Use the REST API from CI

When you finish, your CI moves a devBoard task to Done when its work ships. It takes about ten minutes.

An API is a way for a script to talk to an app without a screen. CI is the service that builds and tests your code on each push, like GitHub Actions. A token is a secret key that lets a tool act as you.

The REST API lives at https://api.getdevboard.app/dev/v1. It takes the same token as the MCP server. Send it in an Authorization: Bearer header.

The six routes

Route What it does
GET me Your name, email, role and workspace id
GET projects The projects, each with its key and columns
GET items?project=APP&q=login Up to 50 items, newest first. q matches titles
GET items/APP-42 One item in full, with comments, pull requests and time logged
GET items/APP-42/pulls The pull requests linked to the item
POST items/APP-42/status Moves the card. Send {"category":"done"}, or a column name as {"status":"Code review"}

A category is a kind of column: backlog, todo, inProgress, done or cancelled. devBoard moves the card to the first column of that kind in its project. If you send a name and a category, the name wins.

What you need

Steps

1. Make a token for CI

In the devBoard Mac app, open Settings → Developer, click New token and name it "CI". Copy it, because it is shown once.

2. Try it from your terminal

Run this, with your token in place of <your-token>. You get your name, role and workspace back as JSON.

curl -H "Authorization: Bearer <your-token>" https://api.getdevboard.app/dev/v1/me

3. Save the token as a GitHub secret

In GitHub, open the repo's Settings → Secrets and variables → Actions. Click New repository secret. Name it DEVBOARD_TOKEN and paste the token.

4. Add the job to a workflow

Save this as .github/workflows/devboard.yml. It runs when a pull request merges into main. It reads the key from the branch name and moves that task to Done.

name: devBoard
on:
  pull_request:
    types: [closed]
    branches: [main]

jobs:
  move-task:
    if: github.event.pull_request.merged == true
    runs-on: ubuntu-latest
    steps:
      # Your deploy steps go here.
      - name: Move the devBoard task to Done
        env:
          DEVBOARD_TOKEN: ${{ secrets.DEVBOARD_TOKEN }}
          BRANCH: ${{ github.head_ref }}
        run: |
          KEY=$(echo "$BRANCH" | grep -oE '^[A-Za-z][A-Za-z0-9]{1,5}-[0-9]+' | tr '[:lower:]' '[:upper:]' || true)
          if [ -z "$KEY" ]; then
            echo "No devBoard key in $BRANCH"
            exit 0
          fi
          curl -fsS -X POST \
            -H "Authorization: Bearer $DEVBOARD_TOKEN" \
            -H "Content-Type: application/json" \
            -d '{"category":"done"}' \
            "https://api.getdevboard.app/dev/v1/items/$KEY/status"

The -f flag makes the step fail on an error, so a bad token or key shows up as a failed run.

5. Merge a pull request

Open a pull request from a branch that starts with a key, like app-42-fix-login. Merge it. The job runs and APP-42 moves to Done.

Branch names from your assistant already start with the key. See start and finish work.

Check that it works

Open the job's log in GitHub. The last line is devBoard's answer, like {"key":"APP-42","status":"Done","category":"done"}. The move shows in the card's activity log under your name, because the token acts as you.

What to try next

The limits

Keep the token in your CI's secret store, never in the workflow file. More in keep your tokens safe. Other how-tos are in the guides.

If it does not work

What you see Why What to do
401 "Unknown token." The token is wrong or revoked, or Bearer is missing Make a new token and save the secret again
404 "No such item." The key is wrong, or the task is in another workspace Check the key and which workspace the token is for
400 "Unknown category." A typo in the category Use backlog, todo, inProgress, done or cancelled
403 Your role is guest Ask an admin to make you a member
The job says "No devBoard key" The branch name does not start with a key Name branches like app-42-fix-login

Questions people ask

Can the REST API create tasks?

No. It can read, and it can move a card. To create tasks, comment or log time, use the MCP server.

Whose name shows when CI moves a card?

The name of the person who made the token, because the token acts as them.

Free while in early access; paid plans will be one plain number, posted here first.

Download on the App Store Get it on Google Play Connect your AI assistant