---
title: "monday"
description: "Search and work with boards, items, and docs in the monday.com account the connected user can access, using monday.com's official remote MCP server."
canonical: https://agentpluginsdirectory.com/plugins/monday--xpert-ai
last-updated: 2026-10-10
---

# monday
Search and work with boards, items, and docs in the monday.com account the connected user can access, using monday.com's official remote MCP server.
- Slug: monday--xpert-ai
- Publisher: Xpert AI
- Repository: https://github.com/xpert-ai/xpert-plugins
- Manifest: agent-plugins/monday/plugin.json
- Version: 1.0.0
- Category (editorial): other
- Skills: 1 (monday-workspace)
- MCP servers: 1 (monday)
- Stars: 8
- Repository created: 2025-09-19
- Repository last pushed: 2026-10-10
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/monday--xpert-ai
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What monday does, in the publisher's words

Search and work with boards, items, and docs available to the monday.com account on the workspace's shared Connector.

Official endpoint: https://mcp.monday.com/mcp

Product docs: Platform MCP overview

- Unauthenticated initialize returned 401. WWW-Authenticate named protected-resource metadata https://mcp.monday.com/.well-known/oauth-protected-resource/mcp.
- That document's resource is https://mcp.monday.com/mcp, which matches the MCP URL. Its authorization server is https://auth.monday.com/mcp. It has no scopes_supported.
- Authorization-server metadata at https://auth.monday.com/.well-known/oauth-authorization-server/mcp names issuer https://auth.monday.com/mcp, authorize https://auth.monday.com/oauth2/authorize, token https://auth.monday.com/oauth_ms/oauth/token, and registration https://auth.monday.com/oauth_ms/oauth/register. PKCE S256 is advertised. Token endpoint auth methods are client_secret_post and client_secret_basic only. That document has no scopes_supported.
- Minimum OAuth scope: TBD. Protected-resource metadata did not advertise scopes. The issuer https://auth.monday.com (without /mcp) publishes a different scope list. Do not treat that list as this resource's required scopes.
- Dynamic registration is advertised, but the token endpoint does not advertise public-client none. A returned confidential client still needs its secret in the Connector form.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/xpert-ai/xpert-plugins/HEAD/agent-plugins/monday/README.md
