Skip to content
view raw .md

Plan · Comments & files

Comments, reactions, attachments, and each task's activity feed and event log. Part of the Dailybot Plan API (Beta).

On this page

Beta

Plan is in beta. Everything under /plan in the web app, the CLI and agent skill commands for projects, goals, boards and tasks, and the /v1/plan/ public API may change before general availability. Want to try it with your team? Write to [email protected].

GET/v1/plan/tasks/{task_id}/comments/BetaAPI keyCLI AuthPage-number pagination

List a task's comments

The task's comments, oldest first, as a page. Each comment carries its reactions and its ready attachments. Use updated_since to fetch only what changed since your last read.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.

Query parameters

NameTypeRequiredDescription
pageintegerOptional1-based page number.
page_sizeintegerOptionalRows per page. Default 50, maximum 100. Out-of-range values are clamped, never rejected: asking for 500 returns 100.
updated_sincestringOptionalA timestamp filter on this paginated list: it returns {count, next, previous, results}, never a cursor. For a change feed use the board delta endpoint.

TaskComment object

NameTypeRequiredDescription
uuiduuidRequiredStable public identifier.
bodystringRequiredMarkdown as typed. Mention someone with <@DB@{uuid}>, using a uuid from the mentionables list. Max 10000 characters.
authorActorRef | nullRequiredWho wrote the comment. See ActorRef.
executed_by_agentobject | nullOptionalThe agent that executed this on behalf of the person, or null when no agent was named: an object with uuid, name, username and avatar. The person in the author field is still the author; the agent is shown as the one who executed it.
mentionsarray<ActorRef>OptionalThe people mentioned. Read them from here, never by parsing body. See ActorRef.
body_htmlstringOptionalbody rendered and sanitized by the server. Client HTML is never accepted.
reactionsarrayOptionalEmoji reactions, with whether you reacted. All fields are always present. Items: {emoji: string, count: integer, reacted: boolean}.
provenanceenumRequiredtyped by a person, agent_authored, or retrieved from another system. One of typed, agent_authored, retrieved.
parent_commentuuid | nullOptionalThe comment this one replies to. One level of threading only.
edited_atdate-time | nullOptionalWhen the comment was last edited.
is_deletedbooleanOptionalDeleted comments keep their row with a blank body.
created_atdate-timeRequiredWhen the row was created.
attachmentsarray<TaskAttachment>OptionalThe comment's ready attachments, ordered by position. See TaskAttachment.

ActorRef object

NameTypeRequiredDescription
kindstringRequired—
uuidstringRequiredStable public identifier.
namestringOptionalDisplay name.
usernamestring | nullOptional—
avatar_urlstring | nullOptional—
has_photobooleanOptional—

TaskAttachment object

NameTypeRequiredDescription
uuiduuidRequiredStable public identifier.
filenamestringRequiredFile name.
content_typestringRequiredMIME type.
sizeintegerRequiredSize in bytes.
urlstringRequiredWhere to download the file.
thumbnail_urluri | nullOptionalThumbnail for images.
widthinteger | nullOptional—
heightinteger | nullOptional—
statusenumRequiredCurrent status. One of pending, ready, scanning, rejected.
uploaded_byActorRef | nullOptionalWho uploaded the file. See ActorRef.
executed_by_agentobject | nullOptionalThe agent that executed this on behalf of the person, or null when no agent was named: an object with uuid, name, username and avatar. The person in the author field is still the author; the agent is shown as the one who executed it.
created_atdate-timeRequiredWhen the row was created.

Response

NameTypeRequiredDescription
countintegerRequiredTotal number of rows.
nexturiRequiredURL of the next page, or null.
previousuriRequiredURL of the previous page, or null.
resultsarray<TaskComment>RequiredThe rows on this page. See TaskComment.

Errors

StatusWhen
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:read`.
  • Rate limit: 120 reads per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
POST/v1/plan/tasks/{task_id}/comments/BetaAPI keyCLI Auth

Comment on a task

Adds a comment to the task. Mention someone with <@DB@{uuid}>, using a uuid from the board's mentionables. Send an Idempotency-Key to retry safely.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.

