API and MCP reference

Tasks

5 operations. Each REST operation is also an MCP tool of the same name. REST https://tlntconnect.com/api/v1

GET/api/v1/tasksTasks the key's member can see, soonest due first; filter by status, priority, creator, assignee, due window.

The tasks the key's member sees on /tasks: admins every task of the workspace; managers the tasks they are assigned or created and the tasks of their assigned creators; other roles the tasks they are assigned or created. Filters: status, priority, creator_id, assigned_to, due_after / due_before (YYYY-MM-DD), completed, q (title). Sorted by due_date (soonest first, undated last); paged with page/limit (limit ≤ 100, default 50).

MCP tool
list_tasks
Scopes
tasks:read
Members
admin, manager, scout, viewer
Idempotency-Key
Ignored (read)
Rate weight
1

Input

limit queryinteger — Page size, default 50.
page queryinteger — 1-based page, default 1.
assigned_to querystring (uuid)
completed queryboolean
creator_id querystring (uuid)
due_after querystring
due_before querystring
priority query"low" | "medium" | "high" | "urgent"
q querystring — Title search.
status query"todo" | "in_progress" | "in_review" | "done"

Responses

200Success
400invalid_input / invalid_json / invalid_id
401missing_token / invalid_token / revoked_token / expired_token
403missing_scope / actor_unavailable / plan_upgrade_required / role_forbidden
404not_found (unknown, cross-workspace or not visible to the key's member)
429rate_limited (honour Retry-After)
500internal_error
POST/api/v1/tasksCreate a task, optionally about a roster creator and assigned to a team member.

Creates a task with the app's rules (the shared status/priority allowlists; normalizeTaskAssignment: admins assign any active member, a manager only themselves and only for creators assigned to them — 403 otherwise; a creator or assignee outside this workspace is 404; portal sharing is off unless visible_to_creator is true on a creator task). Notifies the assignee, like the app. Returns 201 with the task.

MCP tool
create_task
Scopes
tasks:write
Members
admin, manager
Idempotency-Key
optional
Rate weight
1

Input

Idempotency-Key headerstring — Retry-safe key (1-255 printable ASCII; a UUID is recommended; an RFC 8941 quoted string is accepted). The same key with the same request within 24h replays the stored response byte for byte (Idempotent-Replayed: true) without running again; the replay still consumes the operation's rate weight.
assigned_to bodystring (uuid) | null — Team member in this workspace (a manager may only assign themselves).
creator_id bodystring (uuid) | null — Roster creator the task is about (a manager: only their assigned creators).
description bodystring | null
due_date bodystring | null
due_time bodystring | null
priority body"low" | "medium" | "high" | "urgent"
status body"todo" | "in_progress" | "in_review" | "done"
visible_to_creator bodyboolean — Share a creator task in the creator portal (default: not shared).
title body, requiredstring

Responses

201Success
400invalid_input / invalid_json / invalid_id
401missing_token / invalid_token / revoked_token / expired_token
403missing_scope / actor_unavailable / plan_upgrade_required / role_forbidden
404not_found (unknown, cross-workspace or not visible to the key's member)
409idempotency_key_reused / idempotency_in_progress / idempotency_context_changed / idempotency_response_too_large
429rate_limited (honour Retry-After)
500internal_error / idempotent_replay_of_failure
503service_unavailable
GET/api/v1/tasks/{task_id}One task the key's member can see.

One task, with the scope rule of the app (a task outside the member's scope, another workspace's or an unknown id is 404).

MCP tool
get_task
Scopes
tasks:read
Members
admin, manager, scout, viewer
Idempotency-Key
Ignored (read)
Rate weight
1

Input

task_id path, requiredstring (uuid) — Task id in this workspace.

Responses

200Success
400invalid_input / invalid_json / invalid_id
401missing_token / invalid_token / revoked_token / expired_token
403missing_scope / actor_unavailable / plan_upgrade_required / role_forbidden
404not_found (unknown, cross-workspace or not visible to the key's member)
429rate_limited (honour Retry-After)
500internal_error
PATCH/api/v1/tasks/{task_id}Update a task's fields, status or assignment, or complete it (completed: true). Send expected_updated_at.

