abletime.comOpen App

MCP Authentication

Connecting an Agent only takes a few minutes: switch on agent access for your organization, create your personal access key, and either give your Agent host that key or approve the connection in your browser when the host asks.

Only an admin or owner can enable or disable agent access. Any member can create their own personal access key anytime — it starts working as soon as an administrator enables agent access.

1. Enable agent access

Open Settings → Integrations → API Keys. Above the key list you'll find the Agent access (MCP) switch, which controls whether members' personal access keys can be used by agent integrations. Set it to Enabled.

2. Create a personal access key

Open My Profile, go to the API Access tab and click Create access key. The key is shown only once, so store it wherever your Agent host will use it. If you lose it, Rotate creates a new key and the old one stops working immediately — any host you gave the old key needs the new one. Personal access keys are covered in full under Documentation → API → Authentication.

3. Point your host at AbleTime

Give your Agent host (Cursor, Claude Code, Claude, or any app that takes a server URL) your AbleTime site address followed by the path of the connection you want. The work connection — recording time and working the tasks it is recorded against — is:

/api/public/v2/mcp

The board connection, for running the board — assignment, priority, scheduling, epics and milestones — is a separate server entry:

/api/public/v2/mcp/pm

If you'd rather add a single entry, the combined connection carries the work and board tools together:

/api/public/v2/mcp/full

Intelligence Reports are a separate connection that only reads. It is never part of the others, so add it as its own server entry when you want your Agent to read reports:

/api/public/v2/mcp/reports

The same key works for every connection. If your host takes the key directly, it goes in the Authorization header:

Authorization: Bearer <your personal access key>

Only a personal access key can connect an Agent; an organization API key cannot. The key carries your identity and your role: what the Agent may do is decided by who you are and which projects you belong to, exactly as it would be in the application.

...or approve the connection from your Agent host

Hosts such as Claude and Cursor can connect without a pasted key. Add the server address alone and the host opens Connect to AbleTime in your browser. Sign in if you need to; the page then names the app that is asking to connect, and you choose Approve or Deny. A desktop host such as Cursor registers itself, so the page notes that its name is not verified; an app hosted on the web shows its web address instead. The connection works in the organization you are signed in to when you approve. Each server entry you add is approved on its own, so adding the Reports connection, or the board connection as a separate entry, brings you back to this page.

An approved connection acts through your personal access key, so you still need one in that organization, and the organization's Agent access (MCP) switch must be on. Rotating your key does not disconnect an approved app: to cut one off, remove the connection in the app that made it, or have an administrator turn Agent access (MCP) off, which stops every agent in the organization.

4. The Agent calls orientation first

When the host connects, AbleTime tells the Agent to call orientation before anything else. Orientation is how the Agent learns who it's acting as — your open drafts, recent time, active tasks and projects, and the rules for recording work here.

An Agent that skips orientation is missing the recording rules and does not know about your open drafts.

Next

From here, the Agent records drafts as well as creating and updating tasks. For a step-by-step first session, see Guides → Agentic AI → Connecting Your Agent. Every tool is on MCP Tools, and preferences the Agent keeps across sessions are on Customizing Behavior.

Endpoint shapes, status codes, and request fields are in the API Reference.