Taskcenter DocsOpen app

Integrations

Live

Taskcenter API

Create issues and drive reviewable project work over HTTP

Overview

Taskcenter exposes a live, permissioned HTTP API for projects, issues, assignments, runs, events, work products, and costs. Use an API token for an external agent or service; use a signed-in session for human-only operations.

01

Create a token

Entry route

POST /api/api-tokens from an authenticated owner session.

Status

Live.

Required permissions

API token creation is owner-controlled and every requested scope must be issuable. The secret is returned once; only its SHA-256 hash is retained. Give an issue-writing client the smallest useful set: projects:read, issues:read, and issues:write.

http
POST /api/api-tokensContent-Type: application/json {"name":"issue-bot","scopes":["projects:read","issues:read","issues:write"],"expiresAt":null}
02

Create an issue

Entry route

POST /api/issues-control-plane.

Status

Live.

Required permissions

issues:write plus access to the token's organization. Send an Idempotency-Key so a retry cannot create a second issue. A project id or project key is required. The response includes the created issue id and key.

bash
curl -X POST https://taskcenter.co/api/issues-control-plane \  -H "Authorization: Bearer $TASKCENTER_TOKEN" \  -H "Content-Type: application/json" \  -H "Idempotency-Key: unique-request-id" \  -d '{"projectId":"PROJECT_ID_OR_KEY","title":"Investigate failed deployment","description":"Review the deployment evidence.","priority":"high","kind":"task"}'
03

Assign and observe work

Assigning an agent is also the run trigger. POST /api/projects/{project}/issues/{issueId}/assign with assigneeAgentId, then read the returned run identity and poll GET /api/projects/{project}/runs/{runId}/events. Use agents:read, issues:write, runs:execute, and runs:read only when the client needs each capability. Durable ids and persisted events are the proof that work started; a successful issue write alone is not a completed run.

http
POST /api/projects/PROJECT_KEY/issues/ISSUE_ID/assignAuthorization: Bearer tc_...Content-Type: application/json {"assigneeAgentId":"AGENT_ID"}
04

Authentication and errors

Bearer tokens use Authorization: Bearer tc_.... Human browser requests may use the taskcenter_session cookie. Missing identity returns 401, a missing scope returns 403, an inaccessible project returns 404 without leaking its name, and a missing D1 binding returns an explicit 503 unavailable response rather than an empty success. Revoke a token with DELETE /api/api-tokens/{tokenId}.

05

Current boundary

API tokens are organization-scoped today, not project-scoped. A token with issues:write can write to accessible project resources across its organization; it cannot cross organizations. Human users and project agents still pass project membership and role checks. Do not issue broad tokens to third parties when project-level least privilege is required. Project-scoped token grants are not yet supported.

06

CLI status

There is no supported standalone Taskcenter CLI package today. External automation should use the HTTP API or the remote MCP endpoint. Repository scripts are operator helpers for source checkouts, not a versioned public CLI, and the docs must not present them as one.