Integrations
LiveTaskcenter API
Create issues and drive reviewable project work over HTTP
Overview
Taskcenter exposes a live, permissioned HTTP API for projects, issues, assignments, runs, events, work products, and costs. Use an API token for an external agent or service; use a signed-in session for human-only operations.
Create a token
Entry route
POST /api/api-tokens from an authenticated owner session.
Status
Live.
Required permissions
API token creation is owner-controlled and every requested scope must be issuable. The secret is returned once; only its SHA-256 hash is retained. Give an issue-writing client the smallest useful set: projects:read, issues:read, and issues:write.
POST /api/api-tokensContent-Type: application/json {"name":"issue-bot","scopes":["projects:read","issues:read","issues:write"],"expiresAt":null}Create an issue
Entry route
POST /api/issues-control-plane.
Status
Live.
Required permissions
issues:write plus access to the token's organization. Send an Idempotency-Key so a retry cannot create a second issue. A project id or project key is required. The response includes the created issue id and key.
curl -X POST https://taskcenter.co/api/issues-control-plane \ -H "Authorization: Bearer $TASKCENTER_TOKEN" \ -H "Content-Type: application/json" \ -H "Idempotency-Key: unique-request-id" \ -d '{"projectId":"PROJECT_ID_OR_KEY","title":"Investigate failed deployment","description":"Review the deployment evidence.","priority":"high","kind":"task"}'Assign and observe work
Assigning an agent is also the run trigger. POST /api/projects/{project}/issues/{issueId}/assign with assigneeAgentId, then read the returned run identity and poll GET /api/projects/{project}/runs/{runId}/events. Use agents:read, issues:write, runs:execute, and runs:read only when the client needs each capability. Durable ids and persisted events are the proof that work started; a successful issue write alone is not a completed run.
POST /api/projects/PROJECT_KEY/issues/ISSUE_ID/assignAuthorization: Bearer tc_...Content-Type: application/json {"assigneeAgentId":"AGENT_ID"}Authentication and errors
Bearer tokens use Authorization: Bearer tc_.... Human browser requests may use the taskcenter_session cookie. Missing identity returns 401, a missing scope returns 403, an inaccessible project returns 404 without leaking its name, and a missing D1 binding returns an explicit 503 unavailable response rather than an empty success. Revoke a token with DELETE /api/api-tokens/{tokenId}.
Current boundary
API tokens are organization-scoped today, not project-scoped. A token with issues:write can write to accessible project resources across its organization; it cannot cross organizations. Human users and project agents still pass project membership and role checks. Do not issue broad tokens to third parties when project-level least privilege is required. Project-scoped token grants are not yet supported.
CLI status
There is no supported standalone Taskcenter CLI package today. External automation should use the HTTP API or the remote MCP endpoint. Repository scripts are operator helpers for source checkouts, not a versioned public CLI, and the docs must not present them as one.