Partial update with the app's rules (scope, allowlists, assignment, the completed toggle that keeps status and completed_at in step). expected_updated_at (the updated_at from GET /tasks/{id}) is required: missing is 428 expected_updated_at_required, a task changed since is 409 stale_target and nothing is written. A task outside the member's scope is 404.

MCP tool
update_task
Scopes
tasks:write
Members
admin, manager
Idempotency-Key
optional
Rate weight
1

Input

task_id path, requiredstring (uuid) — Task id in this workspace.
Idempotency-Key headerstring — Retry-safe key (1-255 printable ASCII; a UUID is recommended; an RFC 8941 quoted string is accepted). The same key with the same request within 24h replays the stored response byte for byte (Idempotent-Replayed: true) without running again; the replay still consumes the operation's rate weight.
assigned_to bodystring (uuid) | null — Team member in this workspace (a manager may only assign themselves).
creator_id bodystring (uuid) | null — Roster creator the task is about (a manager: only their assigned creators).
description bodystring | null
due_date bodystring | null
due_time bodystring | null
priority body"low" | "medium" | "high" | "urgent"
status body"todo" | "in_progress" | "in_review" | "done"
visible_to_creator bodyboolean — Share a creator task in the creator portal (default: not shared).
completed bodyboolean — true completes the task (status done), false re-opens it.
expected_updated_at bodystring — The record's updated_at as you last read it (ISO 8601). Required on updates: a missing one is 428 expected_updated_at_required, an older one 409 stale_target.
title bodystring

Responses

200Success
400invalid_input / invalid_json / invalid_id
401missing_token / invalid_token / revoked_token / expired_token
403missing_scope / actor_unavailable / plan_upgrade_required / role_forbidden
404not_found (unknown, cross-workspace or not visible to the key's member)
409stale_target / idempotency_key_reused / idempotency_in_progress / idempotency_context_changed / idempotency_response_too_large
428expected_updated_at_required
429rate_limited (honour Retry-After)
500internal_error / idempotent_replay_of_failure
503service_unavailable
DELETE/api/v1/tasks/{task_id}Delete a task. Runs directly within the daily delete cap unless this credential asks for approval in TLNT for deletes (202 pending_approval).

Deletes one task the key's member may manage (the app's scope rule; out of scope is 404). A `delete`-class action (tasks:read + delete): by default it deletes at once (200 { status: "deleted" }) within the credential's daily delete cap. When the credential asks for approval in TLNT for deletes, the call answers 202 { status: "pending_approval", action_id, approval_url } instead and an admin or manager approves or rejects it in TLNT (the Atlas task.delete action); poll GET /actions/{action_id}. With expected_updated_at, a task changed since is 409 stale_target.

MCP tool
delete_task
Scopes
tasks:read + delete
Members
admin, manager
Approval
Runs directly; queued when the credential asks for approval for delete
Idempotency-Key
required
Rate weight
1

Input

task_id path, requiredstring (uuid) — Task id in this workspace.
expected_updated_at querystring — The record's updated_at as you last read it. Optional: when given, a record changed since then is refused (409 stale_target). In a query string, URL-encode it (+ as %2B).
Idempotency-Key header, requiredstring — Retry-safe key (1-255 printable ASCII; a UUID is recommended; an RFC 8941 quoted string is accepted). The same key with the same request within 24h replays the stored response byte for byte (Idempotent-Replayed: true) without running again; the replay still consumes the operation's rate weight.

Responses

200Success
202pending_approval — queued for approval in TLNT (only when the credential asks for approval for this action class; it runs directly by default)
400invalid_input / invalid_json / invalid_id / idempotency_key_required
401missing_token / invalid_token / revoked_token / expired_token
403missing_scope / actor_unavailable / plan_upgrade_required / role_forbidden
404not_found (unknown, cross-workspace or not visible to the key's member)
409stale_target / idempotency_key_reused / idempotency_in_progress / idempotency_context_changed / idempotency_response_too_large
429rate_limited (honour Retry-After) / daily_delete_cap_reached
500internal_error / idempotent_replay_of_failure
503service_unavailable