Headers

NameTypeRequiredDescription
Idempotency-KeystringOptionalA key you generate for this intent. A replay with the same key and body returns the first response without a second side effect and carries Idempotency-Replayed: true. Keys are kept for 24 hours. The same key with a different body is 409 idempotency_key_payload_mismatch; a repeat while the first call is still running gets 409 idempotency_in_progress for up to 120 seconds.
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Request body

NameTypeRequiredDescription
bodystringRequiredMarkdown. Mention someone with <@DB@{uuid}>, using a uuid from the mentionables list. Max 10000 characters.
parent_commentuuid | nullOptionalThe comment this one replies to. One level of threading only.
agent_namestringOptionalThe name of the agent that executed this write on the person's behalf (max 128 characters, blank means no agent). Takes priority over the X-Dailybot-Agent-Name header. See Agent attribution.

Response

NameTypeRequiredDescription
(body)TaskCommentRequiredA TaskComment object.

Errors

StatusWhen
400Validation failed, or a filter, sort or `include` value was not recognised. The response `code` says which. `invalid_agent_attribution` means the agent name is invalid.
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS -X POST "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{
    "body": "Looks good. <@DB@00000000-0000-4000-8000-00000000000c> can you review the rollout plan?"
  }'

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
PATCH/v1/plan/tasks/{task_id}/comments/{comment_id}/BetaAPI keyCLI Auth

Edit a comment

Edits a comment's body. Only its author can edit it (403 comment_not_author); the response sets edited_at.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
comment_idstringRequiredThe comment's uuid.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Request body

NameTypeRequiredDescription
bodystringRequiredMarkdown. Mention someone with <@DB@{uuid}>, using a uuid from the mentionables list. Max 10000 characters.
parent_commentuuid | nullOptionalThe comment this one replies to. One level of threading only.
agent_namestringOptionalThe name of the agent that executed this write on the person's behalf (max 128 characters, blank means no agent). Takes priority over the X-Dailybot-Agent-Name header. See Agent attribution.

Response

NameTypeRequiredDescription
(body)TaskCommentRequiredA TaskComment object.

Errors

StatusWhen
400The agent name is invalid (`invalid_agent_attribution`).
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
403Authenticated but not allowed: missing scope (`insufficient_scope`, which is also what an agent or organization key gets on an operation that needs a person, and what a personal key gets when its explicit Plan scopes do not cover the endpoint) or a guest account (`guest_not_allowed`).
404Not found, or not visible to you. Both cases return the same body.
curl -sS -X PATCH "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/00000000-0000-4000-8000-000000000008/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "body": "Looks good. Rollout plan attached."
  }'

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
DELETE/v1/plan/tasks/{task_id}/comments/{comment_id}/BetaAPI keyCLI Auth

Delete a comment

A soft delete: the row survives so its events keep resolving, and the body is blanked.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
comment_idstringRequiredThe comment's uuid.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Errors

StatusWhen
400The agent name is invalid (`invalid_agent_attribution`).
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
403Authenticated but not allowed: missing scope (`insufficient_scope`, which is also what an agent or organization key gets on an operation that needs a person, and what a personal key gets when its explicit Plan scopes do not cover the endpoint) or a guest account (`guest_not_allowed`).
404Not found, or not visible to you. Both cases return the same body.
curl -sS -X DELETE "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/00000000-0000-4000-8000-000000000008/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
POST/v1/plan/tasks/{task_id}/comments/{comment_id}/reactions/BetaAPI keyCLI Auth

Add an emoji reaction to a comment (idempotent)

Adds your emoji reaction to the comment. It is idempotent: adding the same reaction again changes nothing. The response is the comment with its updated reactions.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
comment_idstringRequiredThe comment's uuid.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Request body

NameTypeRequiredDescription
emojistringRequiredThe emoji. Max 32 characters.
agent_namestringOptionalThe name of the agent that executed this write on the person's behalf (max 128 characters, blank means no agent). Takes priority over the X-Dailybot-Agent-Name header. See Agent attribution.

Response

NameTypeRequiredDescription
(body)TaskCommentRequiredA TaskComment object.

