Topics

File attachments and task time-log API

Upload multipart files, associate attachments with tasks or comments, download protected files, and manage recorded task time.

Updated October 3, 20263 min read

Before you begin

Use https://tasker.fit/api as the REST base URL. Create an active integration token in Profile → API Tokens, and send Authorization: Bearer <your-api-token>. Replace all example IDs with values returned for your account.

Planning your workflow

Upload a file to its board with multipart/form-data. The response contains an attachment ID that can be added to a task's attachment_ids or a new comment. File metadata uses JSON, while the protected file endpoint redirects to a storage URL. A download client should follow that redirect without forwarding the Tasker authorization header to an unrelated storage host.

Time logs record completed work using started_at and duration_seconds. Duration must be positive, and the interval must not end in the future. Time-log IDs are numeric; task IDs remain scoped string identifiers. The summary returns spent_seconds. These endpoints support integrations even though the web frontend's time-tracking feature is currently disabled.

Example

Upload multipart files, associate attachments with tasks or comments, download protected files, and manage recorded task time.

Step-by-step tutorials / 1

Integration workflow

  1. Upload a file with company_id, board_id, and file, then retain its returned attachment ID.

  2. Associate the ID with a task or comment. For downloads, request the protected file endpoint and follow its redirect.

  3. Record completed work with an ISO 8601 start and duration in seconds. Read the task time summary after the log is saved.

What to expect: Read the returned data object and keep the resource identifiers for subsequent requests. Check the HTTP status before treating a write operation as successful.

Endpoints and request examples

Replace example identifiers, tokens, and dates with your own values. Each example shows fields for a specific operation, rather than a complete response schema.

Endpoint directory
MethodPathOperation
POST/attachment/Upload a board file
GET/attachment/Read attachment metadata
GET/attachment/file/Get a protected download redirect
GET/task/time-logs/List task time logs
POST/task/time-logs/Record completed work time
PATCH/task/time-logs/detail/Update a time log
DELETE/task/time-logs/detail/Delete a time log
GET/task/time-logs/summary/Read total spent seconds
POST/api/attachment/

Upload a board file

Authentication and permission for this operation are required.

multipart/form-data

{
  "company_id": "demo",
  "board_id": "RELEASE",
  "file": "@/path/to/screenshot.png"
}

Additional fields: name

cURL example

curl --request POST 'https://tasker.fit/api/attachment/' \
  --header 'Authorization: Bearer <your-api-token>' \
  --form 'company_id=demo' \
  --form 'board_id=RELEASE' \
  --form 'file=@/path/to/screenshot.png'
GET/api/attachment/

Read attachment metadata

Authentication and permission for this operation are required.

URL query parameters (example)

{
  "company_id": "demo",
  "board_id": "RELEASE",
  "attachment_id": 8
}

cURL example

curl --request GET 'https://tasker.fit/api/attachment/?company_id=demo&board_id=RELEASE&attachment_id=8' \
  --header 'Authorization: Bearer <your-api-token>'
GET/api/attachment/file/

Get a protected download redirect

Authentication and permission for this operation are required.

URL query parameters (example)

{
  "company_id": "demo",
  "board_id": "RELEASE",
  "attachment_id": 8
}

cURL example

curl --request GET 'https://tasker.fit/api/attachment/file/?company_id=demo&board_id=RELEASE&attachment_id=8' \
  --header 'Authorization: Bearer <your-api-token>'
GET/api/task/time-logs/

List task time logs

Authentication and permission for this operation are required.

URL query parameters (example)

{
  "company_id": "demo",
  "board_id": "RELEASE",
  "task_id": "<task-id>"
}

Additional fields: tracker_id, page, limit, q

cURL example

curl --request GET 'https://tasker.fit/api/task/time-logs/?company_id=demo&board_id=RELEASE&task_id=%3Ctask-id%3E' \
  --header 'Authorization: Bearer <your-api-token>'
POST/api/task/time-logs/

Record completed work time

Authentication and permission for this operation are required.

JSON request body (example)

{
  "company_id": "demo",
  "board_id": "RELEASE",
  "task_id": "<task-id>",
  "started_at": "2026-10-01T09:00:00Z",
  "duration_seconds": 1800,
  "description": "Checkout verification"
}

cURL example

curl --request POST 'https://tasker.fit/api/task/time-logs/' \
  --header 'Authorization: Bearer <your-api-token>' \
  --header 'Content-Type: application/json' \
  --data '{
  "company_id": "demo",
  "board_id": "RELEASE",
  "task_id": "<task-id>",
  "started_at": "2026-10-01T09:00:00Z",
  "duration_seconds": 1800,
  "description": "Checkout verification"
}'
PATCH/api/task/time-logs/detail/

Update a time log

Authentication and permission for this operation are required.

URL query parameters (example)

{
  "company_id": "demo",
  "board_id": "RELEASE",
  "task_id": "<task-id>",
  "time_log_id": 9
}

JSON request body (example)

{
  "duration_seconds": 2400
}

Additional fields: started_at, description

cURL example

curl --request PATCH 'https://tasker.fit/api/task/time-logs/detail/?company_id=demo&board_id=RELEASE&task_id=%3Ctask-id%3E&time_log_id=9' \
  --header 'Authorization: Bearer <your-api-token>' \
  --header 'Content-Type: application/json' \
  --data '{
  "duration_seconds": 2400
}'
DELETE/api/task/time-logs/detail/

Delete a time log

Authentication and permission for this operation are required.

URL query parameters (example)

{
  "company_id": "demo",
  "board_id": "RELEASE",
  "task_id": "<task-id>",
  "time_log_id": 9
}

cURL example

curl --request DELETE 'https://tasker.fit/api/task/time-logs/detail/?company_id=demo&board_id=RELEASE&task_id=%3Ctask-id%3E&time_log_id=9' \
  --header 'Authorization: Bearer <your-api-token>'
GET/api/task/time-logs/summary/

Read total spent seconds

Authentication and permission for this operation are required.

URL query parameters (example)

{
  "company_id": "demo",
  "board_id": "RELEASE",
  "task_id": "<task-id>"
}

cURL example

curl --request GET 'https://tasker.fit/api/task/time-logs/summary/?company_id=demo&board_id=RELEASE&task_id=%3Ctask-id%3E' \
  --header 'Authorization: Bearer <your-api-token>'

Tips & troubleshooting

  • Examples show the key request fields, not every optional field or a full response schema. Query fields belong in the URL; JSON body fields belong in the request body. Keep trailing slashes on endpoint paths.

Frequently asked questions

Can these examples be used with any account?

Only resources accessible to the token's account can be read or changed. Use returned company, board, task, and numeric resource IDs; the examples' demo values are placeholders.

What should an integration do when a request fails?

Check the HTTP status and returned error payload. Validate identifiers and required fields, then check token activity, expiry, and permissions. Do not blindly repeat a POST: a previous attempt may already have created a resource.

Continue learning