Integrations · On every plan
IntegrationsConnect AgileHero to the tools your team runs on.
Push board changes into the tools you already use, pull work in from them, and automate the steps in between: a REST API for your scripts and apps, webhooks for 28 kinds of change, both on every plan. Slack, GitHub and others are on the way.
What you can build
React to what happens on the board
Point a webhook at your endpoint and pick the changes it should hear about: a card moved, a comment added, someone assigned, an epic updated. Post it to your team chat, update a dashboard or a sheet, kick off a deploy pipeline — each delivery is signed, retried and logged, so your automation can trust it.
Bring work in from other tools
Use the REST API to create cards from support tickets, incidents or forms, set their labels, assignees and checklists, and move them as your pipeline finishes. Read projects, epics and cards with cursor pagination and an updated_since filter to keep another system in step.
Connect securely, revoke cleanly
Your scripts and apps sign in with OAuth 2.1 — the modern standard, and a safer one than long-lived tokens: access is short-lived, scoped to reading or writing, bounded by the permissions of the person who approved it, and revocable per app under Settings → API access.
What is under the hood
Webhooks for 28 kinds of change
Cards created, updated, moved, deleted, labelled, assigned; comments, epics, lists, labels and checklist items; people joining or leaving a project. Filter by event and by project, so each endpoint hears only what it needs.
A full card lifecycle over the API
Create, update, move and delete cards; manage labels, assignees, relations, checklists and comments; read workspaces, projects, members and epics. Every id is the public uid you see in the app, every list page comes with a cursor.
Built for your own automations
Payloads carry the resource as it looks after the change, what changed, who did it and where it came from — the app, an AI agent or the API — so a receiver rarely needs a follow-up call. Apps can register their own endpoints over the API, the same way automation platforms subscribe.
Reliable delivery
Eight attempts over about 28 hours, only a 2xx counts, and an endpoint that keeps failing is disabled with an email to the workspace admins. The log keeps 30 days of deliveries with status and timing; one click redelivers, one button sends a test event.
Verifiable with a standard library
Deliveries are signed to the Standard Webhooks spec — webhook-id, webhook-timestamp and an HMAC-SHA256 signature with a per-endpoint secret you can rotate — so any off-the-shelf verifier checks them. HTTPS only; private and local addresses are refused.
Every plan, no metering
No per-action quotas, on Free as on Pro: a webhook that fires ten thousand times a month costs the same as one that fires twice. Free workspaces get two webhook endpoints and 150 API requests a minute per app; trial and Pro get twenty endpoints and 600 a minute. API authorizations are never capped.
Why integrations are built this way
A project tool earns its place by fitting the tools around it — the chat where the team talks, the pipeline that ships the work, the help desk where requests arrive. AgileHero's integrations start with the general mechanism rather than a short list of named apps: a REST API for anything that needs to read or change your projects, and webhooks for anything that needs to know when something changed. Both speak open standards — plain JSON over OAuth, deliveries signed to the Standard Webhooks spec — so the automation platform or internal script your team already uses can plug in without an adapter.
Two decisions shape the rest. Nothing is metered: integrations are on every plan, including Free, with no per-action quota, because charging by the webhook is the pattern teams resent most. And access is OAuth 2.1 rather than personal API keys — the modern standard and the safer one, with short-lived, scoped, per-app grants you can revoke without touching anything else. What you get today is the API (v0 — complete and tested, still allowed to change before it becomes v1) and the webhooks; there is no app directory yet. Slack, GitHub and others are on the way, built on exactly this mechanism.
What the v0 API covers
Read: /v0/me, workspaces, a workspace's projects and members, a project's epics and single epics. Write: cards end to end — create, update, move, delete — with labels, assignees, relations, checklists and checklist items; lists and labels per project; comments on cards; and your own webhook endpoints, so an app can subscribe and unsubscribe itself. Responses use cursor pagination (cursor and limit, 50 by default, 200 at most) and every id is the public uid you see in the app.
Not in v0 yet: writing epics, projects or workspaces, and editing or deleting comments. The full reference, every endpoint and the OpenAPI document are at agilehero.io/docs/api; AI assistants connect through the MCP server instead, with its own scope, so an API grant never becomes agent-grade access or the reverse.
Common questions
What can I connect AgileHero to?
Anything that can call an HTTPS API or receive a signed POST: your own scripts and internal tools, a deploy pipeline, a help desk, a dashboard, or the automation platform your team already uses. Webhooks push changes out; the REST API lets other systems read and change projects and cards.
Which plans include integrations?
Every plan, including Free, with no per-action metering. Free workspaces can register two webhook endpoints and get 150 API requests a minute per app; trial and Pro workspaces get twenty endpoints and 600 requests a minute. API authorizations are never capped.
Which events do webhooks send?
28 event types, named resource.action: card.created, card.updated, card.moved, card.deleted, card.assigned and the label and assignee changes; comment, epic, list, label and checklist-item events; project and workspace membership changes. Retrospectives send no events. There is no ordering guarantee — use the occurred_at timestamp.
How does an app authenticate?
With OAuth 2.1, the same sign-in your AI clients use — the modern standard, and a safer one than long-lived personal tokens, which AgileHero does not issue. The app gets short-lived access scoped to api:read or api:write and bounded by the permissions of the person who approved it; you see and revoke every grant under Settings → API access.
Is the API stable?
It is v0: complete and tested, but endpoints can still change — not always backwards-compatibly — before it becomes v1. When it does, v0 stays available for a migration window announced in advance. The reference at agilehero.io/docs/api carries a changelog.
How are webhooks secured?
Endpoints must be HTTPS, private and local addresses are refused, and the destination is checked again at every send. Each delivery is signed to the Standard Webhooks spec with a per-endpoint secret that is shown once and can be rotated.
Do you integrate with Slack, GitHub or automation platforms?
Slack, GitHub and others are on the way. There is no app directory yet — today the REST API and the webhooks are the integration surface, and they work with anything that can call an HTTPS API or receive a signed POST.
Can an observer use the API?
No. Read-only observers have no API access at all; a workspace they only observe answers as if it did not exist. The same rule applies to the MCP server.
Start with two seats, free forever
Every plan begins as a 14-day trial of every premium module. Set up your first project in minutes.
Try it for free14-day free trial · no credit card required