Errors

StatusWhen
400Validation failed, or a filter, sort or `include` value was not recognised. The response `code` says which. `invalid_agent_attribution` means the agent name is invalid.
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS -X POST "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/00000000-0000-4000-8000-000000000008/reactions/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "emoji": "👍"
  }'

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
DELETE/v1/plan/tasks/{task_id}/comments/{comment_id}/reactions/{emoji}/BetaAPI keyCLI Auth

Remove the caller's emoji reaction from a comment

Removes your reaction with this emoji from the comment. It answers 204 even when the reaction was already gone.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
comment_idstringRequiredThe comment's uuid.
emojistringRequiredThe emoji to remove, as sent when adding it (max 32 characters), URL-encoded in the path.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Errors

StatusWhen
400Validation failed, or a filter, sort or `include` value was not recognised. The response `code` says which. `invalid_agent_attribution` means the agent name is invalid.
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS -X DELETE "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/00000000-0000-4000-8000-000000000008/reactions/%F0%9F%91%8D/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
GET/v1/plan/tasks/{task_id}/comments/{comment_id}/attachments/BetaAPI keyCLI AuthPage-number pagination

List a comment's attachments

The comment's attachments, ordered by position. The comment itself already carries its ready attachments in attachments. Each url is a download link. Do not store it: keep the attachment uuid and read it again when you need the file.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
comment_idstringRequiredThe comment's uuid.

Query parameters

NameTypeRequiredDescription
pageintegerOptional1-based page number.
page_sizeintegerOptionalRows per page. Default 50, maximum 100. Out-of-range values are clamped, never rejected: asking for 500 returns 100.

Response

NameTypeRequiredDescription
countintegerRequiredTotal number of rows.
nexturiRequiredURL of the next page, or null.
previousuriRequiredURL of the previous page, or null.
resultsarray<TaskAttachment>RequiredThe rows on this page. See TaskAttachment.

Errors

StatusWhen
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404The task, comment or attachment does not exist or you cannot see it (`not_found`), never a 403.
curl -sS "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/00000000-0000-4000-8000-000000000008/attachments/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:read`.
  • Rate limit: 120 reads per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
POST/v1/plan/tasks/{task_id}/comments/{comment_id}/attachments/BetaAPI keyCLI Auth

Upload an attachment to a comment

Attach a file to a comment. Only the comment's author can attach to it. Send multipart/form-data with the file field and an optional caption; there is no presign flow here. The limit is 5 MiB in every environment: a larger file is 400 attachment_too_large, with extra.max_size_bytes. The file type is checked from its content against the same list as task attachments (attachment_invalid_type). A comment holds at most 50 attachments (attachment_limit_reached).

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
comment_idstringRequiredThe comment's uuid.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Request body

NameTypeRequiredDescription
filebinaryRequiredThe file to upload (max 5 MiB this way).
captionstringOptionalOptional caption. Max 255 characters.

Response

NameTypeRequiredDescription
(body)TaskAttachmentRequiredA TaskAttachment object.

Errors

StatusWhen
400The file is missing, too large (`attachment_too_large`, over 5 MiB), of an unsupported type (`attachment_invalid_type`), or the limit of 50 is reached (`attachment_limit_reached`). `invalid_agent_attribution` means the agent name is invalid.
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
403You are not the comment's author (`comment_not_author`).
404The task, comment or attachment does not exist or you cannot see it (`not_found`), never a 403.
curl -sS -X POST "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/00000000-0000-4000-8000-000000000008/attachments/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY" \
  -F "file=@./screenshot.png" \
  -F "caption=Staging dashboard"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
GET/v1/plan/tasks/{task_id}/comments/{comment_id}/attachments/{attachment_id}/content/BetaAPI keyCLI Auth

Download a comment attachment's bytes

Streams the file with the content type recorded at upload, X-Content-Type-Options: nosniff and Cache-Control: no-store. It never redirects to storage. Authorized like every other read of the task.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
comment_idstringRequiredThe comment's uuid.
attachment_idstringRequiredThe attachment's uuid.

Errors

StatusWhen
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404The task, comment or attachment does not exist or you cannot see it (`not_found`), never a 403.
curl -sS "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/00000000-0000-4000-8000-000000000008/attachments/00000000-0000-4000-8000-000000000009/content/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:read`.
  • Rate limit: 120 reads per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
DELETE/v1/plan/tasks/{task_id}/comments/{comment_id}/attachments/{attachment_id}/BetaAPI keyCLI Auth

Remove an attachment from a comment

Removes the attachment from the comment. Allowed for the person who uploaded it, the comment's author or an organization admin.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
comment_idstringRequiredThe comment's uuid.
attachment_idstringRequiredThe attachment's uuid.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Errors

StatusWhen
400The agent name is invalid (`invalid_agent_attribution`).
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
403You are not the uploader, the comment's author or an organization admin (`attachment_delete_forbidden`).
404The task, comment or attachment does not exist or you cannot see it (`not_found`), never a 403.
curl -sS -X DELETE "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/00000000-0000-4000-8000-000000000008/attachments/00000000-0000-4000-8000-000000000009/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
GET/v1/plan/tasks/{task_id}/attachments/BetaAPI keyCLI AuthPage-number pagination

List a task's attachments

The task's attachments, ordered by position, as a page. Each url is a download link; do not store it. Read the attachment again for the current one, or download through the content endpoint.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.

