REST API reference
The AgileHero REST API lets your own scripts and integrations read and change the workspaces, projects, boards, and cards you can access in AgileHero, with exactly your permissions. It signs in the same way the MCP server does, with OAuth: there is no API key to create or leak.
- Base URL
https://api.agilehero.io, every path starts with/v0- Sign-in
- OAuth 2.1 at
https://mcp.agilehero.io, authorization code with PKCE - Scopes
api:readfor every endpoint; addapi:writeto create, change, or delete. Request only what you need.- Permissions
- Your workspace role applies. Observers cannot use the API: a workspace where you are an observer is not listed, and everything in it answers
404 - Rate limits
- 600/min per token, 1,200/min per IP, 60/min without a token;
429+Retry-After - Pagination
{ data, next_cursor }; passnext_cursorascursor; 50 per page, max 200- Errors
- One body,
{ "error": { "code", "message", "details"? } }:400invalid_request ·401unauthorized ·403insufficient_scope ·403forbidden ·404not_found ·422validation_failed ·429rate_limited - Webhooks
- Signed per Standard Webhooks; workspace owners and admins manage the webhook endpoints
- OpenAPI
- agilehero.io/api/openapi.yaml (OpenAPI 3.0)
First request
- Identify your client. Publish a Client ID Metadata Document: a JSON file at an HTTPS URL you control that names your client and its redirect URIs. That URL is your
client_id; there is no registration form and no client secret. The MCP docs explain why AgileHero signs clients in this way. - Get a token. Run the authorization-code flow with PKCE (S256) against
https://mcp.agilehero.io(endpoints in its metadata), sendingresource=https://api.agilehero.io/v0andscope=api:read api:write(or justapi:readfor a read-only script) on both the authorization and the token request. - Call the API.
curl https://api.agilehero.io/v0/me \ -H "Authorization: Bearer <access token>"
{ "id": "k3v9x2mq", "name": "Ada Lovelace", "workspaces": [ { "id": "w7p4n8rt", "name": "Acme", "role": "owner" } ] }
You sign in once, in a browser. Access tokens last an hour; trade the refresh token for a new pair and keep the new refresh token each time. Each refresh token stays valid for 30 days, so a script that runs at least monthly keeps working until you revoke it under Settings → AI clients in the app.
Connecting an AI assistant instead? The MCP server reference covers setup for Claude, ChatGPT, VS Code and other clients, and every agent tool.
| Method | Path | Summary |
|---|---|---|
| GET | /v0/me | The token owner and their workspaces |
| GET | /v0/workspaces | Workspaces the token owner belongs to |
| GET | /v0/workspaces/{workspace_id}/members | Members of a workspace, with their roles |
| GET | /v0/workspaces/{workspace_id}/projects | Projects of a workspace the token owner can see |
| GET | /v0/projects/{project_id}/lists | The lists of a project's board |
| POST | /v0/projects/{project_id}/lists | Create a list |
| PATCH | /v0/lists/{list_id} | Rename a list or change its WIP limit |
| DELETE | /v0/lists/{list_id} | Delete a list |
| GET | /v0/projects/{project_id}/labels | A project's labels |
| POST | /v0/projects/{project_id}/labels | Create a label |
| PATCH | /v0/labels/{label_id} | Rename a label |
| DELETE | /v0/labels/{label_id} | Delete a label |
| GET | /v0/projects/{project_id}/epics | A project's epics |
| GET | /v0/epics/{epic_id} | One epic, with its description |
| GET | /v0/projects/{project_id}/cards | Cards on a project's board |
| POST | /v0/projects/{project_id}/cards | Create a card |
| GET | /v0/cards/{card_id} | One card, with its description, checklists and relations |
| PATCH | /v0/cards/{card_id} | Update a card |
| DELETE | /v0/cards/{card_id} | Delete a card |
| POST | /v0/cards/{card_id}/move | Move a card to a list or the backlog, or reorder it |
| POST | /v0/cards/{card_id}/labels | Put a label on a card |
| DELETE | /v0/cards/{card_id}/labels/{label_id} | Take a label off a card |
| POST | /v0/cards/{card_id}/assignees | Assign a user to a card |
| DELETE | /v0/cards/{card_id}/assignees/{user_id} | Unassign a user from a card |
| GET | /v0/cards/{card_id}/relations | A card's relations to other cards |
| POST | /v0/cards/{card_id}/relations | Relate two cards |
| DELETE | /v0/cards/{card_id}/relations/{relation_id} | Remove a relation |
| GET | /v0/cards/{card_id}/checklists | A card's checklists with their items |
| POST | /v0/cards/{card_id}/checklists | Add a checklist to a card |
| DELETE | /v0/checklists/{checklist_id} | Delete a card checklist and its items |
| POST | /v0/checklists/{checklist_id}/items | Add an item to a card checklist |
| PATCH | /v0/checklist_items/{item_id} | Edit, check or uncheck a checklist item |
| DELETE | /v0/checklist_items/{item_id} | Delete a checklist item |
| GET | /v0/cards/{card_id}/comments | A card's comments |
| POST | /v0/cards/{card_id}/comments | Comment on a card |
| GET | /v0/webhook_endpoints | A workspace's webhook endpoints |
| POST | /v0/webhook_endpoints | Subscribe an endpoint (REST Hooks subscribe) |
| GET | /v0/webhook_endpoints/sample | A sample event body (REST Hooks perform list) |
| DELETE | /v0/webhook_endpoints/{webhook_endpoint_id} | Unsubscribe an endpoint (REST Hooks unsubscribe) |
| GET | /.well-known/oauth-protected-resource | OAuth protected-resource metadata (RFC 9728) |
Start with two seats, free forever
Every plan begins as a 14-day trial of every premium module. Set up your first project in minutes.
Try it for free14-day free trial · no credit card required