AgileHero

REST API reference

The AgileHero REST API lets your own scripts and integrations read and change the workspaces, projects, boards, and cards you can access in AgileHero, with exactly your permissions. It signs in the same way the MCP server does, with OAuth: there is no API key to create or leak.

Base URL
https://api.agilehero.io, every path starts with /v0
Sign-in
OAuth 2.1 at https://mcp.agilehero.io, authorization code with PKCE
Scopes
api:read for every endpoint; add api:write to create, change, or delete. Request only what you need.
Permissions
Your workspace role applies. Observers cannot use the API: a workspace where you are an observer is not listed, and everything in it answers 404
Rate limits
600/min per token, 1,200/min per IP, 60/min without a token; 429 + Retry-After
Pagination
{ data, next_cursor }; pass next_cursor as cursor; 50 per page, max 200
Errors
One body, { "error": { "code", "message", "details"? } }: 400 invalid_request · 401 unauthorized · 403 insufficient_scope · 403 forbidden · 404 not_found · 422 validation_failed · 429 rate_limited
Webhooks
Signed per Standard Webhooks; workspace owners and admins manage the webhook endpoints
OpenAPI
agilehero.io/api/openapi.yaml (OpenAPI 3.0)

First request

  1. Identify your client. Publish a Client ID Metadata Document: a JSON file at an HTTPS URL you control that names your client and its redirect URIs. That URL is your client_id; there is no registration form and no client secret. The MCP docs explain why AgileHero signs clients in this way.
  2. Get a token. Run the authorization-code flow with PKCE (S256) against https://mcp.agilehero.io (endpoints in its metadata), sending resource=https://api.agilehero.io/v0 and scope=api:read api:write (or just api:read for a read-only script) on both the authorization and the token request.
  3. Call the API.
    curl https://api.agilehero.io/v0/me \
      -H "Authorization: Bearer <access token>"
    {
      "id": "k3v9x2mq",
      "name": "Ada Lovelace",
      "workspaces": [
        { "id": "w7p4n8rt", "name": "Acme", "role": "owner" }
      ]
    }

You sign in once, in a browser. Access tokens last an hour; trade the refresh token for a new pair and keep the new refresh token each time. Each refresh token stays valid for 30 days, so a script that runs at least monthly keeps working until you revoke it under Settings → AI clients in the app.

Endpoints
MethodPathSummary
GET/v0/meThe token owner and their workspaces
GET/v0/workspacesWorkspaces the token owner belongs to
GET/v0/workspaces/{workspace_id}/membersMembers of a workspace, with their roles
GET/v0/workspaces/{workspace_id}/projectsProjects of a workspace the token owner can see
GET/v0/projects/{project_id}/listsThe lists of a project's board
POST/v0/projects/{project_id}/listsCreate a list
PATCH/v0/lists/{list_id}Rename a list or change its WIP limit
DELETE/v0/lists/{list_id}Delete a list
GET/v0/projects/{project_id}/labelsA project's labels
POST/v0/projects/{project_id}/labelsCreate a label
PATCH/v0/labels/{label_id}Rename a label
DELETE/v0/labels/{label_id}Delete a label
GET/v0/projects/{project_id}/epicsA project's epics
GET/v0/epics/{epic_id}One epic, with its description
GET/v0/projects/{project_id}/cardsCards on a project's board
POST/v0/projects/{project_id}/cardsCreate a card
GET/v0/cards/{card_id}One card, with its description, checklists and relations
PATCH/v0/cards/{card_id}Update a card
DELETE/v0/cards/{card_id}Delete a card
POST/v0/cards/{card_id}/moveMove a card to a list or the backlog, or reorder it
POST/v0/cards/{card_id}/labelsPut a label on a card
DELETE/v0/cards/{card_id}/labels/{label_id}Take a label off a card
POST/v0/cards/{card_id}/assigneesAssign a user to a card
DELETE/v0/cards/{card_id}/assignees/{user_id}Unassign a user from a card
GET/v0/cards/{card_id}/relationsA card's relations to other cards
POST/v0/cards/{card_id}/relationsRelate two cards
DELETE/v0/cards/{card_id}/relations/{relation_id}Remove a relation
GET/v0/cards/{card_id}/checklistsA card's checklists with their items
POST/v0/cards/{card_id}/checklistsAdd a checklist to a card
DELETE/v0/checklists/{checklist_id}Delete a card checklist and its items
POST/v0/checklists/{checklist_id}/itemsAdd an item to a card checklist
PATCH/v0/checklist_items/{item_id}Edit, check or uncheck a checklist item
DELETE/v0/checklist_items/{item_id}Delete a checklist item
GET/v0/cards/{card_id}/commentsA card's comments
POST/v0/cards/{card_id}/commentsComment on a card
GET/v0/webhook_endpointsA workspace's webhook endpoints
POST/v0/webhook_endpointsSubscribe an endpoint (REST Hooks subscribe)
GET/v0/webhook_endpoints/sampleA sample event body (REST Hooks perform list)
DELETE/v0/webhook_endpoints/{webhook_endpoint_id}Unsubscribe an endpoint (REST Hooks unsubscribe)
GET/.well-known/oauth-protected-resourceOAuth protected-resource metadata (RFC 9728)

Start with two seats, free forever

Every plan begins as a 14-day trial of every premium module. Set up your first project in minutes.

Try it for free

14-day free trial · no credit card required