REST API
The REST API for teams, stories, runs, decisions and the audit log: base URL, authentication, pagination, rate limits and identifiers.
The kanman REST API lets your own tools read teams, stories, runs, decisions and the audit log, answer decisions and export the audit log, for example for a status dashboard, a bot in your chat tool or a nightly archive in your compliance system. To be told when something happens instead of asking, use webhooks.
kanman has two more programmatic interfaces: the kanman MCP server, which lets Claude Code or Codex on your machine work on a kanman story, and the self-hosted runner, which runs kanman’s work on your own infrastructure. All three authenticate with a km_ API token.
Endpoints
| Method and path | What it does | Permission |
|---|---|---|
GET /v1/teams |
List the workspace’s teams with their policy summary | read |
GET /v1/teams/{team} |
Read one team | read |
GET /v1/teams/{team}/stories |
List a team’s stories | read |
GET /v1/stories/{story-key} |
Read one story with acceptance criteria | read |
GET /v1/runs |
List runs | read |
GET /v1/runs/{run-key} |
Read one run with its attempts and evidence pack | read |
GET /v1/decisions |
List decisions | read |
GET /v1/decisions/{decision-key} |
Read one decision | read |
POST /v1/decisions/{decision-key}/resolve |
Answer a decision | write |
GET /v1/audit |
Read the audit log (owners and admins) | read |
GET /v1/audit/export |
Export the audit log as CSV or JSON (owners and admins) | read |
The pages of this section describe each endpoint next to the place in the app where you do the same by hand. Changing a team’s policy, pausing a team, submitting requirements, and stopping or retrying runs are done in the app, in Slack or through the MCP server.
Base URL and format
| Property | Value |
|---|---|
| Base URL | https://api.kanman.ai/functions/v1/api-gateway |
| Version | Every path starts with /v1 |
| Protocol | HTTPS only |
| Format | JSON, UTF-8 |
| Authentication | Authorization: Bearer km_... with a token from Settings, API. See Authentication. |
| Scope | A token only reaches the workspace it was created in. |
| Errors | { "error": { "code": "...", "message": "..." } }. See Errors and rate limits. |
Example:
curl https://api.kanman.ai/functions/v1/api-gateway/v1/teams \
--header "Authorization: Bearer $KANMAN_API_KEY"
{
"data": [
{
"id": "3c9a1f2e-5b7d-4e8a-9c0b-1d2e3f4a5b6c",
"slug": "sandbox-team",
"name": "Sandbox Team",
"description": null,
"keyPrefix": "SBX",
"paused": false,
"policy": {
"preset": "balanced", "custom": false, "version": 4, "executor": "claude-code", "maxConcurrency": 2,
"budgets": { "runCents": 400, "dayCents": null, "monthCents": 20000 },
"planApproval": "always", "mergePolicy": "human", "pausedAt": null, "updatedAt": "2026-10-01T09:00:00Z"
},
"createdAt": "2026-09-28T11:22:47Z",
"updatedAt": null
}
],
"nextCursor": null
}
Pagination
Lists return the newest items first, as { "data": [...], "nextCursor": "..." }.
limitsets the page size: 25 by default, at most 100.- When
nextCursoris notnull, pass it unchanged ascursorto get the next page. Treat it as an opaque string. - The team list is short and always complete in one page.
curl "https://api.kanman.ai/functions/v1/api-gateway/v1/runs?limit=50&cursor=$NEXT" \
--header "Authorization: Bearer $KANMAN_API_KEY"
Identifiers
kanman uses the same readable keys everywhere: in the app’s URLs, in Slack, in the MCP server and in the API.
| Object | Identifier | Example |
|---|---|---|
| Team | team slug | sandbox-team |
| Story | story key | SBX-12 |
| Run | run key | run-7f3k |
| Decision | decision key | dec-4h2k |
| Intake request | intake slug | export-invoices-k3f9 |
Rate limits
Each token may send 120 requests per minute. Every answer carries X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset (Unix seconds); see Errors and rate limits.
Everything is audited
Every change you make, in the app, in Slack, through the MCP server or through the API, writes the same audit entries, with you as the actor. A decision records the channel it was answered through: app, slack, mcp or api. See Audit export format.
Earlier versions
The first version of the API served boards, projects and tasks. GET /boards and GET /boards/{id} still answer with the workspace’s teams in the old shape; use /v1/teams instead. The project and task endpoints answer 410 Gone: projects no longer exist, and stories come from your tracker, where you create and change them.
Support
- Email: [email protected]
- Status: status.kanman.ai
Authentication
Create, use and revoke the km_ API tokens that authenticate the REST API, the kanman MCP server and the self-hosted runner.
Teams
Where you create teams, read and change a team's policy, and pause or resume a team, and how your tools read teams through the REST API.
Stories and intake
Where you submit requirements, review draft stories and edit stories, and how your tools read stories through the REST API.
Runs
Where you follow runs with their attempts and evidence pack, how you stop or retry a run, and how your tools read runs through the REST API.
Decisions
Decision kinds and option actions, where you answer decisions, and how your tools list, read and answer them through the REST API.
Audit
Where you read and export the audit log in the app, and how your tools read and export it through the REST API.