Model Context Protocol server for Harvest API integration, providing complete time tracking and project management functionality
Server has 17 tools with visible schemas and descriptions. Naming follows verb_noun pattern (harvest_list_*, harvest_create_*, etc.), which is good. However, descriptions are generic and often defer detailed information to an 'about' tool rather than being self-contained. Most tools have basic parameter descriptions but lack examples of valid values, constraints, enums, or format specifications. Output schemas are not documented, LLMs cannot predict what fields will be returned. No error handling guidance is visible. Tool composition is reasonable (single concerns), but descriptions lack the LLM-optimization details needed for confident tool selection.
Get detailed information about the Harvest MCP server and its tools. Call about without parameters for general info, or with {"tool": "tool_name"} for specific tool documentation.
Create a new time entry. Use about {"tool": "harvest_create_time_entry"} for detailed parameters and examples.
Delete a time entry. Use about {"tool": "harvest_delete_time_entry"} for detailed usage and warnings.
Get information about the authenticated user. Use about {"tool": "harvest_get_current_user"} for detailed response format.
Get details of a specific project. Use about {"tool": "harvest_get_project"} for detailed usage examples.
List all clients with filtering options. Use about {"tool": "harvest_list_clients"} for detailed parameters and examples.
Descriptions lack context for tool selection. Most descriptions (e.g., 'Create a new time entry. Use about {"tool": "harvest_create_time_entry"} for detailed parameters and examples.') defer information to an external 'about' tool instead of being self-contained. LLMs cannot confidently select tools when the description punts key details elsewhere.
Output schemas are not documented. Tools like harvest_list_time_entries and harvest_create_time_entry do not declare what fields will be returned. LLMs cannot plan downstream tool calls or extract required data without knowing the response structure. This forces agents to make assumptions and risks failed downstream operations.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
List project assignments for the current user. Use about {"tool": "harvest_list_project_assignments"} for detailed usage.
List all projects with filtering options. Use about {"tool": "harvest_list_projects"} for detailed parameters and examples.
List task assignments for a project. Use about {"tool": "harvest_list_task_assignments"} for detailed workflow and examples.
List all tasks with filtering options. Use about {"tool": "harvest_list_tasks"} for detailed parameters and examples.
List time entries with optional filters. Use about {"tool": "harvest_list_time_entries"} for detailed usage examples.
List all users in the account with filtering. Use about {"tool": "harvest_list_users"} for detailed parameters and examples.
Restart a stopped time entry timer. Use about {"tool": "harvest_restart_timer"} for detailed workflow and examples.
Stop a running time entry timer. Use about {"tool": "harvest_stop_timer"} for detailed workflow and examples.
Generate detailed time reports for date ranges. Use about {"tool": "harvest_time_report"} for filtering options and examples.
Update an existing time entry. Use about {"tool": "harvest_update_time_entry"} for detailed parameters and examples.
Get version information about the Harvest MCP server.
Parameter descriptions lack constraint details. Numeric parameters like 'page' and 'per_page' have no min/max bounds, format strings like 'spent_date' do not state the strict YYYY-MM-DD requirement, and no enums are declared for constrained fields. Free-form strings invite hallucinated values and invalid API calls.
No error handling or recovery guidance. Tools return no documentation on what errors are possible (e.g., 'project_id not found', 'authentication failed'), how to classify them (retryable vs. user-fixable), or what the agent should do next. Raw errors or stack traces provide no actionable guidance.
Destructive tools (harvest_delete_time_entry) lack confirmation or dry-run support. No dry-run parameter, no confirmation step, and no explicit documentation that this operation is irreversible. Agents may delete entries unintentionally.
Tool 'version' has minimal description (5 characters: 'Get version information about the Harvest MCP server.'). While not below 20 characters, it provides no context for when an LLM should call it or what it returns. This is borderline inadequate.
Pagination details are sparse. Tools like harvest_list_time_entries accept 'page' and 'per_page' parameters but do not document whether pagination is cursor-based or offset-based, what the maximum per_page is (spec says 'max 100', but this is buried in the description, not a JSON Schema constraint), or whether a 'total' or 'next_cursor' is returned. LLMs cannot reliably paginate without these details.
No permission or scope declarations. Tools do not document what permissions they require (e.g., 'read:time_entries', 'write:time_entries'). This prevents least-privilege agent configuration and complicates audit trails.