application-tracker
Enables AI agents to manage job applications, documents, and contacts via the Application Tracker workspace, with read-only or write access controlled by administrator settings.
README
Application Tracker
Application Tracker is a self-hosted workspace for recording job applications, documents, follow-up actions, contacts, and outcomes. It combines a responsive web interface with optional local and authenticated remote Model Context Protocol (MCP) access.
The application stores its data in SQLite and sends no workspace content to a hosted service. A fresh installation contains no account, sample data, or default password.
Features
- Dashboard metrics, searchable applications, sortable tables, detail drawers, modal editing, contacts, links, due actions, and immutable history
- Configurable statuses, sources, role types, and document types
- Local administrator and member accounts with revocable sessions
- Original document storage, SHA-256 deduplication, application associations, inline PDF viewing, bounded DOCX and email previews, and safe downloads
- Bounded email-link extraction without server-side network requests or stored email bodies
- Local stdio MCP and authenticated Streamable HTTP MCP with bounded application and document transfer, explicit actor binding, website-controlled write access, and immutable audit events
- Built-in remote MCP OAuth using local accounts, plus administrator-managed client IDs and one-time bearer tokens and optional external token verification
- Online SQLite backup, verification, non-overwriting restore, and forward migrations
Application Tracker does not yet provide OpenID Connect browser login. Local password login always remains available.
Security model
- First-run setup requires an operator-generated one-time token.
- The project never creates
admin/adminor another known credential. - Passwords use salted, memory-hard scrypt hashes; random session and MCP tokens are stored only as hashes.
- Every application, document, user, and MCP operation preserves workspace and role checks in shared application services.
- Runtime secrets, databases, backups, and machine configuration remain outside Git and container images.
Read the product contract, architecture, and security model for the complete boundary.
Requirements
- Node.js 22.12 or newer for a direct installation
- Docker Engine with the Compose plugin for a container installation
- A trusted HTTPS reverse proxy for Internet access
Quick start for development
cp .env.example .env
npm ci
npm run dev
Open http://<server-ip>:5173, replacing <server-ip> with an address assigned
to the host. The development server and backend listen on all interfaces for
LAN and container access. Restrict both ports with the host firewall, and never
use Vite as a public reverse proxy.
Generate a setup token with openssl rand -hex 32, place it in .env, and
follow the initial administrator setup. Remove the token
and restart the service after setup succeeds.
Run every local quality gate with:
npm run check
Deploy
Choose one supported path:
Both guides keep data and secrets outside the checkout. The container example publishes port 3333 on loopback by default; LAN exposure requires an explicit override. Internet exposure requires HTTPS at a trusted reverse proxy.
Before upgrades, create an online backup and follow the backup and restore runbook. Copying a live WAL database file is not a valid backup.
MCP
Local clients should follow the stdio guide. Remote clients should follow the authenticated HTTPS guide.
Settings → MCP provides copyable templates for Claude.ai, remote Codex, local Codex, and Claude Desktop. Remote interactive clients use the built-in OAuth flow and the same local username and password as the website; no Authentik or other external identity provider is required.
Fresh workspaces are read-only through MCP. An administrator can enable Read and write under Settings → MCP. The server rechecks this policy on every mutation, including calls made through existing sessions.
Job-email agent skill
The repository includes the installable Application Tracker Job Email skill. It teaches compatible AI clients how to reconcile messages from an Outlook Jobs folder with Application Tracker through the server's deterministic match and idempotent email-upsert tools, while stopping when evidence is ambiguous or conflicting.
The skill discovers an already-connected
@softeria/ms-365-mcp-server instance by its live mail-tool capabilities, so
users may name or host it however they choose and may use HTTP or stdio
transport. The workflow requires a stable internetMessageId, attachment
metadata, and bounded download tools. Agents must not silently install or
launch a second M365 server when no compatible tool surface is attached.
Codex discovers the skill from .agents/skills while working in this checkout.
Other clients that support SKILL.md skills can install the
.agents/skills/application-tracker-job-email directory using their normal
skill installation flow. Connect both an Application Tracker MCP server and a
Softeria Microsoft 365 MCP server before invoking
$application-tracker-job-email; their local names and URLs do not matter.
Documentation
- Development standards
- Database and migrations
- Documents and previews
- Reference lists
- User management
- MCP status
- MCP data transfer
- Capability checklist
Contributing and security
Contributions are welcome through pull requests. Read the contribution guide before submitting code. Report suspected vulnerabilities through the private process in the security policy, not a public issue.
License
Application Tracker is source-available under the Elastic License 2.0. You may use, modify, and redistribute it, but you may not provide the software to third parties as a hosted or managed service that exposes a substantial set of its features.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.