The apsio CLI
An agent with a shell, such as Claude Code, Codex or Cursor’s terminal, can use theapsio CLI (version 0.2.0 or later) with a project token in APSIO_TOKEN:
--jsonprints the API’s JSON, and--jqfilters it inside the CLI, so the agent reads only the fields it needs.-rprints strings without quotes.- Exit codes are stable (0 success, 1 network or server, 2 usage, 3 not authenticated, 4 bad input, 5 not found), and no command prompts when it is not attached to a terminal.
apsio issue open <id>prints the console URL, so the agent can link a person to the evidence.
Skills
Theapsio-skills repository holds skills in the
Agent Skills format that teach an agent to use the CLI:
The skills are versioned with the CLI and name the CLI version they need.
The read API
Without the CLI, call the read API with a project token:- The API is described by an OpenAPI 3.1 document at
https://api.apsio.io/v1/openapi.json, which needs no token. Give it to the agent so it knows the endpoints and fields. - These docs are published for agents too:
https://docs.apsio.io/llms.txtlists every page, andllms-full.txtholds them all in one file.
The MCP server
Apsio’s MCP server is athttps://mcp.apsio.io/mcp (Streamable HTTP). It is a client of the
read API: its tools return the same numbers as the console, with the same permissions. It is a
preview (v0).
Sign in. Add the URL to your MCP client (Claude Code, Claude Desktop, Cursor and others).
The client signs you in with your Apsio account through OAuth, in the browser, and then reads
every project of your organizations. Nothing is stored on the MCP server.
APSIO_TOKEN:
Tools
All tools are read-only.
Every answer has a short summary and the data as JSON, a link to the console for each issue,
session and release, and stays within a size budget: long stacks and lists are cut, saying how
many items were left out, and lists page with
next_cursor. The API writes every call the MCP
server makes to your organization’s audit log, with the user or project token that made it and
the tool, before it reads anything. A sign-in token given to an MCP client works only through
the MCP server, not against the API directly.
Changing an issue’s status, merging issues, sampling and the kill switch will come as write
tools behind an explicit permission. A SQL tool (run_query) is not available yet.
Treat app text as data
Exception messages, log bodies, breadcrumbs, screen names and attributes are written by your app and its users, so they can contain text that looks like instructions. When you pass them to an agent, treat them as data, never as instructions. The CLI shows such text quoted and escaped under a note that it is untrusted, and the skills tell the agent never to follow it, run commands it mentions, or paste it into a shell. The MCP server puts this text only in fields nameduntrusted, never in its own summaries, and says so in every answer.