Let your agent run the board

Tarsen speaks MCP, the Model Context Protocol. Your assistant connects to your real workspace and works it: reads the board, makes cards, moves them, comments. No plugin, no middleman, and no pasting your cards into a chat window.

What your agent can do

14 tools, covering projects, boards, cards and comments. 5 only read. 9 can change something.

  • Read every project, board and card you can see, and search across all of them.
  • List what is assigned to you, soonest due first.
  • Create a card, and set its title, description, priority and due date.
  • Move a card to another stage, by the name of the list on your board.
  • Assign a card to a person, or to another agent.
  • Set a card's labels, from the labels your workspace already has.
  • Comment on a card, and edit a comment it wrote earlier.
  • Add, rename or reorder a stage on a board.

These are real writes, not suggestions. A card your agent creates is a real card, a comment it posts is attributed to you, and your team is notified the same way as always.

What it cannot do

The list above is the whole list. There is no tool for anything else, so there is nothing to switch off:

  • It cannot delete a card, a list or a project.
  • It cannot change billing, invite anyone, or remove anyone.
  • It cannot create a label. A name that does not exist is an error naming the ones that do.
  • It cannot decide which list completes work. That stays a human decision in the app.
  • It cannot edit somebody else's comment, and the server refuses if it tries.

Which assistants can connect

Any client that speaks MCP over HTTP and can send an Authorization header. Your Tarsen API key goes in that header. These are the ones people ask about:

AssistantWhere the key goes
Claude CodeOne command: claude mcp add --transport http, with a --header flag.
Claude DesktopSettings, Developer, Edit Config. An http server with a headers block.
Gemini CLIsettings.json: an httpUrl entry with a headers block beside it.
Cursormcp.json: a url entry with a headers block beside it.
GitHub Copilot in VS Codemcp.json: a server of type http, with a headers block.
WindsurfA remote server URL, with the key sent as a header.

ChatGPT is not on this list yet. Its custom connectors accept OAuth or no authentication, and Tarsen keys are bearer tokens, so there is nowhere to put one. Nothing on our side blocks it.

Your permissions, not new ones

A key acts as you, in one workspace. Everything else follows from that:

  • It reaches exactly the projects you reach. A private project you are not in is invisible to it.
  • It cannot do anything you cannot. View-only access for you is view-only for your agent.
  • It is locked to the workspace it was made in, and stops the moment you leave.
  • Keys are personal. Even a workspace admin cannot see or use yours.
  • You can revoke a key from the same screen you made it on. It stops working on the next request.

Hold an agent to its own work

There is a second, optional layer, and it is the one that matters when an agent is left running. Tick “Only let this agent change work assigned to it” when you create the key.

A scoped key still reads the whole board and can still claim an unassigned card. What it cannot do is move, relabel, comment on or reassign a card that somebody else holds, including another agent. 6 of the 9 writing tools are held this way.

This is how a team runs several agents on one board without them treading on each other, or on a person.

What it costs

Nothing extra. API keys are on every plan, including the free one, and connecting an agent does not use your AI requests or your voice minutes: your assistant runs on its own account and talks to Tarsen over the wire.

Something missing here? Email support@tarsen.co and we’ll write it.