Shortcut for AI agents

Shortcut is project management software that aligns product development work, like stories and epics, with company objectives. Software teams use it to plan and track engineering work. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Project managementAPI keyMCP + RESTshortcut.com
AUDIT LOG · SHORTCUTPOLICY: acme-support
09:41:07 · claude · u_8f2read
shortcut.list_docs
List docs✓ allowed · 212ms
09:41:08 · claude · u_8f2read
shortcut.get_doc
Get doc✓ allowed · 164ms
09:41:09 · claude · u_8f2write
shortcut.create_doc
Create doc✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
shortcut.delete_doc
Delete doc✕ blocked · policy: deny
EVERY SHORTCUT CALL, ON THE RECORD
01 · USE CASES

What agents do in Shortcut.

01

Create a new story

Add a story to a team's backlog with the work details for an upcoming iteration.

02

Create an epic for a project

Group related stories under a new epic to track a larger body of work.

03

Confirm before deleting an epic

Check an epic's linked stories and get approval before deleting it, since that removes the grouping.

02 · ACTIONS

142 Shortcut actions, graded by risk.

Every Shortcut action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

69

Look things up. Allowed by default.

  • shortcut.get_doc
    Get doc
  • shortcut.get_epic
    Get epic
  • shortcut.get_file
    Get file
  • shortcut.get_task
    Get task
  • shortcut.get_group
    Get group
  • shortcut.get_label
    Get label
  • shortcut.get_story
    Get story
  • shortcut.list_docs
    List docs
  • shortcut.get_member
    Get member
  • shortcut.list_epics
    List epics
  • shortcut.list_files
    List files
  • shortcut.get_project
    Get project
  • shortcut.list_groups
    List groups
  • shortcut.list_labels
    List labels
  • shortcut.get_category
    Get category
  • shortcut.get_workflow
    Get workflow
+ 53 MORE

write

51

Create and change things. Allow, or ask the user first.

  • shortcut.create_doc
    Create doc
  • shortcut.update_doc
    Update Doc
  • shortcut.create_epic
    Create epic
  • shortcut.create_task
    Create task
  • shortcut.update_epic
    Update epic
  • shortcut.update_file
    Update file
  • shortcut.update_task
    Update task
  • shortcut.create_group
    Create group
  • shortcut.create_label
    Create label
  • shortcut.create_story
    Create story
  • shortcut.update_group
    Update group
  • shortcut.update_label
    Update label
  • shortcut.update_story
    Update story
  • shortcut.update_health
    Update health status
  • shortcut.create_project
    Create project
  • shortcut.update_project
    Update project
+ 35 MORE

destructive

22

Delete, cancel or archive. Ask first, or deny outright.

  • shortcut.delete_doc
    Delete doc
  • shortcut.delete_epic
    Delete epic
  • shortcut.delete_file
    Delete file
  • shortcut.delete_task
    Delete task
  • shortcut.delete_label
    Delete label
  • shortcut.delete_story
    Delete story
  • shortcut.delete_project
    Delete project
  • shortcut.delete_category
    Delete category
  • shortcut.delete_iteration
    Delete iteration
  • shortcut.delete_milestone
    Delete milestone
  • shortcut.delete_objective
    Delete objective
  • shortcut.delete_story_link
    Delete story link
  • shortcut.delete_linked_file
    Delete linked file
  • shortcut.delete_custom_field
    Delete custom field
  • shortcut.delete_epic_comment
    Delete epic comment
  • shortcut.delete_story_comment
    Delete story comment
+ 6 MORE
03 · HOW IT WORKS

Shortcut in three steps.

  1. 01Your users connect ShortcutThey add their Shortcut api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create doc” can wait for the user, and “delete doc” can be denied outright.
  3. 03Any agent can actYour agent calls Shortcut through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('shortcut', {
  read: 'allow',
  write: 'ask',        // create_doc
  destructive: 'deny',  // delete_doc
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Shortcut connects.

Users add their Shortcut api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Shortcut connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Shortcut from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Shortcut and Arc0, answered.

Q01

Can I use Shortcut with Claude, ChatGPT or Cursor?

Yes. Connect Shortcut to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Shortcut actions you allow.

Q02

How do users connect Shortcut?

Users add their Shortcut api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Shortcut actions can my agent take?

142 in total: 69 read, 51 write and 22 destructive, such as “create doc”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Shortcut?

Yes. Actions like “delete doc” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Shortcut too?

Yes. The same Shortcut connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Shortcut into your agent.

Your users connect Shortcut once, under your brand. Your agent gets 142 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan