The monday.com connector wraps the monday.com v2 GraphQL API as MCP tools for Agent Factory agents, and as Monday.op: App instructions for Builder automations — covering boards, items, subitems, columns, groups, workspaces, updates, files, webhooks, docs, folders, tags and activity logs, plus a generic graphql passthrough. The MCP server runs in the tenant app-instance context: it resolves the installing workspace’s own credentials and authorizes the calling agent against that workspace’s allowlist. Authentication supports three modes:
- Per-user OAuth2 — central client (
oauthCentral, recommended) — one monday.com OAuth application is registered once by the platform maintainer; every end user signs in with their own monday.com account. Nothing to register per workspace: each one just installs the app and clicks Connect. - Per-user OAuth2 — tenant client (
oauth) — paste your own monday.com OAuth client ID/secret in the connector config app. Each user signs in with their own account against your client (authorization-code + PKCE flow). - Personal API Token (
accessToken) — a caller-managed monday.com Personal API Token (v2), used as-is with no exchange. One identity acts for the whole workspace.
Boards & Items
Collaboration
Per-user auth
Who is this for?
This connector is used by three different roles. Jump to the section that matches yours — each one is self-contained.Agent builder
Platform admin
Workspace builder
Prerequisites
- A monday.com account.
- For the OAuth modes — a monday.com OAuth application created at monday.com/developers/apps; copy its Application ID (client id) and Client Secret. The platform maintainer registers one app for the central mode; a workspace can also register its own for the tenant mode.
- For the access-token mode — a Personal API Token (v2) generated in monday.com Developer center > My access tokens.
-
The default OAuth scopes requested are:
-
Base URL:
https://api.monday.com(the connector targets the/v2GraphQL endpoint).
Platform admin (Governance) — one-time platform setup
Platform admin (Governance) — one-time platform setup
<api-url> is your environment’s API URL (https://api.studio.prisme.ai/v2 on production).1. Configure the connector
Register the OAuth application at monday.com
https://api.studio.prisme.ai/v2/workspaces/slug:monday/webhooks/oauthCallback on production). Add the scopes listed in Prerequisites. Save and copy the Application ID (client id) and Client Secret (the secret is shown only once).Enter the credentials through the configuration app
monday workspace and launch its Configuration app — <studio>/apps/monday (e.g. https://studio.prisme.ai/apps/monday). Loaded from the core workspace, the app shows the maintainer view (org owner / editor / admin only); paste the Application ID and Client Secret there and Save — the app stores them in the core workspace’s secrets for you. Do not edit Studio’s raw Secrets by hand. These credentials stay in the monday workspace and are never exposed to tenants or end users; token exchange is proxied through the core centralTokenExchange webhook so the client secret never leaves the core workspace.Tell workspaces to use the central client
oauthCentral in the connector configuration app (no client id/secret to enter on their side). Their users then just click Connect.(Optional) Publish to the Capabilities catalog
2. Declare the capability in AI Governance
As an alternative to (or in addition to) the catalog button, you can declare monday.com as a named capability in AI Governance. Agent builders then enable that capability on their agents instead of pasting a raw MCP endpoint.Open AI Governance > Capabilities
Point it at the MCP endpoint
agent_id in the scope is what lets the connector identify and authorize the calling agent.Make it available to agent builders
Smoke-test
oauthCentral, trigger any tool (e.g. me). The user is prompted to connect once (monday.com sign-in); subsequent calls reuse the stored token transparently and refresh it automatically.- Agent builder (Agent Factory)
- Workspace builder (DSUL)
Agent builder
Goal: let an agent you build in Agent Factory use monday.com through MCP tools.agent_id that Agent Factory injects through the capability Scope, and that agent must appear in the connector’s authorized-agents allowlist (managed in the configuration app). The monday.com access token itself is resolved server-side from the configured auth mode.There are two ways to wire it up. Pick based on how much isolation you need.Option A — Enable the shared capability from the catalog
