Manage API keys
DEVELOPER SERVICES · V1

Connect the work.

Read workspaces, requirements, tasks, goals, releases, milestones and delivery forecasts. Create or update planning work and contribute comments through the same Java services used by RedRover.

MCP · 0.1.0

Connect your agent to the work.

Use Codex, Claude Code or a Streamable HTTP terminal client to find work, create requirements and tasks, link them to releases, append progress notes and manage your own time.

Using Codex? Select Codex mode.

RedRover’s Bearer key works in Codex mode. ChatGPT mode requires OAuth, which RedRover does not currently support. Switch to Codex mode and open a Codex conversation to use this connection.

My MCP connectionsDownload developer guide (.md)
  1. A workspace owner enables MCP under Workspace Settings → MCP access and chooses its limits.
  2. Under My MCP connections in your profile menu, create your personal key with selected workspaces and permissions.
  3. Store it as REDROVER_MCP_KEY in your client's environment. Copy your environment's endpoint from the connection page.
  4. Connect and ask your agent to call rr_context first. Each call respects your current account, membership and permissions.

These examples use local RedRover. For a shared server, replace the URL with the exact HTTPS endpoint shown in your connection page. Never put the key in a URL or commit it to your project.

Codex · Codex mode required

Select Codex mode, not ChatGPT mode. Merge this into ~/.codex/config.toml or your trusted project's .codex/config.toml. Start the client with the key available, restart its MCP connection and open a Codex conversation. Signing into Codex with your ChatGPT account is fine; the conversation must be in Codex mode.

[mcp_servers.redrover]
url = "http://localhost:8080/redrover/mcp"
bearer_token_env_var = "REDROVER_MCP_KEY"
Official Codex configuration
Claude Code

Merge this into your project's .mcp.json. Export the key before starting Claude Code, approve the project server and check /mcp. The variable reference below stays in the file; your actual key does not.

{
  "mcpServers" : {
    "redrover" : {
      "url" : "http://localhost:8080/redrover/mcp",
      "headers" : {
        "Authorization" : "Bearer ${REDROVER_MCP_KEY}"
      },
      "type" : "http"
    }
  }
}

This release supports key-based Claude Code connections. OAuth-only Claude.ai connectors need a separate integration.

Official Claude Code configuration
Terminal clients

Use stateless Streamable HTTP JSON-RPC POSTs. Send Authorization: Bearer …, Content-Type: application/json and Accept: application/json, text/event-stream. Initialize, then use tools/list and tools/call. GET returning 405 is expected.

The downloadable guide includes curl commands, tool reference, filtering and planning examples, version checks, safe retries, key rotation and troubleshooting. Inspect result.isError even when HTTP succeeds.

MCP permissions only narrow your existing access. Delete starts off. Task Orders, approvals, financial data, files and account administration are outside this first MCP release. REST API keys and MCP connections are configured separately.


REST API

Start with access

  1. An account owner creates a key under System → API keys & integrations, chooses the acting user, expiry and per-resource read/write grants.
  2. Keep the key in your server's secret manager. Send X-API-Key: <secret> or Authorization: ApiKey <secret>, using exactly one header.
  3. Call /api/v1/workspaces below your RedRover application URL. Use a returned workspace ID for work and forecast requests.

A key can only do what both its grants and its user's current permissions allow. Revocation, account access and workspace membership are checked on every request. Linked requirements and releases need read grants too. Users, roles, approvals, task orders, settings and key administration are excluded from key access.

OpenAPI contractPostman collection

Work, safely

Read /api/v1/options?workspaceId=… for configured statuses, priorities and eligible assignees. Use the status key together with its canonical state. New task status planned and priority normal are defaults, not a substitute for checking this workspace’s options.

GET /api/v1/items?workspaceId=…&type=task&after=0&limit=50 returns a cursor page. Continue using nextAfter while hasMore is true. Types also include requirement, goal, release and milestone.

To update, fetch /api/v1/item?workspaceId=…&id=…, edit allowed fields, then post {"workspaceId":123,"record":{…}} to /api/v1/items/save. Keep the current id and version. A 409 means someone changed the record; reload and reconcile. The API preserves associations that are omitted from its bounded work representation.

Use /api/v1/comments for the latest 100 notes or to add a note. /api/v1/capacity provides read-only capacity and delivery scenarios; it requires read grants for workspaces, capacity, tasks, requirements and releases, plus the user's project time oversight.

On an uncertain write response, check the record before retrying: creation and comments are not idempotent. Authentication failures return 401, access denials 403, invalid data 400 and throttling 429 with Retry-After. Do not follow redirects with key-bearing requests.

Ready-to-adapt clients

Server examples read REDROVER_URL and REDROVER_API_KEY from the environment. Set the URL to your application's configured public base URL, including its context path. Use HTTPS outside localhost. Each example performs a workspace read and includes timeouts and error handling.

cURLJava / OkHttpJava Maven POMC++ / libcurlC#VB.NET

Java: place the source under src/main/java and rename the example POM to pom.xml; build with Maven on Java 21. C++: compile with C++17 and libcurl development files. C# and VB.NET: start a .NET 8 or later console project and replace its Program file.

React: a session, not a secret

The typed browser client uses the existing same-origin RedRover session and fetches a current CSRF token before writing. Permissions remain enforced in Java. Deploy your React page under the same origin and context boundary; the hook cancels stale loads when the selected workspace changes.

Typed serviceReact hook & component

For a React application on another origin, use your own authenticated backend to hold the key and enforce the end-user's access. Never expose an unrestricted proxy. RedRover does not enable cross-origin cookie or API-key access by default. Do not place a key in VITE_, REACT_APP_, localStorage or a distributed Electron package.

References: React effect cleanup, OkHttp, libcurl headers, .NET HttpClient, Postman import.

Copyright 2026, Hatchery LLC - all rights reserved. Terms · Privacy · Change log 1.6.0 Appearance