
Yandex 360 (ycli)
io.github.bim-bav0.36.0更新於 Oct 2, 2026
Yandex 360 Tracker, Wiki and Forms: read and write tools with honest read-only annotations.
概覽
讓助理透過 322 個 MCP 工具讀寫 Yandex 360 的 Tracker 議題、Wiki 頁面和 Forms 表單。
- 功能
- 為 Yandex 360 的 Tracker、Wiki 和 Forms 提供讀寫工具,每個工具對應一個已包裝的 API 操作,另有一個跨領域的 status 工具。讀取操作標示為唯讀,寫入操作會宣告是否具破壞性或冪等性。可依服務、精選核心設定或個別工具名稱縮小工具集,唯讀模式則不提供任何寫入工具。
- 適用情境
- 當助理需要處理 Yandex 360 內容時使用:查詢或更新 Tracker 議題、留言、狀態轉換和工作日誌,讀取或編輯 Wiki 頁面,或檢視 Forms 表單及其回覆。謹慎部署時可選擇唯讀啟動。
- 執行需求
- 透過 stdio 在本機執行,通常用 uvx 從帶 mcp 額外元件的 yandex-cli 套件啟動。需要 Yandex OAuth 權杖(YANDEX_ID_OAUTH_TOKEN)和組織 id(YANDEX_ID_ORGANIZATION_ID),後者以 X-Org-Id 標頭送出。權杖須由已註冊的 Yandex OAuth 應用程式簽發,並具備 Tracker、Wiki 和 Forms 權限。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Yandex 360 (ycli),將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
ycli
One Yandex 360 toolkit — four ways to use it. Drive Tracker, Wiki, and Forms from a CLI, an MCP server, a Python SDK, or a Claude Code plugin. Built for AI agents first — pleasant for humans too.
[CI] [Coverage] [PyPI] [Python] [License] [Ask DeepWiki]
[ycli in action]- 🧩 One SDK, four surfaces — write logic once, use it as a CLI, an MCP server, a Python library, or a Claude Code plugin.
- 🤖 Agent-native — the MCP server exposes read and write
tracker_*,wiki_*,forms_*tools, one per SDK/CLI operation, plus a cross-cuttingstatustool (counts in Coverage), with honest annotations (reads are marked read-only; writes declare whether they are destructive/idempotent);ycli mcp start --read-onlyserves a reads-only view for cautious deployments, and--toolsets coreserves a curated everyday profile when a host limits how many tools it accepts. - 🛡️ Trustworthy — typed pydantic models, the real Yandex API quirks handled for you, and a test suite kept at 100% coverage.
- ⚡ Zero-friction start —
uv add yandex-cli,ycli auth login, go.
Install
Run it without installing, or install it as a standalone tool:
pip install yandex-cli works too. The CLI ships as both yandex-cli and the short ycli.
Using an AI harness (Claude Code, Claude Desktop, Cursor, VS Code, Codex, Gemini CLI, opencode, Docker)? See Install in your harness.
The SDK's ServiceAccountAuth (IAM tokens minted from a Yandex Cloud service-account key) needs
the service-account extra: uv add 'yandex-cli[service-account]'.
Quick start
Pick the surface that fits how you work.
CLI
Output formats — a global --format / -o picks how results print (the global options work before or after the subcommand: ycli -o json tracker issues get K = ycli tracker issues get K -o json; a command that declares an option of its own, like forms answers export --format, keeps it):
--jq EXPR runs a jq program over the command's JSON result and prints
like jq -r: a string comes out raw, anything else as one compact JSON value per line. It
cannot be combined with -o yaml / -o pretty, and it needs the jq Python package (a
dependency; it has no build for Windows on ARM).
Deleting asks first. A command that destroys data (every delete, clear, abort…) asks
DELETE <url> — this deletes data. Continue? on stderr when you are at a terminal, and exits 1
if you decline. In a script, a pipe or CI there is no one to ask, so it fails with exit 2 until
you pass --yes / -y: ycli tracker boards delete 7 --yes. Reads and ordinary writes never ask.
Preview a write. --dry-run sends nothing for any write: it prints the request instead
(method, URL, body; never your token), through the same -o / --jq output, and exits 0.
Reads still run, so a command that reads and then writes shows its first write only:
ycli tracker boards delete 7 --dry-run. (The two commands that ask the API itself to validate
a request, forms filling submit and wiki pages move, call that --validate-only.)
An endpoint ycli has not wrapped. ycli api PATH --service tracker|wiki|forms calls it like
gh api would, with the same auth, retries, output and exit codes:
PATH is relative to the service's base URL; a full URL of a service needs no --service, and
any other host is refused (your token never goes elsewhere). -f key=value is a string, -F is
typed (true, null, numbers, JSON, @file for a file's text, key[sub]=v to nest, key[]=v
for an array); fields of a GET or DELETE go to the query string, otherwise to a JSON body (--input FILE sends a raw body instead). -H 'Name: value' adds a header, -X sets the method, and
--dry-run, --yes and --jq behave as everywhere. --paginate follows Tracker's Link: rel="next"
and Wiki's next_cursor; Forms pages its listings in more than one way, so pass its paging
parameters with -f yourself.
