An MCP Server that interacts with the Basecamp 3+ API
{
"mcpServers": {
"basecamp": {
"env": {
"PYTHONPATH": "/path/to/your/project",
"VIRTUAL_ENV": "/path/to/your/project/venv",
"BASECAMP_ACCOUNT_ID": "your_account_id"
},
"args": [
"/path/to/your/project/basecamp_fastmcp.py"
],
"command": "/path/to/your/project/venv/bin/python"
}
}
}An MCP Server that interacts with the Basecamp 3+ API
Is it safe?
No known CVEs for mcp. 3 previously resolved.
No authentication — any process on your machine can connect.
MIT. View license →
Is it maintained?
Last commit 30 days ago. 81 stars.
Will it work with my client?
Transport: stdio, http. Works with Claude Desktop, Cursor, Claude Code, and most MCP clients.
Context cost
22 tools. ~1,300 tokens (0.7% of 200K). Consider loading selectively.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
uvx mcp 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
get_projectsGet all Basecamp projects
get_projectGet details for a specific project
get_todolistsGet todo lists for a project
get_todolistGet a specific todo list by ID
create_todolistCreate a new todo list in a project
update_todolistUpdate an existing todo list (name and/or description)
trash_todolistMove a todo list to the trash (recoverable within 30 days)
get_todosGet todos from a todo list (returns all pages; handles Basecamp pagination transparently)
get_todoGet a single todo item by its ID
create_todoCreate a new todo item in a todo list (with assignees, due dates, descriptions)
This server is missing a description.If you've used it, help the community.
Add informationNo open vulnerabilities. 3 fixed CVEs.
CVE-2025-66416FixedModel Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
### Description The Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication using `FastMCP` with streamable HTTP or SSE transport, and has not configured `TransportSecuritySettings`, a malicious website could exploit DNS rebinding to bypass same-origin policy restrictions and send requests to the local MCP server. This could allow an attacker to invoke tools or ac
CVE-2025-53366FixedMCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
A validation error in the MCP SDK can cause an unhandled exception when processing malformed requests, resulting in service unavailability (500 errors) until manually restarted. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures. Thank you to Rich Harang for reporting this issue.
CVE-2025-53365FixedMCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
If a client deliberately triggers an exception after establishing a streamable HTTP session, this can lead to an uncaught ClosedResourceError on the server side, causing the server to crash and requiring a restart to restore service. Impact may vary depending on the deployment conditions, and presence of infrastructure-level resilience measures. Thank you to Rich Harang for reporting this issue.
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.