Query parameters

NameTypeRequiredDescription
pageintegerOptional1-based page number.
page_sizeintegerOptionalRows per page. Default 50, maximum 100. Out-of-range values are clamped, never rejected: asking for 500 returns 100.

Response

NameTypeRequiredDescription
countintegerRequiredTotal number of rows.
nexturiRequiredURL of the next page, or null.
previousuriRequiredURL of the previous page, or null.
resultsarray<TaskAttachment>RequiredThe rows on this page. See TaskAttachment.

Errors

StatusWhen
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS "https://api.dailybot.com/v1/plan/tasks/ENG-142/attachments/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:read`.
  • Rate limit: 120 reads per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
POST/v1/plan/tasks/{task_id}/attachments/BetaAPI keyCLI Auth

Upload an attachment in one request

Upload a file in one request, up to 5 MiB. For files up to 25 MiB, use presign → upload → confirm.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Request body

NameTypeRequiredDescription
filebinaryRequiredThe file to upload (max 5 MiB this way).
captionstringOptionalOptional caption. Max 255 characters.

Response

NameTypeRequiredDescription
(body)TaskAttachmentRequiredA TaskAttachment object.

Errors

StatusWhen
400Validation failed, or a filter, sort or `include` value was not recognised. The response `code` says which. `invalid_agent_attribution` means the agent name is invalid.
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS -X POST "https://api.dailybot.com/v1/plan/tasks/ENG-142/attachments/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY" \
  -F "file=@./screenshot.png" \
  -F "caption=Staging dashboard"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
POST/v1/plan/tasks/{task_id}/attachments/presign/BetaAPI keyCLI Auth

Reserve an attachment and receive an upload target

Reserve an attachment and get an upload target. The declared size may be up to 25 MiB when the server has object storage; otherwise uploads are capped at 5 MiB and larger declarations are refused with attachment_too_large.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Request body

NameTypeRequiredDescription
filenamestringRequiredFile name. Max 255 characters.
content_typestringRequiredMIME type. Max 127 characters.
sizeintegerRequiredSize in bytes. From 1 to 26214400.
agent_namestringOptionalThe name of the agent that executed this write on the person's behalf (max 128 characters, blank means no agent). Takes priority over the X-Dailybot-Agent-Name header. See Agent attribution.

TaskAttachmentPresignResponse object

NameTypeRequiredDescription
upload_urlstringRequiredWhere to upload the bytes.
methodstringRequiredHTTP method for the upload.
headersobjectRequiredHeaders to send with the upload.
expires_inintegerRequiredSeconds until the upload target expires.
attachmentTaskAttachmentRequiredThe pending attachment. See TaskAttachment.

Response

NameTypeRequiredDescription
(body)TaskAttachmentPresignResponseRequiredA TaskAttachmentPresignResponse object.

Errors

StatusWhen
400Validation failed, or a filter, sort or `include` value was not recognised. The response `code` says which. `invalid_agent_attribution` means the agent name is invalid.
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS -X POST "https://api.dailybot.com/v1/plan/tasks/ENG-142/attachments/presign/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "filename": "screenshot.png",
    "content_type": "image/png",
    "size": 482133
  }'

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
GET/v1/plan/tasks/{task_id}/attachments/{attachment_id}/content/BetaAPI keyCLI Auth

Download an attachment's bytes through the API

Streams the file, authorized like every other read of the task. On servers without object storage, this is the attachment's url; otherwise url is a download link and this endpoint is the alternative for clients that prefer to send their credential. 409 attachment_not_ready if the upload was never completed.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
attachment_idstringRequiredThe attachment's uuid.