MCP server (read/write)
Run it over stdio (needs the mcp extra):
Serving all 322 tools costs a large tools/list and some hosts cap a request (VS Code allows
128 tools), so pick what the session needs:
status_get is always served. The listing omits output schemas and doctest examples (results
still carry structuredContent), which cuts tools/list from about 1.9 MB to about 0.5 MB for
the full set.
For several users, serve it over HTTP: each MCP client signs its user in through Yandex ID (OAuth), and every tool call runs with that user's own Yandex token. Setup, including the Yandex OAuth app and the reverse proxy, is in Self-host over HTTP.
List the tool names a given set of flags exposes without running the server:
Point an MCP client at it — no prior install needed via uvx (tools are namespaced
tracker_*, wiki_*, forms_*):
Python SDK
Claude Code plugin
Teaches an agent to drive Yandex 360 through ycli — including the real API quirks.
See plugins/yandex-360/.
Skills (Claude Code plugin)
The skills encode the read/write commands and the gnarly Yandex API quirks
(epic-vs-parent, transition discovery, permanent wiki slugs, fields= rules, Forms
host/header traps, answers pagination).
Configure
ycli reads two values from the environment (or a .env file — cp .env.example .env):
ycli sends the org id as X-Org-Id for every service (HTTP header names are case-insensitive
per RFC 9110, so one casing serves all).
Optional settings follow the YCLI__<GROUP>__<SETTING> pattern; ycli rejects an invalid value
at startup and names the variable:
Get your credentials
Yandex issues OAuth tokens only through a registered application, so it's a one-time app registration plus one command.
1. Register an OAuth app at oauth.yandex.ru and
grant it the Tracker, Wiki, and Forms permissions (read and write — the
CLI and the MCP server both write; the read scopes alone suffice only if you run the MCP
server with ycli mcp start --read-only). Put the ClientID — and the Client secret
if you want the headless flow — in your .env (ycli reads it from there):
2. Log in. ycli auth login gets a token, detects your organization, and writes both
into .env:
- client id + secret → the device flow: ycli prints a code and a
https://ya.ru/devicelink; approve there and it captures the token — no redirect, works over SSH. - only the client id (or
--implicit) → the browser flow: ycli opens the Yandex authorize page; approve, then copy the token it displays and paste it back.
Check it any time with ycli auth status: it shows whose token it is (from Yandex ID), your
organization (its name needs the optional directory:read_organization scope; without it you
get the id and a note) and whether each service accepts the token. ycli tracker auth status
(or wiki, forms) probes just that one service. Both exit non-zero when a service rejects
the token.
Prefer to do it by hand?
Headless (device flow):
Browser (implicit): open
https://oauth.yandex.ru/authorize?response_type=token&client_id=<ClientID> in a logged-in
browser, approve, and copy the token from the page. (Plain curl can't — implicit needs an
interactive browser session.)
Organization id: tracker.yandex.ru/admin/orgs → your organization → copy the identifier.
Exit codes
A failed ycli command exits with a code that says what kind of failure it was, so a script can branch without parsing the message.
Coverage
ycli wraps 334 operations across 62 resources of the Tracker, Wiki, and Forms REST API — every one reachable from the Python SDK and the CLI, plus 322 MCP tools (321 domain-scoped + 1 cross-cutting: status) for agents.
Legend — operations ship on SDK + CLI, and the MCP server mirrors them with honest annotations: reads carry
readOnlyHint, writes carry explicit destructive/idempotent hints, andycli mcp start --read-onlyserves the reads-only view. In each table SDK and CLI mean the operation is wrapped on that surface; MCP is ✅ when the resource exposes at least one MCP tool. Resource and operation names link to the official Yandex API reference (yandex.ru/support/…/api-ref). These tables are generated from the code byscripts/gen_coverage.py— do not edit by hand.
Tracker
35 resources · 190 operations · 187 MCP tools
Issues & work items
Agile boards
Dictionaries
Fields, queues & structure
Automation & bulk
Entities, users & search
Wiki
11 resources · 58 operations · 56 MCP tools
Pages
Collaboration
Grids (dynamic tables)
Async & uploads
Identity
Forms
16 resources · 86 operations · 78 MCP tools
Surveys & questions
Responses & export
Integrations
Distribution
Media
Identity
Every resource and operation above deep-links to the Yandex API reference: 318 of 334 operations resolve to their own endpoint page and 15 to their resource's page. No public API reference exists yet for tracker.linktypes, tracker.linktypes.list, shown as plain text. See CONTRIBUTING.md for the intentional exclusions (UI-only endpoints with no public REST API) and per-method notes.
Layout
Development
See CONTRIBUTING.md for conventions and how to add an endpoint. Contributions welcome.
License
MIT © 2026 Sava Znatnov
來源:README.md,提交 834801d
工具
0版本歷史
1- v0.36.0最新Oct 2, 2026
