How to Connect the Asana MCP Server With Your Own OAuth App
Register an Asana MCP app, connect it to Spojit as a custom server, then turn inbound requests into Asana tasks from a workflow.
What This Integration Does
Asana hosts a V2 MCP server that gives agents access to the Asana Work Graph: tasks, projects and portfolios in the workspaces you authorize. Unlike servers that support one-click sign-in, Asana requires you to register an app in its developer console first, so the connection uses an OAuth application you own and control. This is the bring-your-own-app route, and the same shape applies to Slack, Box, Zoom, Salesforce, HubSpot and Dynamics 365.
Once connected, the workflow in this tutorial takes an inbound request, decides whether it is actionable, and creates an Asana task with a useful title and description. It runs on a webhook so you can point a form, an email parser, or another workflow at it. Creating a task is a write, so the run is not idempotent: if the caller retries, you get a second task unless you guard against it, which Step 6 covers.
Prerequisites
- An Asana account with permission to create an app in the developer console.
- The Asana workspace and project you want tasks created in.
- Permission to add connections in Spojit.
Step 1: Copy Spojit's Redirect URI
In Spojit, go to Connections, click Add custom server, and choose OAuth 2.0. Copy the Redirect URI shown in the form, which is https://miraxa.spojit.com/api/connectors/oauth/callback. The form has a copy button; use it rather than retyping, because Asana rejects a redirect that does not match exactly. Leave this tab open.
Step 2: Create an Asana MCP App
Open the Asana developer console at My apps and click Create new app. Enter a name such as Spojit, select MCP app as the type, and create it. Copy the Client ID and Client secret.
On the app's OAuth tab, add Spojit's redirect URI from Step 1.
Step 3: Choose Where the App Is Available
Under Manage distribution, choose Specific workspaces and select yours, or Any workspace. This step is easy to skip and it is the most common reason the connection fails: without at least one workspace selected, sign-in fails with "This app is not available".
Step 4: Add the Custom Server in Spojit
Back in Add custom server, enter:
- Name:
Asana. - Server URL:
https://mcp.asana.com/v2/mcp - Authentication: choose Auto and click Save & connect.
Because Asana needs your own app, Spojit discovers that automatic registration is not available and opens the OAuth 2.0 form with the authorization and token URLs already filled in. Paste the Client ID and Client Secret from Step 2 and click Save & connect. Asana opens its authorization page: choose the workspace and allow access.
If the form does not prefill, choose OAuth 2.0 and enter Authorization URL https://app.asana.com/-/oauth_authorize and Token URL https://app.asana.com/-/oauth_token. Asana MCP apps need no specific scopes.
Step 5: Build the Workflow
Create a workflow with a Webhook trigger and copy the URL it generates. Add a Condition node that drops anything without the fields you need, so malformed calls do not reach Asana. Then add a Connector node, select your Asana server from the Custom Servers section, and set it to Agent Mode with a prompt like:
You have Asana tools available. From this request:
{{ trigger.body }}
1. Decide whether it describes actionable work. If it does not,
reply with "skipped" and do nothing else.
2. If it does, create a task in the project named "Inbound requests".
Title: a short imperative summary, under 60 characters.
Description: the original request plus who it came from.
3. Reply with the task title and its URL.
Step 6: Guard Against Duplicates
Creating a task is a write, so a retried webhook creates a second task. Include a stable identifier from the caller in the task title or description, for example a request id, and have the prompt search for it before creating. Add this to the prompt above:
Before creating anything, search Asana for a task whose description
contains the request id. If one exists, reply with its URL instead
of creating a duplicate.
Then add a Response node so the caller receives the task URL rather than an empty acknowledgement.
Tips
- Asana access tokens last one hour. Spojit refreshes them automatically, so this only matters if a connection sits unused and the refresh token itself is revoked in Asana.
- Use Organization visibility if teammates will build workflows on the same connection, and Private if it should act only for you.
- Have the agent search before it writes on any create-task workflow, not just this one. It is the cheapest form of idempotency.
- Once the task shape is stable, consider moving the create step to Direct Mode to remove the agent cost from every run.
Common Pitfalls
- "This app is not available": the MCP app has no workspaces selected. Fix it under Manage distribution, then click Reconnect on the connection.
- Asana reports an invalid redirect URI: the URI on the app's OAuth tab must match the one Spojit shows exactly, including the scheme and trailing path.
- Changing credentials without reconnecting: saving a new client secret does not re-issue the token. Save, then use Reconnect.
- The agent inventing a project: name the target project exactly as it appears in Asana. If the name is ambiguous across workspaces, say which workspace in the prompt.
Testing
Call the webhook with a single realistic request before pointing anything real at it. Check that the Condition node lets it through, that the Asana node creates one task in the expected project, and that the Response node returns the URL. Then call it a second time with the same payload: the duplicate guard should return the existing task instead of creating another. Only then connect the real source.