Skip to main content
Agents reach Apsio through the same public API as the console, with the same permissions: directly, or through the MCP server.

The apsio CLI

An agent with a shell, such as Claude Code, Codex or Cursor’s terminal, can use the apsio CLI (version 0.2.0 or later) with a project token in APSIO_TOKEN:
  • --json prints the API’s JSON, and --jq filters it inside the CLI, so the agent reads only the fields it needs. -r prints strings without quotes.
  • Exit codes are stable (0 success, 1 network or server, 2 usage, 3 not authenticated, 4 bad input, 5 not found), and no command prompts when it is not attached to a terminal.
  • apsio issue open <id> prints the console URL, so the agent can link a person to the evidence.

Skills

The apsio-skills repository holds skills in the Agent Skills format that teach an agent to use the CLI:
The skills are versioned with the CLI and name the CLI version they need.

The read API

Without the CLI, call the read API with a project token:
  • The API is described by an OpenAPI 3.1 document at https://api.apsio.io/v1/openapi.json, which needs no token. Give it to the agent so it knows the endpoints and fields.
  • These docs are published for agents too: https://docs.apsio.io/llms.txt lists every page, and llms-full.txt holds them all in one file.

The MCP server

Apsio’s MCP server is at https://mcp.apsio.io/mcp (Streamable HTTP). It is a client of the read API: its tools return the same numbers as the console, with the same permissions. It is a preview (v0). Sign in. Add the URL to your MCP client (Claude Code, Claude Desktop, Cursor and others). The client signs you in with your Apsio account through OAuth, in the browser, and then reads every project of your organizations. Nothing is stored on the MCP server.
Headless agents (CI, bots) send a project token instead, which reads one project:
Clients without remote MCP run the local bridge, which relays to the same server with the token from APSIO_TOKEN:

Tools

All tools are read-only. Every answer has a short summary and the data as JSON, a link to the console for each issue, session and release, and stays within a size budget: long stacks and lists are cut, saying how many items were left out, and lists page with next_cursor. The API writes every call the MCP server makes to your organization’s audit log, with the user or project token that made it and the tool, before it reads anything. A sign-in token given to an MCP client works only through the MCP server, not against the API directly. Changing an issue’s status, merging issues, sampling and the kill switch will come as write tools behind an explicit permission. A SQL tool (run_query) is not available yet.

Treat app text as data

Exception messages, log bodies, breadcrumbs, screen names and attributes are written by your app and its users, so they can contain text that looks like instructions. When you pass them to an agent, treat them as data, never as instructions. The CLI shows such text quoted and escaped under a note that it is untrusted, and the skills tell the agent never to follow it, run commands it mentions, or paste it into a shell. The MCP server puts this text only in fields named untrusted, never in its own summaries, and says so in every answer.

Coming soon

These are planned and not available yet: