Permanent Access Token authentication
Use a Wrike Permanent Access Token to authenticate Wrike MCP when OAuth is not appropriate for your use case.
Permanent Access Tokens are most useful for:
- individual testing
- scripts and automation
- headless or non-interactive environments
- MCP clients that support custom authorization headers
For interactive connections used by multiple users, OAuth 2.0 or an official Wrike marketplace connector is recommended.
How Permanent Access Tokens work
A Permanent Access Token belongs to an individual Wrike user and inherits that user's permissions.
Unlike an OAuth application, which can be configured once and used by multiple users who authenticate individually, a Permanent Access Token represents the specific user who generated it.
Treat the token like a password.
Generate a Wrike Permanent Access Token
-
Open Wrike.
-
Click your profile icon and select Apps & Integrations.
-
Open the API tab.
-
Create a new app or open an existing app.
-
Enter a name for the integration, for example:
Wrike MCP Integration -
Find the Permanent access token section.
-
Click Create token or Get token.
-
Copy and securely store the generated token.
-
Save the application.
Store the token securely. Anyone with access to the token can act with the Wrike permissions of the user who generated it.
Connect to Wrike MCP
Use the Wrike MCP v2 endpoint:
https://mcp.wrike.com/v2Send your token using the HTTP Authorization header:
Authorization: Bearer YOUR_ACCESS_TOKENReplace YOUR_ACCESS_TOKEN with your Wrike Permanent Access Token.
The exact configuration depends on your MCP client.
If your MCP client supports custom HTTP headers directly, configure the Authorization header there.
If your client requires a local MCP command or proxy to add HTTP headers, follow that client's documentation for connecting to a remote MCP server with bearer-token authentication.
Example using mcp-remote
For MCP clients that require a local stdio command, you can use mcp-remote to connect to the remote Wrike MCP server:
{
"mcpServers": {
"wrike": {
"command": "npx",
"args": [
"mcp-remote",
"https://mcp.wrike.com/v2",
"--header",
"Authorization:Bearer YOUR_ACCESS_TOKEN"
]
}
}
}Replace YOUR_ACCESS_TOKEN with your Wrike Permanent Access Token.
Use this configuration only for clients that require a local MCP command. Clients that support remote MCP servers and custom HTTP headers can connect directly to
https://mcp.wrike.com/v2.
Permissions
The Permanent Access Token inherits all permissions of the Wrike user who created it.
Wrike MCP can only access data and perform actions that this user is authorized to access or perform.
If the user's permissions change in Wrike, the effective access available through the token changes accordingly.
Security recommendations
- Treat Permanent Access Tokens like passwords.
- Never commit tokens to source control.
- Store tokens in a secure secrets manager or credential store when possible.
- Do not share tokens between users.
- Revoke a token immediately if you suspect it has been exposed.
- Generate a separate token when you need to isolate integrations or environments.
When to use OAuth instead
Use OAuth 2.0 instead of a Permanent Access Token when:
- multiple users need to connect
- users should authenticate with their own Wrike identities
- your MCP client supports OAuth
- you want users to connect without manually managing API tokens
See Connect Wrike MCP as a custom connector for OAuth setup instructions.
Updated 16 days ago