Prerequisites
- An Asana account with access to the workspace, teams, projects, and tasks you want CloudThinker to use.
- Permission to create an OAuth app in the Asana developer console, or its client ID and client secret from an administrator.
- A CloudThinker workspace where Asana is not already connected.
Asana does not support dynamic client registration for its MCP server. Each CloudThinker workspace supplies its own OAuth app credentials.
Setup
1
Copy the redirect URL
In CloudThinker, navigate to Connections → Asana, then click Connect. Copy the redirect URL shown in step 1 and keep the dialog open.
2
Create and configure the Asana app
In step 2, click Open Asana developer console. Select Create new app, enter a name, choose MCP app, and create the app.Open OAuth in the Asana app, add the copied redirect URL, and save it. Then open Manage distribution and allow the workspaces that may authorize the app.Return to CloudThinker and click Mark as Configured.
3
Enter the app credentials
In step 3, copy the app’s Client ID and Client secret from Asana into CloudThinker, then click Connect.Sign in to Asana, select the workspace CloudThinker should use, and approve access. CloudThinker shows a Connected status.
Connection details
Required permissions
Asana MCP access is user-based inside the selected workspace. Actions appear as the authorizing user, and CloudThinker can only reach projects and tasks that user can access.- Read operations cover people, teams, projects, tasks, workload, due dates, and project status.
- Write operations cover task creation, task updates, and task deletion. Each operation requires explicit approval.
- Excluded operations include creating projects, adding comments, and posting project status updates.
Agent capabilities
Verify the connection
Example prompts
Troubleshooting
CloudThinker rejects the app credentials
CloudThinker rejects the app credentials
Copy the client ID and client secret again from the same Asana app. Confirm that neither value contains spaces added during copying, then retry.
Asana reports a redirect URL mismatch
Asana reports a redirect URL mismatch
Open the Asana connection dialog again. Copy the complete redirect URL into the app’s Redirect URLs setting and save the app. Return to CloudThinker, click Mark as Configured, then retry.
Expected projects or tasks are missing
Expected projects or tasks are missing
The authorizing user may lack access, or another workspace may have been selected during OAuth. Confirm the user can open the resource in Asana, or reconnect and select the correct workspace.
A task cannot be found
A task cannot be found
The task may be deleted, unavailable to the authorizing user, or from another workspace. Ask Anna to discover the current workspace and resolve the project or task again.
A task change did not run
A task change did not run
Task creation, updates, and deletion require approval. Approve the exact action in CloudThinker, then retry with a task and project from the current connection.
Asana reports a rate limit or temporary error
Asana reports a rate limit or temporary error
For a rate limit, wait for the time Asana requests before retrying. For another temporary error, retry the same request once and keep the error visible if it repeats.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- OAuth app credentials — keep the client secret out of source control. CloudThinker encrypts it during OAuth and in the saved connection environment.
- Workspace scope — limit app distribution and user access to the Asana workspaces and projects CloudThinker needs.
Related
Connections
Browse every service CloudThinker agents can use.
Approval
See how CloudThinker asks before an agent changes connected services.