The Linear MCP server is Linear's own hosted server at https://mcp.linear.app/mcp. It lets an agent read and manage issues, projects, and cycles. It runs over HTTP with OAuth 2.1 — scoped, revocable tokens, no API key in a config file. TrustedMCP grades it A; it is one of the better-secured integrations in the directory.

What it connects

  • Read: issues, projects, cycles, comments, teams, and users in the workspaces you authorise.
  • Write: create and update issues, move them through states, add comments — bounded by the OAuth scopes you grant at connect time.
  • Runs remotely, so there is no local process and no stdio command-execution surface.

Setup

Claude Code:

claude mcp add --transport http linear https://mcp.linear.app/mcp

Cursor — ~/.cursor/mcp.json:

{ "mcpServers": { "linear": { "url": "https://mcp.linear.app/mcp" } } }

VS Code — .vscode/mcp.json:

{ "servers": { "linear": { "type": "http", "url": "https://mcp.linear.app/mcp" } } }

Claude Desktop uses the same URL via a custom connector. On first use the client opens Linear's OAuth screen; approve the workspace and scopes there. Nothing secret is stored in the config file — the token lives in the client's credential store and can be revoked from Linear's settings.

Security notes

The remote OAuth model removes the two biggest MCP risk classes at once: no long-lived key sits in a checked-in file, and the HTTP transport avoids the stdio command-execution issue entirely. Two things still apply:

  • Grant the narrowest scope. If the agent only triages, it does not need issue-delete or admin scope.
  • Issue and comment text is untrusted input. A ticket body can carry instructions aimed at the model, so keep any high-impact follow-on action (closing a sprint, bulk edits) behind a human confirmation. See MCP security best practices.

Full trust breakdown on the Linear MCP listing; the scoring method is in how TrustedMCP scores servers. For enabling it in the editor, see the VS Code MCP guide.

Need this built and hardened for you?

We build custom, security-reviewed MCP servers. Tell us what you need an agent to reach.

Start a conversation