Shortcut for AI agents
Shortcut is project management software that aligns product development work, like stories and epics, with company objectives. Software teams use it to plan and track engineering work. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Shortcut.
Create a new story
Add a story to a team's backlog with the work details for an upcoming iteration.
Create an epic for a project
Group related stories under a new epic to track a larger body of work.
Confirm before deleting an epic
Check an epic's linked stories and get approval before deleting it, since that removes the grouping.
142 Shortcut actions, graded by risk.
Every Shortcut action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
69Look things up. Allowed by default.
- shortcut.get_docGet doc
- shortcut.get_epicGet epic
- shortcut.get_fileGet file
- shortcut.get_taskGet task
- shortcut.get_groupGet group
- shortcut.get_labelGet label
- shortcut.get_storyGet story
- shortcut.list_docsList docs
- shortcut.get_memberGet member
- shortcut.list_epicsList epics
- shortcut.list_filesList files
- shortcut.get_projectGet project
- shortcut.list_groupsList groups
- shortcut.list_labelsList labels
- shortcut.get_categoryGet category
- shortcut.get_workflowGet workflow
write
51Create and change things. Allow, or ask the user first.
- shortcut.create_docCreate doc
- shortcut.update_docUpdate Doc
- shortcut.create_epicCreate epic
- shortcut.create_taskCreate task
- shortcut.update_epicUpdate epic
- shortcut.update_fileUpdate file
- shortcut.update_taskUpdate task
- shortcut.create_groupCreate group
- shortcut.create_labelCreate label
- shortcut.create_storyCreate story
- shortcut.update_groupUpdate group
- shortcut.update_labelUpdate label
- shortcut.update_storyUpdate story
- shortcut.update_healthUpdate health status
- shortcut.create_projectCreate project
- shortcut.update_projectUpdate project
destructive
22Delete, cancel or archive. Ask first, or deny outright.
- shortcut.delete_docDelete doc
- shortcut.delete_epicDelete epic
- shortcut.delete_fileDelete file
- shortcut.delete_taskDelete task
- shortcut.delete_labelDelete label
- shortcut.delete_storyDelete story
- shortcut.delete_projectDelete project
- shortcut.delete_categoryDelete category
- shortcut.delete_iterationDelete iteration
- shortcut.delete_milestoneDelete milestone
- shortcut.delete_objectiveDelete objective
- shortcut.delete_story_linkDelete story link
- shortcut.delete_linked_fileDelete linked file
- shortcut.delete_custom_fieldDelete custom field
- shortcut.delete_epic_commentDelete epic comment
- shortcut.delete_story_commentDelete story comment
Shortcut in three steps.
- 01Your users connect ShortcutThey add their Shortcut api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create doc” can wait for the user, and “delete doc” can be denied outright.
- 03Any agent can actYour agent calls Shortcut through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('shortcut', { read: 'allow', write: 'ask', // create_doc destructive: 'deny', // delete_doc }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Shortcut connects.
Users add their Shortcut api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Shortcut connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Shortcut from any agent.
More project management apps.
Shortcut and Arc0, answered.
Can I use Shortcut with Claude, ChatGPT or Cursor?
Yes. Connect Shortcut to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Shortcut actions you allow.
How do users connect Shortcut?
Users add their Shortcut api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Shortcut actions can my agent take?
142 in total: 69 read, 51 write and 22 destructive, such as “create doc”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Shortcut?
Yes. Actions like “delete doc” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Shortcut too?
Yes. The same Shortcut connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Shortcut into your agent.
Your users connect Shortcut once, under your brand. Your agent gets 142 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan