this when the user wants to view or search for teams. IMPORTANT: Use this tool to find team IDs by searching team names, which can then be used to filter pr
- `project_list` — Use this when the user wants to view their projects. IMPORTANT: When the user asks for a specific number (e.g., "show me 5 projects"), use the limit parameter t
- `project_create` — Use this when the user wants to create a new project to organize their time tracking.
- `project_update` — Use this when the user wants to modify an existing project's details such as title, description, or archive status.
- `project_delete` — Use this when the user wants to permanently delete a project. WARNING: This is a destructive operation that cannot be undone. All associated tasks will remain b
- `project_get` — Use this when the user wants to view detailed information about a specific project.
- `task_list` — Use this when the user wants to view their time entries. IMPORTANT: When the user asks for a specific number (e.g., "show me 10 tasks"), use the limit parameter
- `task_create` — Use this when the user wants to manually create a time entry for past work, rather than using the timer.
- `task_update` — Use this when the user wants to modify details of an existing time entry such as times, description, or billing status.
- `task_delete` — Use this when the user wants to permanently delete a time entry. WARNING: This is a destructive operation that cannot be undone.
- `task_get` — Use this when the user wants to view detailed information about a specific time entry/task.
- `auth_configure` — Use this when the user needs to configure API key authentication for the Timesheet MCP server. NOTE: This will be deprecated once OAuth 2.1 is implemented.
- `report_document_get` — Use this when the user wants to retrieve formatted document/invoice data including tasks, expenses, and financial calculations. Returns JSON data ready for disp
- `report_document_pdf` — Use this when the user wants to generate and download a PDF version of a document/invoice. The PDF is attached to the result as a file (up to 5 MB).
- `report_document_xml` — Use this when the user wants to generate XML representation of a document for e-invoicing (Zugferd, XRechnung, ebInterface). Returns XML data for electronic inv
- `report_task_get` — Use this when the user wants to retrieve formatted task data including time tracking, rates, and project details.
- `report_task_pdf` — Use this when the user wants to generate and download a PDF report for a specific task. The PDF is attached to the result as a file (up to 5 MB).
- `report_expense_get` — Use this when the user wants to retrieve formatted expense data including amounts and receipt information.
- `report_expense_pdf` — Use this when the user wants to generate and download a PDF report for a specific expense including receipt images. The PDF is attached to the result as a file 
- `report_note_get` — Use this when the user wants to retrieve formatted note data including content and attachments.
- `report_note_pdf` — Use this when the user wants to generate and download a PDF report for a specific note including images. The PDF is attached to the result as a file (up to 5 MB
- `export_generate` — Use this when the user wants to export their timesheet data in Excel (xlsx), CSV, or PDF format. Returns a download URL for the export file.
- `export_send` — Use this when the user wants to generate and send a timesheet export directly to an email address, as an Excel, CSV, or PDF file.
- `export_from_template` — Use this when the user wants to generate an export using a previously saved template with specific date range.
- `export_fields` — Use this when the user wants to see what fields/columns are available for customizing exports.
- `export_report_types` — Use this when the user wants to see what report types are available for export (e.g., detailed, summary, by project).
- `export_template_list` — Use this when the user wants to see their saved export templates for quick recurring exports.
- `export_template_get` — Use this when the user wants to view details of a specific export template.
- `export_template_create` — Use this when the user wants to save their export configuration as a reusable template.
- `export_template_update` — Use this when the user wants to modify an existing export template.
- `export_template_delete` — Use this when the user wants to delete an export template. This cannot be undone.

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"mcp\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"@timesheet/mcp\"\n      ],\n      \"env\": {\n        \"TIMESHEET_API_TOKEN\": \"<YOUR_TIMESHEET_API_TOKEN>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `TIMESHEET_API_TOKEN` — Timesheet API Token (required)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 1 credential (1 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Extensive blast radius — deletes data; runs locally and hosted.
- Floor 58, ceiling 58 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/%40timesheet%2Fmcp
- Install plan: https://forgeregistry.com/api/v1/packages/%40timesheet%2Fmcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/%40timesheet%2Fmcp
- HTML page: https://forgeregistry.com/registry/%40timesheet%2Fmcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