Errors

StatusWhen
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
409The upload was never completed or confirmed (`attachment_not_ready`).
curl -sS "https://api.dailybot.com/v1/plan/tasks/ENG-142/attachments/00000000-0000-4000-8000-000000000009/content/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:read`.
  • Rate limit: 120 reads per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
PUT/v1/plan/tasks/{task_id}/attachments/{attachment_id}/content/BetaAPI keyCLI Auth

Upload bytes for a presigned attachment (local/dev fallback)

Upload the bytes for a presigned attachment when the upload target points back at the API (servers without object storage). Capped at 5 MiB.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
attachment_idstringRequiredThe attachment's uuid.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Response

NameTypeRequiredDescription
(body)TaskAttachmentRequiredA TaskAttachment object.

Errors

StatusWhen
400Validation failed, or a filter, sort or `include` value was not recognised. The response `code` says which. `invalid_agent_attribution` means the agent name is invalid.
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS -X PUT "https://api.dailybot.com/v1/plan/tasks/ENG-142/attachments/00000000-0000-4000-8000-000000000009/content/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY" \
  -H "Content-Type: image/png" \
  --data-binary @./screenshot.png

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
POST/v1/plan/tasks/{task_id}/attachments/{attachment_id}/confirm/BetaAPI keyCLI Auth

Mark a presigned attachment ready after upload

The last step of presign → upload → confirm: marks the attachment ready once its bytes are uploaded. Until then, downloading it answers 409 attachment_not_ready.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
attachment_idstringRequiredThe attachment's uuid.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Response

NameTypeRequiredDescription
(body)TaskAttachmentRequiredA TaskAttachment object.

Errors

StatusWhen
400The agent name is invalid (`invalid_agent_attribution`).
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS -X POST "https://api.dailybot.com/v1/plan/tasks/ENG-142/attachments/00000000-0000-4000-8000-000000000009/confirm/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
DELETE/v1/plan/tasks/{task_id}/attachments/{attachment_id}/BetaAPI keyCLI Auth

Remove an attachment

Removes the attachment from the task. The stored file is deleted when nothing else references it.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
attachment_idstringRequiredThe attachment's uuid.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Errors

StatusWhen
400The agent name is invalid (`invalid_agent_attribution`).
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
403Authenticated but not allowed: missing scope (`insufficient_scope`, which is also what an agent or organization key gets on an operation that needs a person, and what a personal key gets when its explicit Plan scopes do not cover the endpoint) or a guest account (`guest_not_allowed`).
404Not found, or not visible to you. Both cases return the same body.
curl -sS -X DELETE "https://api.dailybot.com/v1/plan/tasks/ENG-142/attachments/00000000-0000-4000-8000-000000000009/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
GET/v1/plan/tasks/{task_id}/events/BetaAPI keyCLI AuthPage-number pagination

A task's activity, rendered from the event log

Events carry ids, enum members, numbers, booleans and dates — never user prose. There is no title, description, comment body or label name in a payload. Join what you are entitled to read: comment bodies come from the comments endpoint, titles from the task itself.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.

Query parameters

NameTypeRequiredDescription
pageintegerOptional1-based page number.
page_sizeintegerOptionalRows per page. Default 50, maximum 100. Out-of-range values are clamped, never rejected: asking for 500 returns 100.
event_typearrayOptionalFilter to one or more event types.

TaskEvent object

NameTypeRequiredDescription
uuidstringRequiredStable public identifier.
event_typestringRequiredThe event type. New types are added over time: ignore ones you do not recognise.
entityobjectOptional—
payloadobjectOptionalIds, enum values, numbers, booleans and dates only, never user-written text.
actorobjectOptionalWho acted.
executed_by_agentobject | nullOptionalThe agent that executed this on behalf of the person, or null when no agent was named: an object with uuid, name, username and avatar. The person in the author field is still the author; the agent is shown as the one who executed it.
originstringOptional—
correlation_idstring | nullOptional—
observed_atstringOptionalWhen it was recorded.
occurred_atstringRequiredWhen it happened.

Response

NameTypeRequiredDescription
countintegerRequiredTotal number of rows.
nexturiRequiredURL of the next page, or null.
previousuriRequiredURL of the previous page, or null.
resultsarray<TaskEvent>RequiredThe rows on this page. See TaskEvent.

Errors

StatusWhen
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS "https://api.dailybot.com/v1/plan/tasks/ENG-142/events/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:read`.
  • Rate limit: 120 reads per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
GET/v1/plan/tasks/{task_id}/activity/BetaAPI keyCLI AuthPage-number pagination

A task's activity feed, enriched for display

Paginated, with the same row shape as GET /v1/plan/activity/ (task card plus resolved changes[{field, from, to}]). This is what ?include=activity embeds on task detail. For the raw event log use GET …/tasks/{task_id}/events/.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.

