Topics

API authentication, tokens, and account access

Authenticate REST integrations with bearer tokens, understand JWT browser sessions, manage credentials, and read account information.

Updated October 3, 20263 min read

Before you begin

Use https://tasker.fit/api as the REST base URL. Create an active integration token in Profile → API Tokens, and send Authorization: Bearer <your-api-token>. Replace all example IDs with values returned for your account.

Planning your workflow

Tasker supports two authentication mechanisms. A named API token uses the Bearer authorization scheme and is appropriate for a server integration or MCP client. Interactive sign-in returns access_token and refresh_token; the web client sends its access token with the JWT scheme. These credentials are different: do not label a JWT access token as a named API token or place a refresh token in an authorization header.

Account registration and sign-in require a valid captcha_token. Sign-in accepts the username field and an optional authenticator code when two-factor authentication is enabled. Token management remains authenticated; do not attempt to create a token anonymously. Refresh-token rotation should be handled by saving the returned replacement pair before issuing later requests.

Example

Authenticate REST integrations with bearer tokens, understand JWT browser sessions, manage credentials, and read account information.

Step-by-step tutorials / 1

Integration workflow

  1. Create a named token in the web profile and copy it into private integration configuration.

  2. Send GET /member/me/ with a Bearer header to confirm which account owns the credential.

  3. Name credentials by integration, set an expiry when appropriate, and deactivate or delete unused tokens.

What to expect: Read the returned data object and keep the resource identifiers for subsequent requests. Check the HTTP status before treating a write operation as successful.

Endpoints and request examples

Replace example identifiers, tokens, and dates with your own values. Each example shows fields for a specific operation, rather than a complete response schema.

Endpoint directory
MethodPathOperation
GET/member/me/Read the authenticated account
GET/member/bearer-tokens/List integration tokens
POST/member/bearer-tokens/Create an integration token
PATCH/member/bearer-tokens/detail/Deactivate or edit a token
DELETE/member/bearer-tokens/detail/Revoke a token
POST/member/login/Interactive sign-in
POST/member/register/Register an account
POST/member/refresh-token/Refresh a JWT session
GET/api/member/me/

Read the authenticated account

Authentication and permission for this operation are required.

cURL example

curl --request GET 'https://tasker.fit/api/member/me/' \
  --header 'Authorization: Bearer <your-api-token>'
GET/api/member/bearer-tokens/

List integration tokens

Authentication and permission for this operation are required.

URL query parameters (example)

{
  "page": 1,
  "limit": 20
}

cURL example

curl --request GET 'https://tasker.fit/api/member/bearer-tokens/?page=1&limit=20' \
  --header 'Authorization: Bearer <your-api-token>'
POST/api/member/bearer-tokens/

Create an integration token

Authentication and permission for this operation are required.

JSON request body (example)

{
  "title": "Release integration",
  "is_active": true
}

Additional fields: metadata, expires_at

cURL example

curl --request POST 'https://tasker.fit/api/member/bearer-tokens/' \
  --header 'Authorization: Bearer <your-api-token>' \
  --header 'Content-Type: application/json' \
  --data '{
  "title": "Release integration",
  "is_active": true
}'
PATCH/api/member/bearer-tokens/detail/

Deactivate or edit a token

Authentication and permission for this operation are required.

URL query parameters (example)

{
  "key": "<token-key>"
}

JSON request body (example)

{
  "is_active": false
}

Additional fields: title, metadata, expires_at

cURL example

curl --request PATCH 'https://tasker.fit/api/member/bearer-tokens/detail/?key=%3Ctoken-key%3E' \
  --header 'Authorization: Bearer <your-api-token>' \
  --header 'Content-Type: application/json' \
  --data '{
  "is_active": false
}'
DELETE/api/member/bearer-tokens/detail/

Revoke a token

Authentication and permission for this operation are required.

URL query parameters (example)

{
  "key": "<token-key>"
}

cURL example

curl --request DELETE 'https://tasker.fit/api/member/bearer-tokens/detail/?key=%3Ctoken-key%3E' \
  --header 'Authorization: Bearer <your-api-token>'
POST/api/member/login/

Interactive sign-in

No Bearer header; satisfy the request-body requirements.

JSON request body (example)

{
  "username": "your-username",
  "password": "<password>",
  "captcha_token": "<valid-captcha-token>"
}

Additional fields: code

cURL example

curl --request POST 'https://tasker.fit/api/member/login/' \
  --header 'Content-Type: application/json' \
  --data '{
  "username": "your-username",
  "password": "<password>",
  "captcha_token": "<valid-captcha-token>"
}'
POST/api/member/register/

Register an account

No Bearer header; satisfy the request-body requirements.

JSON request body (example)

{
  "first_name": "Alex",
  "username": "your-username",
  "email": "[email protected]",
  "password": "<password>",
  "captcha_token": "<valid-captcha-token>"
}

Additional fields: last_name, description

cURL example

curl --request POST 'https://tasker.fit/api/member/register/' \
  --header 'Content-Type: application/json' \
  --data '{
  "first_name": "Alex",
  "username": "your-username",
  "email": "[email protected]",
  "password": "<password>",
  "captcha_token": "<valid-captcha-token>"
}'
POST/api/member/refresh-token/

Refresh a JWT session

No Bearer header; satisfy the request-body requirements.

JSON request body (example)

{
  "refresh_token": "<refresh-token>"
}

cURL example

curl --request POST 'https://tasker.fit/api/member/refresh-token/' \
  --header 'Content-Type: application/json' \
  --data '{
  "refresh_token": "<refresh-token>"
}'

Tips & troubleshooting

  • Examples show the key request fields, not every optional field or a full response schema. Query fields belong in the URL; JSON body fields belong in the request body. Keep trailing slashes on endpoint paths.
  • Never publish token keys or passwords. The examples deliberately contain placeholders. Deleting the token used by a client invalidates that client's later requests.

Frequently asked questions

Can these examples be used with any account?

Only resources accessible to the token's account can be read or changed. Use returned company, board, task, and numeric resource IDs; the examples' demo values are placeholders.

What should an integration do when a request fails?

Check the HTTP status and returned error payload. Validate identifiers and required fields, then check token activity, expiry, and permissions. Do not blindly repeat a POST: a previous attempt may already have created a resource.

Continue learning