Skip to main content

tripl-mcp

Standalone MCP server exposing a curated, agent-safe toolset over a running tripl instance. It is a pure HTTP client of the tripl REST API (/api/v1) — it imports no backend code and is not mounted into the FastAPI app.

  • 18 curated tools (15 read, 3 write): plan search, event read/write, event types & fields, variables, branches & diffs, scans, monitors, reconciliation, projects.
  • Read tools carry readOnlyHint; write tools require a tk_w_ API key.
  • Plan-mutating tools require branch_id so an agent never edits the live main plan by accident. Operators can override with TRIPL_MCP_ALLOW_MAIN=1.
  • Branch merge/revert/transition, SSE streams, and photo upload are intentionally not exposed in v1.
  • The HTTP client is not in this package. It lives in the tripl distribution (../cli) and is imported from there, so the CLI and this server share one implementation rather than two that drift (tripl-ey6j.1).

stdio (Claude Code / Claude Desktop)

No form below needs a checkout of your own, but the first two get tripl — the distribution this package imports its HTTP client from (tripl-ey6j.1) — from different places, and the difference is worth knowing:

  • uvx tripl-mcp installs the release from PyPI and resolves tripl from the index, as an ordinary dependency of the published wheel.
  • The git+…#subdirectory=mcp-server form clones the whole repository, so the sibling cli/ arrives with it and the [tool.uv.sources] table below points tripl at that directory. Server and client are therefore built from one commit, and the form does not care what the index currently serves.

This README describes main, which between releases can be ahead of what PyPI serves. Deliberately no version numbers or tool counts here: they were hand-maintained and went stale the moment a release shipped. uvx tripl-mcp gives you the current release; the git form gives you what has landed but not yet shipped. git log mcp-server/ is the honest diff between them.

From PyPI — the released version:

{
  "mcpServers": {
    "tripl": {
      "command": "uvx",
      "args": ["tripl-mcp"],
      "env": {
        "TRIPL_BASE_URL": "https://tripl.example.com",
        "TRIPL_API_KEY": "tk_r_..."
      }
    }
  }
}

From git — no clone needed, and the way to run what is in this repository:

{
  "mcpServers": {
    "tripl": {
      "command": "uvx",
      "args": [
        "--from",
        "git+https://github.com/vladenisov/tripl.git#subdirectory=mcp-server",
        "tripl-mcp"
      ],
      "env": {
        "TRIPL_BASE_URL": "https://tripl.example.com",
        "TRIPL_API_KEY": "tk_r_..."
      }
    }
  }
}

From a local checkout:

{
  "command": "uv",
  "args": ["run", "--project", "/path/to/tripl/mcp-server", "tripl-mcp"]
}

Create API keys in the tripl app under Settings → API keys. Use a project-scoped tk_r_ key for read-only agents; reserve tk_w_ keys for agents explicitly allowed to edit the plan.

streamable-http (shared server)

TRIPL_BASE_URL=https://tripl.example.com tripl-mcp --transport streamable-http --port 8765

In this mode the server holds no credentials. Every incoming MCP request must carry Authorization: Bearer tk_...; the header is forwarded verbatim to the tripl API and never stored. Requests without it get a clear tool error.

Environment

Variable Meaning
TRIPL_BASE_URL Base URL of the tripl instance (required)
TRIPL_API_KEY API key for stdio mode (required for stdio)
TRIPL_MCP_ALLOW_MAIN Set to 1 to allow plan writes without branch_id (edits main)

Development

cd mcp-server
uv sync
uv run --group dev pytest -q
uv run --group dev ruff check
uv run --group dev ruff format --check
uv run --group dev mypy src

uv resolves tripl from ../cli via [tool.uv.sources], so an edit there is picked up with no install step — and must be, because tripl_cli.client is this server's transport. Run both suites after touching it, which is what ci.yml's cli and mcp jobs do.

The container image builds from the repository root, not this directory, for the same reason:

docker build -f mcp-server/Dockerfile .   # `docker build ./mcp-server` no longer works

Docs

Full agent workflow guidance lives in the website docs: website/docs/integrate/agent-api-guide.md and website/docs/use-cases/llm-agent.md.

Metadata

Release files for tripl-mcp 0.2.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tripl-mcp 0.2.2
File Size Uploaded
tripl_mcp-0.2.2.tar.gz 101.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for tripl-mcp 0.2.2
File Interpreter ABI Platform
tripl_mcp-0.2.2-py3-none-any.whl Python 3 none any Details

Total release size: 139.2 kB

Release files / tripl_mcp-0.2.2.tar.gz

Download URL tripl_mcp-0.2.2.tar.gz
Size 101.7 kB
Tags Source
SHA-256 checksum
How to use checksums
8c87269821dc50c99bc895bdf2ccc000b2725b75e5cabd8fecbb5a35820ef3f5
BLAKE2b-256 checksum
How to use checksums
a09e1962375a855b6c240a3d19f3a7b5e68ef8c6c5943ede39e82bedb227a8f2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / tripl_mcp-0.2.2-py3-none-any.whl

Download URL tripl_mcp-0.2.2-py3-none-any.whl
Size 37.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
dfc17c1affe7f6e3304b1b3dae89fb5ee719f571dc8d60863184deef5dbafb16
BLAKE2b-256 checksum
How to use checksums
273584eca38b562fd1a286babfaa60afa11c6798d3184d50d919083f2d094b00
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.2 This release

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page