Skip to content

Agents

Agent API reference

For AI assistants and the people who set them up. A director's own assistant can read their board through the same access rules as the app, and can save private drafts of pre-meeting questions. Nothing else. To set up an assistant step by step, see Connect your AI assistant.

Base URLs

  • REST: https://preparedboard.com/api/agent/v1
  • MCP (Streamable HTTP, JSON-RPC): https://preparedboard.com/api/mcp
  • API version: 1.1.0 (the same number in OpenAPI, the MCP manifest, MCP serverInfo and /status.json)

IDs are stable strings. Times are ISO 8601 in UTC. List results come in pages: pass the nextCursor you received as cursor; it is null on the last page.

Getting a token

  • Off until the chair allows it. A chair, owner or admin turns on agent access for the board in Settings → Security → Agent access.
  • Personal access token. The director creates it in Settings → Security → Agent access, for one board, with a 7, 30 or 90-day expiry. It starts with pb_pat_, is shown once, is stored only as a hash and can be revoked at any time. Send it as Authorization: Bearer pb_pat_….
  • Sign-in for web connectors. Claude.ai and ChatGPT connectors use OAuth 2.1 with PKCE instead of a pasted token; the director signs in and approves the board and scopes. Details on /agents/connect.

Scopes

ScopeWhat it allows
readRead what the director can see on one board: profile, meetings, board packs, decisions, decision records, their action items and documents.
questions:draftSave a pre-meeting question as a private draft marked agent-assisted. The director reviews it and decides whether to share it. Optional; the director can leave it off.

A call that needs a scope the token lacks returns 403 and is written to the board's audit log.

Operations

Every REST operation is also an MCP tool with the same inputs and the same JSON result.

RESTMCP toolScope
GET /api/agent/v1/meget_profileread
GET /api/agent/v1/meetingslist_meetingsread
GET /api/agent/v1/meetings/{id}get_meetingread
GET /api/agent/v1/meetings/{id}/packget_packread
GET /api/agent/v1/decisionslist_decisionsread
GET /api/agent/v1/decisions/{id}get_decisionread
GET /api/agent/v1/decisions/{id}/recordget_decision_recordread
GET /api/agent/v1/actionslist_my_actionsread
GET /api/agent/v1/documents/{id}get_documentread
POST /api/agent/v1/meetings/{id}/questionsdraft_pre_meeting_questionquestions:draft

Rate limits

60 requests a minute per token, counted across all of our servers. Every response carries RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset (seconds) and RateLimit-Policy. Over the limit you get 429 with Retry-After.

Errors

Errors are JSON: {"error": "plain-language message"}. Every response carries an X-Request-Id header; quote it if you report a problem.

StatusWhen
400A parameter is wrong, for example an unknown status filter or a cursor that did not come from the previous page.
401No token, a token that is not a Prepared Board token, or one that was revoked or has expired. The response carries WWW-Authenticate.
403The token is valid but not allowed: agent access is off for the board, the director is no longer an active member, the board requires two-factor sign-in and the account has it off, the token lacks the scope, or the director's role cannot see that item.
404The item does not exist on this board, or the director cannot see it (the two look the same on purpose).
409The item exists but is not in a state that has this resource, for example a decision record for a decision that is still open.
429More than 60 requests in a minute on this token. Wait the number of seconds in Retry-After.

Machine-readable files

  • /openapi.json — OpenAPI 3.1 description of the REST API
  • /.well-known/mcp.json — MCP discovery manifest: server URL, sign-in, tools and scopes
  • /status.json — Service status: running version, database and file storage checks
  • /changelog.json — What is live on preparedboard.com, newest first
  • /llms.txt — Plain-text product facts for language models
  • /agent-facts.json — Structured product facts, including what is not live
  • /.well-known/security.txt — How to report a security problem
  • /api/public/v1/records/{sealId}/verify — Check a sealed decision record against its published hash (not live yet)

Copy and paste

curl

curl -H "Authorization: Bearer pb_pat_YOUR_TOKEN" \
  "https://preparedboard.com/api/agent/v1/decisions?status=open"

MCP client config (Cursor and other clients that take a URL and headers)

{
  "mcpServers": {
    "prepared-board": {
      "url": "https://preparedboard.com/api/mcp",
      "headers": { "Authorization": "Bearer pb_pat_YOUR_TOKEN" }
    }
  }
}

Claude Code

claude mcp add --transport http prepared-board https://preparedboard.com/api/mcp \
  --header "Authorization: Bearer pb_pat_YOUR_TOKEN"

What agents cannot do

An assistant cannot write anything except a private draft of a pre-meeting question: no votes, approvals, minutes edits, messages or document changes. It sees nothing outside the one board its token is for, and nothing that director could not open in the app: confidentiality levels, document access lists, committee seats, executive-session limits and recusals are applied the same way as in the app. Uploaded PDFs come back as a title and a link, not the file. Prepared Board does not call any AI model.

Related: /agents · /agents/connect · /trust/ai