The fastest path: a Platform admin has already published a monday.com capability to the Capabilities catalog (see the Platform admin setup accordion above — the Add to catalog button, or §2), so you just pick it from the catalog.Open your agent in Agent Factory
Add the monday.com capability
context_id,agent_id,user_id) are already wired by the admin — nothing to paste, and the shared instance accepts every agent, so there is no allowlist step on your side.Connect a monday.com account
connect_url to monday.com’s authorization page. After sign-in the per-user token is stored and reused on subsequent calls.Option B — Run it from your own workspace (recommended)
For production agents, install the connector in your own workspace and point the agent at that workspace’s MCP endpoint.Install and configure the connector in your workspace
Allowlist your agent
Add the MCP capability to your agent
agent_id is what lets the connector identify and authorize your agent — without it, every call is rejected with an explicit “agent could not be identified” message. This Scope is separate from the monday.com OAuth scopes.Connect a monday.com account
Brief the agent in its system prompt
Whichever option you pick, wiring the capability is not enough — the agent also needs to know the tools exist and when to reach for them. Copy-pasteable starter:agent_id.:write scope, e.g.:oauthCentral) you do not create your own monday app — keep oauthCentral and enter the read scopes; your tenant scope overrides the platform default (the central app must list these read scopes). Write calls (GraphQL mutations) are then rejected by monday with a permission error. The scope is set at the workspace level (a workspace editor can widen it again).Available Tools
All tools accept anoutputFormat argument (verbose default / structured / both). monday.com IDs are numeric strings; list the parent resource first to obtain them.Boards
Items & Subitems
Columns
Groups
Users & Teams
Workspaces
Updates (comments)
Tags, Assets, Webhooks, Notifications
Docs & Folders
Meta & Admin
Output Formats
Every tool accepts anoutputFormat parameter that controls the MCP response shape:verbose(default) — human-readable text optimized for LLM consumption.structured— machine-readable JSON instructuredContent.both— both text and structured content.
Tool Details
create_item
items_page_by_column_values
Filter board items by column values server-side.change_column_value vs change_simple_column_value
change_column_valuetakes a typed JSON payload (e.g.{"label": "Done"}forstatus,{"date": "2026-05-15"}fordate).change_simple_column_valuetakes a plain string and lets monday.com infer the format (e.g.Done,2026-05-15).
{"personsAndTeams":[{"id":123,"kind":"person"}]}).create_notification
create_doc
location.board instead:Error Handling
Common Issues
“This agent is not authorized to use this connector” — The calling agent is not in the allowlist. Open the configuration app → Authorized agents → tick this agent (id is shown in the error) or enable Allow all agents, and Save. The Install capability button does this for you. “The calling agent could not be identified” — The MCP capability Scope does not declareagent_id, so Agent Factory never injects the agent identity. Set the Scope to context_id,agent_id,user_id on the capability (this is separate from the monday.com OAuth scopes), then allow the agent in the config app.
“monday.com is not connected for this user” — No per-user OAuth token is stored for the caller. Open the configuration app (OAuth mode) and click Connect, or use the agent’s connect flow. In the accessToken mode, paste a Personal API Token in the config app instead.
“monday.com token refresh failed … must reconnect” — The stored refresh token was rejected by monday.com (revoked / expired). The connection is dropped automatically; the user must reconnect from the config app.
“monday.com OAuth is not configured” — Neither a tenant OAuth client nor the central platform client is available. Set the OAuth client id/secret in the config app (tenant mode), or ask the platform maintainer to provision the central OAuth client from the core workspace’s config app.
“Complexity budget exceeded” — monday.com rate limits by query complexity, not request count. Large items_page calls can exhaust the budget quickly. Paginate with smaller limit, or fetch fewer columns.
“Invalid column value” — The payload shape depends on the column type. Prefer change_simple_column_value for simple types (text, numbers, status) and change_column_value for complex ones (people, dropdown, timeline). create_labels_if_missing only applies to status and dropdown columns.