Query parameters

NameTypeRequiredDescription
pageintegerOptional1-based page number.
page_sizeintegerOptionalRows per page. Default 50, maximum 100. Out-of-range values are clamped, never rejected: asking for 500 returns 100.

ActivityEvent object

NameTypeRequiredDescription
uuidstringRequiredStable public identifier.
typestringRequiredThe event type. New types are added over time: ignore ones you do not recognise.
actorobjectRequiredWho acted.
executed_by_agentobject | nullOptionalThe agent that executed this on behalf of the person, or null when no agent was named: an object with uuid, name, username and avatar. The person in the author field is still the author; the agent is shown as the one who executed it.
created_atstringRequiredWhen the row was created.
taskobjectOptionalShape: {uuid, key, title, board {uuid, key, name} | null} | null.
payloadobjectRequiredIds, enum values, numbers, booleans and dates only, never user-written text.
changesarrayRequiredResolved field changes, [{field, from, to}].

Response

NameTypeRequiredDescription
countintegerRequiredTotal number of rows.
nexturiRequiredURL of the next page, or null.
previousuriRequiredURL of the previous page, or null.
resultsarray<ActivityEvent>RequiredThe rows on this page. See ActivityEvent.

Errors

StatusWhen
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404Not found, or not visible to you. Both cases return the same body.
curl -sS "https://api.dailybot.com/v1/plan/tasks/ENG-142/activity/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:read`.
  • Rate limit: 120 reads per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
GET/v1/plan/attachments/resolve/BetaAPI keyCLI Auth

Resolve attachment references

Turns the attachment references you hold (for example the attachment:{uuid} markers in a description, or a stored content_url) into each attachment's current url. Pass 1 to 50 uuids in ids, separated by commas; it covers task, comment, project, goal, board, milestone and project-update attachments. An id that does not exist, that you cannot see, or whose attachment is not ready is simply absent from resolved: the three cases look the same and there is no error. Do not store url and do not paste it into public places: treat it as opaque. url_expires_at is either null or an ISO timestamp, so ask again when you render. To download, prefer GET …/attachments/{attachment_id}/content/ with your credential.

Query parameters

NameTypeRequiredDescription
idsstringRequiredAttachment uuids, separated by commas.

Response

NameTypeRequiredDescription
resolvedobjectRequiredA map from each attachment uuid you can see to {url, url_expires_at}. Absent ids are not listed.
resolved.{uuid}.urlstringRequiredThe attachment's current download link.
resolved.{uuid}.url_expires_atstring | nullRequiredWhen the link stops working, as an ISO datetime, or null when it has no expiry.

Errors

StatusWhen
400`ids` is empty or holds a malformed uuid (`invalid_filter_value`, refused rather than skipped), or has more than 50 values (`too_many_filter_values`).
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
curl -sS "https://api.dailybot.com/v1/plan/attachments/resolve/?ids=00000000-0000-4000-8000-000000000009,00000000-0000-4000-8000-000000000010" \
  -H "Authorization: Bearer $DAILYBOT_TOKEN"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:read`.
  • Rate limit: 120 reads per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
PATCH/v1/plan/tasks/{task_id}/comments/{comment_id}/attachments/{attachment_id}/BetaAPI keyCLI Auth

Rename a comment attachment

Changes the display file name; the stored bytes do not change. Anyone who may write to the parent can rename its attachments.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
comment_idstringRequiredThe comment's uuid.
attachment_iduuidRequiredThe attachment's uuid.

Headers

NameTypeRequiredDescription
X-Dailybot-Agent-NamestringOptionalThe name of the agent that executed this write on the person's behalf. Use it on multipart and body-less writes (DELETE, archive, restore); on JSON writes send the body field agent_name instead, which wins if both are present. Percent-encode the value as UTF-8. Control characters are stripped; a blank value means no agent. More than 128 characters, or a value that cannot be decoded, is 400 invalid_agent_attribution (never truncated). An agent-type key, which is not bound to a person, gets 400 invalid_agent_attribution if it sends it. The stamp never changes a permission answer. See Agent attribution.

