Use the REST API from CI
When you finish, your CI moves a devBoard task to Done when its work ships. It takes about ten minutes.
An API is a way for a script to talk to an app without a screen. CI is the service that builds and tests your code on each push, like GitHub Actions. A token is a secret key that lets a tool act as you.
The REST API lives at https://api.getdevboard.app/dev/v1. It takes the same token as the MCP server. Send it in an Authorization: Bearer header.
The six routes
| Route | What it does |
|---|---|
GET me |
Your name, email, role and workspace id |
GET projects |
The projects, each with its key and columns |
GET items?project=APP&q=login |
Up to 50 items, newest first. q matches titles |
GET items/APP-42 |
One item in full, with comments, pull requests and time logged |
GET items/APP-42/pulls |
The pull requests linked to the item |
POST items/APP-42/status |
Moves the card. Send {"category":"done"}, or a column name as {"status":"Code review"} |
A category is a kind of column: backlog, todo, inProgress, done or cancelled. devBoard moves the card to the first column of that kind in its project. If you send a name and a category, the name wins.
What you need
- devBoard on a Mac, to make the token.
- Your role is member, admin or owner. A guest cannot move cards.
- A GitHub repo with Actions on, and the right to add secrets.
Steps
1. Make a token for CI
In the devBoard Mac app, open Settings → Developer, click New token and name it "CI". Copy it, because it is shown once.
2. Try it from your terminal
Run this, with your token in place of <your-token>. You get your name, role and workspace back as JSON.
curl -H "Authorization: Bearer <your-token>" https://api.getdevboard.app/dev/v1/me
3. Save the token as a GitHub secret
In GitHub, open the repo's Settings → Secrets and variables → Actions. Click New repository secret. Name it DEVBOARD_TOKEN and paste the token.
4. Add the job to a workflow
Save this as .github/workflows/devboard.yml. It runs when a pull request merges into main. It reads the key from the branch name and moves that task to Done.
name: devBoard
on:
pull_request:
types: [closed]
branches: [main]
jobs:
move-task:
if: github.event.pull_request.merged == true
runs-on: ubuntu-latest
steps:
# Your deploy steps go here.
- name: Move the devBoard task to Done
env:
DEVBOARD_TOKEN: ${{ secrets.DEVBOARD_TOKEN }}
BRANCH: ${{ github.head_ref }}
run: |
KEY=$(echo "$BRANCH" | grep -oE '^[A-Za-z][A-Za-z0-9]{1,5}-[0-9]+' | tr '[:lower:]' '[:upper:]' || true)
if [ -z "$KEY" ]; then
echo "No devBoard key in $BRANCH"
exit 0
fi
curl -fsS -X POST \
-H "Authorization: Bearer $DEVBOARD_TOKEN" \
-H "Content-Type: application/json" \
-d '{"category":"done"}' \
"https://api.getdevboard.app/dev/v1/items/$KEY/status"
The -f flag makes the step fail on an error, so a bad token or key shows up as a failed run.
5. Merge a pull request
Open a pull request from a branch that starts with a key, like app-42-fix-login. Merge it. The job runs and APP-42 moves to Done.
Branch names from your assistant already start with the key. See start and finish work.
Check that it works
Open the job's log in GitHub. The last line is devBoard's answer, like {"key":"APP-42","status":"Done","category":"done"}. The move shows in the card's activity log under your name, because the token acts as you.
What to try next
- Put the step after your deploy steps, so the card moves only when the work is live. If a merge is enough, the GitHub webhook does it with no CI.
- Send a card to review from a script with
{"status":"Code review"}.
The limits
- One write. The API can move a card, and that is all. Comments and time tracking go through MCP.
- A list returns at most 50 items.
qsearches titles, not descriptions or comments. - One workspace per token. A second workspace needs a second token.
Keep the token in your CI's secret store, never in the workflow file. More in keep your tokens safe. Other how-tos are in the guides.
If it does not work
| What you see | Why | What to do |
|---|---|---|
| 401 "Unknown token." | The token is wrong or revoked, or Bearer is missing |
Make a new token and save the secret again |
| 404 "No such item." | The key is wrong, or the task is in another workspace | Check the key and which workspace the token is for |
| 400 "Unknown category." | A typo in the category | Use backlog, todo, inProgress, done or cancelled |
| 403 | Your role is guest | Ask an admin to make you a member |
| The job says "No devBoard key" | The branch name does not start with a key | Name branches like app-42-fix-login |
Questions people ask
Can the REST API create tasks?
No. It can read, and it can move a card. To create tasks, comment or log time, use the MCP server.
Whose name shows when CI moves a card?
The name of the person who made the token, because the token acts as them.
Free while in early access; paid plans will be one plain number, posted here first.
Download on the App Store Get it on Google Play Connect your AI assistant