Toggl for AI agents
Toggl is a time tracking tool for logging work hours, projects, and clients, used by freelancers and teams that need accurate records of billable time. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Toggl.
Create a time entry
Log time spent on a project or task for later reporting.
Get the current time entry
Check whether a timer is currently running, a read-only status check.
Confirm before deleting a client
Check with the user before deleting a client, since projects and time entries reference it.
56 Toggl actions, graded by risk.
Every Toggl action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
34Look things up. Allowed by default.
- toggl.get_keysGet JWKS Keys
- toggl.get_tagsGet Tags
- toggl.get_tasksList Tasks
- toggl.get_statusGet Webhooks Status
- toggl.get_my_quotaGet My Quota
- toggl.get_projectsGet Projects
- toggl.get_all_plansGet All Plans
- toggl.get_countriesGet Countries
- toggl.get_timezonesGet Timezones
- toggl.get_user_tagsGet User Tags
- toggl.get_currenciesGet Currencies
- toggl.get_time_entryGet Time Entry
- toggl.get_user_tasksGet User Tasks
- toggl.get_my_locationGet My Location
- toggl.get_list_clientsList Clients
- toggl.get_time_entriesGet Time Entries
write
15Create and change things. Allow, or ask the user first.
- toggl.create_tagCreate Tag
- toggl.create_groupCreate Group
- toggl.create_clientCreate Client
- toggl.update_clientUpdate Client
- toggl.create_projectCreate Project
- toggl.send_demo_emailSend Demo Email
- toggl.send_smail_meetSend Smail Meet
- toggl.create_invitationCreate Invitation
- toggl.create_time_entryCreate Time Entry
- toggl.send_email_contactSend Email to Contact
- toggl.create_organizationCreate Organization
- toggl.create_workspaces_project_usersAdd User to Workspace Project
- toggl.put_update_tagUpdate Tag
- toggl.edit_time_entriesBulk Edit Time Entries
- toggl.patch_stop_time_entryStop Time Entry
destructive
7Delete, cancel or archive. Ask first, or deny outright.
- toggl.delete_tagDelete Tag
- toggl.delete_groupDelete Group
- toggl.delete_clientDelete Toggl Client
- toggl.delete_subscriptionDelete Subscription
- toggl.delete_project_groupDelete Project Group
- toggl.disable_weekly_reportDisable Weekly Report
- toggl.post_me_disable_product_emailsDisable Product Emails
Toggl in three steps.
- 01Your users connect TogglThey add their Toggl api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Tag” can wait for the user, and “delete Tag” can be denied outright.
- 03Any agent can actYour agent calls Toggl through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('toggl', { read: 'allow', write: 'ask', // create_tag destructive: 'deny', // delete_tag }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Toggl connects.
Users add their Toggl api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Toggl connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Toggl from any agent.
Toggl and Arc0, answered.
Can I use Toggl with Claude, ChatGPT or Cursor?
Yes. Connect Toggl to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Toggl actions you allow.
How do users connect Toggl?
Users add their Toggl api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Toggl actions can my agent take?
56 in total: 34 read, 15 write and 7 destructive, such as “create Tag”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Toggl?
Yes. Actions like “delete Tag” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Toggl too?
Yes. The same Toggl connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Toggl into your agent.
Your users connect Toggl once, under your brand. Your agent gets 56 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan