lansura-mcp
v0.2.0
Published
MCP server for a shared lansura project. Reads the task tree; writes only tags and dated narrative.
Maintainers
Readme
lansura-mcp
The MCP server for one shared lansura project. An agent reads the task tree and writes only its own layer: tags and dated narrative. It cannot add, edit, move or delete a task, and that is enforced by an allow-list of event kinds rather than by the absence of a tool.
Install
Nothing to build. Register it with your agent and point it at a share link.
claude mcp add lansura -s user \
--env LANSURA_SHARE='https://lansura.com/p/PROJECT_ID#sharekey=KEY&salt=SALT&kc=CHECK' \
--env LANSURA_PASSPHRASE='the passphrase you were given' \
-- npx -y lansura-mcpUse -s user, which writes to ~/.claude.json. The default project scope writes .mcp.json inside
your repo, and that file gets committed: the passphrase is what protects the data and it has no
business travelling to git.
Configuration
Everything comes from the environment and is validated at startup, so a typo fails the server rather than every later tool call.
| variable | |
| ---------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| LANSURA_SHARE | The whole share link, FRAGMENT INCLUDED. The #sharekey=…&salt=… part is where the key material lives; a link copied without it cannot decrypt anything. |
| LANSURA_PASSPHRASE | The passphrase the project owner gave you out of band. Never in the link. |
| GATEWAY_URL | Optional. Defaults to the link's own origin, except a lansura.com link which defaults to gw.lansura.com. Set it for a dev box or a non-production deploy. |
| LANSURA_MCP_IDENTITY | Optional keypair file. Defaults to ~/.lansura-mcp-identity.json. |
What it can do
Reads: get_tree, get_actionable (with a last-modified per task, for spotting work nothing has
touched), get_delta (what changed between two datetimes). Both reads take an optional tags filter.
Writes, and only these: tag_task, tag_tasks (the bulk cross product: every id gets every tag,
in one call), untag_task, list_tags, delete_tag, add_narrative, remove_narrative.
What the link level means
A viewer link reads and writes nothing; every layer write is refused by name. A contributor link is what the write tools need. The server re-checks the link on every call, so disabling it in the app stops this server at its next call.
Disabling a link does NOT revoke a gateway grant that has already been minted, because grants are upgrade-only. It stops this server, which is the control the owner can actually reach. Treat the passphrase and the link together as the credential they are.
Privacy
Projects are end-to-end encrypted. The passphrase never leaves your machine, the key is derived once at startup, and the agent sees folded state only: no events, no ciphertext, no salt.
