Skip to content
MCPCompare

Vendor-published

Monday.com MCP server

MCP server for monday.com integration.

Monday.com (`com.monday/monday.com`, v0.0.1) is published by the vendor. It exposes a hosted endpoint over streamable-http and sse, and no self-hostable package. It requires authentication; it publishes no scope list we could read. 4 of 4 enterprise control criteria are undocumented. Last checked 2026-09-19.
Add to comparisonSource repository

Identity and maintenance

Publisher and version information
Registry namecom.monday/monday.com
Publisher domainmonday.com
Maintainer typeVendor-published

namespace com.monday -> monday.com; host mcp.monday.com is within monday.com

Latest version seen0.0.1
Last checked
Last changed

Separate from “last checked”: we check far more often than anything changes.

Enterprise evaluation

Every row below exists whether or not we found an answer. Expand any row to see the exact source and the date. Unknown means undocumented, never unsupported.

Enterprise evaluation criteria for Monday.com
Access and authentication
Authentication required

Whether the hosted endpoint accepted a connection with no credentials when we checked.

Yes
We checked checked
POST initialize without credentials -> HTTP 401
Unauthenticated connection attempthttps://mcp.monday.com/mcp
OAuth 2.1 authorization

Whether the server publishes OAuth discovery metadata a client can follow automatically.

Yes
We checked checked
https://mcp.monday.com/.well-known/oauth-protected-resource/mcp -> 200
OAuth discovery metadatahttps://mcp.monday.com/mcp
Dynamic client registration

Without it, an IdP administrator must register a client by hand before anyone can connect.

Yes
We checked checked
"registration_endpoint": "https://auth.monday.com/oauth_ms/oauth/register"
Authorization server metadatahttps://mcp.monday.com/mcp
Documented scopes
Not checked
Read and write are separate scopes

A single opaque scope means read-only access cannot be granted: approving access approves everything.

Not checked
Deployment and transport
Streamable HTTP transport
Yes
Registry checked
"type": "streamable-http", "url": "https://mcp.monday.com/mcp"
SSE transport
Yes
Registry checked
"type": "sse", "url": "https://mcp.monday.com/sse"
Vendor-hosted endpoint

Data leaves your network. Where it goes is a question for the vendor's documentation.

Yes
Registry checked
Self-hostable package

A published npm, PyPI, container or bundle artifact you can run inside your own perimeter.

No
Registry checked
Supply chain
Public source repository
Yes
Registry checked
Open-source license
Yes
MIT
Vendor checked
license: MIT
GitHub repositoryhttps://github.com/mondaycom/mcp
Repository actively maintained
Yes
Vendor checked
last push 3 days ago
GitHub repositoryhttps://github.com/mondaycom/mcp
Package deprecated
Not checked
Secret inputs marked as secret

Credential-shaped inputs the publisher did not flag as secret may be logged by a client.

Yes
Registry checked
2 credential input(s), all marked isSecret
Documented controls
Audit logging documented
Not documented
Access controls documented
Not documented
Data residency documented
Not documented
Data retention documented
Not documented

What remains unknown

7 of 18 criteria are undocumented. These are the questions to put to the vendor — not conclusions about the product.

Turn these into a vendor questionnaire

How we checked

One unauthenticated initialize request, plus the two OAuth discovery documents. Nothing was installed or executed. The exact request headers are below so you can reproduce the result — endpoint behaviour can depend on them.

POST https://mcp.monday.com/mcp
user-agent: mcpcompare.ai/1.0 (+https://mcpcompare.ai/methodology/probe; probe@mcpcompare.ai)
content-type: application/json
accept: application/json, text/event-stream
mcp-protocol-version: 2025-06-18

-> HTTP 401  (auth-required)
   checked 2026-09-19T17:17:16.086Z

Questions people ask

Does the Monday.com MCP server require authentication?
Yes. When we connected to https://mcp.monday.com/mcp without credentials on 2026-09-19, it returned HTTP 401.
Can I grant read-only access to the Monday.com MCP server?
Not documented. We found no scope list to read.
Can the Monday.com MCP server be self-hosted?
Not from the registry record. No installable package is declared, so the vendor-hosted endpoint is the only documented option.