Request body

NameTypeRequiredDescription
filenamestringRequiredThe new file name (1–255 characters). The stored bytes do not change.
agent_namestringOptionalThe name of the agent that executed this write on the person's behalf (max 128 characters, blank means no agent). Takes priority over the X-Dailybot-Agent-Name header. See Agent attribution.

Response

NameTypeRequiredDescription
(body)TaskAttachmentRequiredA TaskAttachment object.

Errors

StatusWhen
400Validation failed; the response `code` says which field. `invalid_agent_attribution` means the agent name is invalid.
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
403You may not write here (`insufficient_scope`), or you are a guest (`guest_not_allowed`).
404The parent or the attachment does not exist or you cannot see it (`not_found`), never a 403.
curl -sS -X PATCH "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/00000000-0000-4000-8000-000000000008/attachments/00000000-0000-4000-8000-000000000009/" \
  -H "X-API-KEY: $DAILYBOT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "filename": "spec-v2.pdf"
}'

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:write`.
  • Rate limit: 60 writes per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.
GET/v1/plan/tasks/{task_id}/comments/{comment_id}/reactions/BetaAPI keyCLI AuthPage-number pagination

List who reacted to a comment

Everyone who reacted, oldest first, as a page: the full list behind the capped users preview on each of the comment's reactions. emoji narrows to one emoji.

Path parameters

NameTypeRequiredDescription
task_idstringRequiredA task uuid or its key, such as ENG-142, including a key retired by a board rename. Resolution is scoped to your organization first, so another organization's key is a 404 identical to a missing one. Numeric ids are never accepted.
comment_idstringRequiredThe comment's uuid.

Query parameters

NameTypeRequiredDescription
pageintegerOptional1-based page number.
page_sizeintegerOptionalRows per page. Default 50, maximum 100. Out-of-range values are clamped, never rejected: asking for 500 returns 100.
emojistringOptionalOne emoji; every emoji when omitted. The same rule as writes: anything else is 400 reaction_invalid_emoji.

Reactor object

NameTypeRequiredDescription
emojistringRequired—
userActorRefRequiredWho reacted.
executed_by_agentAgentRef | nullOptionalThe agent that executed the reaction for that person, or null.
created_atdatetimeRequired—

ActorRef object

NameTypeRequiredDescription
kindstringRequired—
uuidstringRequiredStable public identifier.
namestringOptionalDisplay name.
usernamestring | nullOptional—
avatar_urlstring | nullOptional—
has_photobooleanOptional—

Response

NameTypeRequiredDescription
countintegerRequiredTotal number of rows.
nexturiRequiredURL of the next page, or null.
previousuriRequiredURL of the previous page, or null.
resultsarray<Reactor>RequiredThe page of Reactor objects.

Errors

StatusWhen
400`emoji` is not a single emoji (`reaction_invalid_emoji`), or a paging value is not valid.
401Missing, expired or malformed credential (`credential_absent`, `credential_expired`, `credential_malformed`).
402Plan is not enabled for your organization yet (`plan_upgrade_required`). Expected during the Beta: write to [email protected].
404The task or the comment does not exist or you cannot see it (`not_found`), never a 403.
curl -sS "https://api.dailybot.com/v1/plan/tasks/ENG-142/comments/00000000-0000-4000-8000-000000000008/reactions/?emoji=%F0%9F%91%8D" \
  -H "X-API-KEY: $DAILYBOT_API_KEY"

Try it

This is a copy-only helper — the request is not sent from your browser. Paste the command into your terminal to execute it.

  • Scope: `tasks:read`.
  • Rate limit: 120 reads per minute per actor.
  • Works with a login session, a CLI user token, a personal API key, or an agent or organization key. A personal key sees what its person sees; an agent or organization key acts as a system actor and sees organization-visible boards only.

This page is the reference for Plan · Comments & files. Every endpoint lives under https://api.dailybot.com/v1/plan/ and answers JSON.

Authenticate with a login session or a CLI user token (Authorization: Bearer …), or with an API key (X-API-KEY). A personal API key acts as its person and can do everything that person can do in Dailybot; an agent or organization key never acts as a person and is refused on the endpoints that need one. On an endpoint, the API key badge means an agent or organization key is accepted too. See Authentication for Plan, Authentication and Errors for the rules shared by every Dailybot API.

New to Plan? Read the overview for the model: projects, boards, workflow states, keys, ordering, versions and archive.