Skip to main content
Connect Asana to let Anna review projects, workloads, due dates, and delivery status. Anna can also create, update, or delete one task after you approve the action. Asana uses OAuth through its official hosted MCP server and an OAuth app that your workspace administrator creates. The selected workspace and authorizing user define what CloudThinker can reach.

Prerequisites

  • An Asana account with access to the workspace, teams, projects, and tasks you want CloudThinker to use.
  • Permission to create an OAuth app in the Asana developer console, or its client ID and client secret from an administrator.
  • A CloudThinker workspace where Asana is not already connected.
Asana does not support dynamic client registration for its MCP server. Each CloudThinker workspace supplies its own OAuth app credentials.

Setup

1

Copy the redirect URL

In CloudThinker, navigate to Connections → Asana, then click Connect. Copy the redirect URL shown in step 1 and keep the dialog open.
2

Create and configure the Asana app

In step 2, click Open Asana developer console. Select Create new app, enter a name, choose MCP app, and create the app.Open OAuth in the Asana app, add the copied redirect URL, and save it. Then open Manage distribution and allow the workspaces that may authorize the app.Return to CloudThinker and click Mark as Configured.
3

Enter the app credentials

In step 3, copy the app’s Client ID and Client secret from Asana into CloudThinker, then click Connect.Sign in to Asana, select the workspace CloudThinker should use, and approve access. CloudThinker shows a Connected status.

Connection details

Required permissions

Asana MCP access is user-based inside the selected workspace. Actions appear as the authorizing user, and CloudThinker can only reach projects and tasks that user can access.
  • Read operations cover people, teams, projects, tasks, workload, due dates, and project status.
  • Write operations cover task creation, task updates, and task deletion. Each operation requires explicit approval.
  • Excluded operations include creating projects, adding comments, and posting project status updates.
Authorize with an Asana user whose access matches the projects CloudThinker needs in the selected workspace.

Agent capabilities

Deleting an Asana task through the MCP tool is permanent and cannot be undone. It also deletes subtasks unless a subtask belongs to another project. CloudThinker shows the task record and asks for approval first.

Verify the connection

Example prompts

Troubleshooting

Copy the client ID and client secret again from the same Asana app. Confirm that neither value contains spaces added during copying, then retry.
Open the Asana connection dialog again. Copy the complete redirect URL into the app’s Redirect URLs setting and save the app. Return to CloudThinker, click Mark as Configured, then retry.
Open Manage distribution for the Asana app. Allow all workspaces or select the intended workspace. A specific-workspace policy with no selected workspace blocks authorization.
The authorizing user may lack access, or another workspace may have been selected during OAuth. Confirm the user can open the resource in Asana, or reconnect and select the correct workspace.
The task may be deleted, unavailable to the authorizing user, or from another workspace. Ask Anna to discover the current workspace and resolve the project or task again.
Task creation, updates, and deletion require approval. Approve the exact action in CloudThinker, then retry with a task and project from the current connection.
For a rate limit, wait for the time Asana requests before retrying. For another temporary error, retry the same request once and keep the error visible if it repeats.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • OAuth app credentials — keep the client secret out of source control. CloudThinker encrypts it during OAuth and in the saved connection environment.
  • Workspace scope — limit app distribution and user access to the Asana workspaces and projects CloudThinker needs.

Connections

Browse every service CloudThinker agents can use.

Approval

See how CloudThinker asks before an agent changes connected services.