Skip to content
Last updated

Asana integration

Asana is a work management platform that helps teams organize, track, and manage their tasks and projects.

It can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:

  • Official — Agen.co connects through Asana's own hosted MCP server, so your AI agents get access to tasks, projects, teams, and more through Asana's native OAuth flow.
  • In-house — Agen.co wraps the Asana API directly through its own integration layer, using an OAuth app you register in the Asana developer console.

Pick Official if the built-in MCP tools cover what your agents need. Fall back to In-house if you need broader API coverage.


Connect via the official MCP server

Prerequisites

  1. In Agen.co, go to Connectors → My connectors, click Add connector, search for Asana, and select it. At the top of the Add Asana panel, keep Official selected — the same card also opens the In-house flow. Keep this panel open — you'll need the Callback URL and Gateway callback URL it displays in the next steps.
  2. In the Instance Slug field, enter a slug for this connector instance — it prefixes each imported tool as slug__tool, so a second instance of the same connector needs a slug of its own. Use lowercase kebab-case. You can change it later from the connector's settings.
  3. Go to the Asana developer console and sign in.
  4. Click Create new app. Select Asana MCP as the app type, enter a name (for example, Agen.co Asana MCP), and click Create app.

The app type cannot be worked around later

Only an app registered under the Asana MCP type mints tokens Asana accepts for MCP. Don't pick External MCP, the option next to it: it works in the opposite direction, registering your own MCP server for Asana's AI Teammates to call, and the connector won't work with it. A regular API app authenticates and passes the consent screen normally, and then every MCP request fails with invalid_token: Token audience must be 'mcp-service' for MCP access.

  1. On the app's settings page, copy the Client ID and Client Secret.

Keep your Client Secret safe

Treat the Client Secret like a password: don't share it or commit it to source control. If it's exposed, reset it from the app's OAuth tab by clicking Reset next to the secret, then update it in Agen.co.

  1. Return to the Agen.co panel and fill in the Client ID and Client Secret from step 5.

  2. Go back to Asana. In the left sidebar, click OAuth. Under redirect URIs, click Add redirect URL and add both URLs from the Agen.co panel you opened in step 1:

    • Callback URL — completes the initial OAuth handshake between Agen.co and your Asana app.
    • Gateway callback URL — used by the Agen.co MCP gateway for per-user authorization at runtime.

    Then click Save changes at the bottom of the page.

Add doesn't save the redirect URLs

The Add button in the Add redirect URL dialog only adds the URL to the unsaved form, and the list looks correct until you reload. Without Save changes, both URLs are silently dropped. After saving, reload the page and confirm both URLs are still listed.

  1. In the left sidebar, click Manage distribution. Under Distribution method, choose Specific workspaces and select at least one workspace, or choose Any workspace, then click Save changes. If you choose Specific workspaces without selecting one, sign-in fails with This app is not available to your Asana workspace or organization.
  2. Return to Agen.co and click Connect.
  3. You're redirected to Asana to sign in and approve access.
  4. Return to Agen.co and click Add below the list of tools. Until you do, nothing is imported and the connector is not created — the callback page reports success either way.

Once connected, Asana appears under My connectors with tools spanning:

AreaWhat it covers
TasksCreating, reading, updating, and deleting tasks
ProjectsListing, reading, creating, and managing projects
PortfoliosReading portfolios and the items they contain
Teams & usersReading team and user information
SearchSearching tasks and other objects
Status updatesCreating project status updates and reading status overviews
TemplatesCreating tasks and projects from templates
StoriesReading and creating task comments
AttachmentsReading attachment details
AgentsListing a workspace's Asana AI Teammates and reading an agent's details

The tool list comes from Asana, not from Agen.co, and can include internal or preview tools such as get_project_internal or create_task_preview_v4. It also ships *_confirm and *_preview variants of several write and search tools, such as create_task_confirm and search_tasks_preview. Asana marks the *_confirm tools as invoked by its own widget UI rather than by the model, so leave them out of your policy unless you have a reason to include them. Grant only the tools you intend your agents to use.

Enabling the Asana connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Connect via the Asana API

Asana is a work management platform that helps teams organize, track, and manage their tasks and projects. The Frontegg integration with Asana allows your application to create, update, and manage tasks and projects on behalf of your users using OAuth 2.0.


Prerequisites

  • An Asana account with access to the developer console
  • Permissions to create apps in your Asana workspace

Connect Asana

Step 1: Open the Asana developer console

Go to app.asana.com/0/my-apps and sign in with your Asana account. This is the My apps page where you manage your OAuth applications.

Click Create new app.

Asana developer console

Step 2: Name your app

In the Create new app dialog, enter a name for your application. You can use any name that identifies this integration, for example Frontegg Integration.

Create new app dialog

Step 3: Agree to terms and create the app

Check I agree to the Asana API Terms, then click Create app.

App creation form with terms accepted

Step 4: Copy your credentials

After the app is created, you are taken to the Basic information page. Copy your Client ID — you will need it when configuring the integration in Frontegg.

Your Client Secret is also shown here. Copy it and store it securely — it is only shown once in full.

Basic information page with Client ID and Client Secret

Step 5: Navigate to the OAuth settings

In the left sidebar, click OAuth. This opens the OAuth & permissions page where you configure redirect URLs and permission scopes.

Click Add redirect URL.

OAuth page with Add redirect URL button

Step 6: Add redirect URLs

In the Add redirect URL dialog, enter the following URL and click Add:

https://YOUR_MCP_GATEWAY_URL/integration-callback

Add redirect URL dialog

Step 7: Select permission scopes

Scroll down to the Permission scopes section. Select the following scopes required for the integration:

ScopePermissionDescription
AttachmentsReadRead attachment details
Identity / OpenID ConnectOpenID, Email, ProfileAccess user identity and profile info
ProjectsRead, Write, DeleteManage projects
StoriesRead, WriteRead and create task comments
TagsRead, WriteManage task tags
TasksRead, Write, DeleteManage tasks
TeamsReadRead team information
UsersReadRead user information
WorkspacesReadRead workspace information

Permission scopes — top section

Permission scopes — tasks, stories, and tags

Step 8: Save your changes

Click Save changes. Asana will confirm that your settings were saved successfully.

OAuth page after saving

Configure the Frontegg portal

Once you have obtained your Client ID and Client Secret from the steps above, enter them in the integration configuration page of the Frontegg portal:

  1. Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → Asana.
  2. Enter the Client ID and Client Secret in the corresponding fields.
  3. Select the required scopes.
  4. Click Save.

Keep your credentials secure

Never share or commit your Client Secret to version control.

Additional resources