The Shortcut connector.
Stories, epics and iterations. Connect once with your own key. Every agent your team runs reads the same 6 tools under one permission model.
How access is governed
6
Read tools
Open by default. They run when called, and every call is logged with the endpoint, tool and capability.
0
Write tools
Shortcut exposes no write tools. Nothing it does mutates external state.
0
Destructive tools
Shortcut defines no destructive tools. Nothing here deletes data.
Defaults come from the capability on each tool definition, and an admin can tighten or open any tool individually. The endpoint's capability ceiling can only tighten that policy. An endpoint scoped to read never surfaces a write tool.
Every Shortcut tool
6 tools, named as the agent sees them.
- search_storiesread
Search stories with Shortcut's search syntax (e.g. 'state:"In Progress" owner:alice', 'is:story !is:done epic:42'). The main entry point — returns story ids to pass to get_story.
- get_storyread
Get one story in full — description, tasks and comment thread included. Takes a numeric story id from search_stories.
- list_epicsread
List every epic in the workspace with its state and progress stats. Use it to resolve the epic_id carried on a story into a name.
- list_iterationsread
List iterations (sprints) with their date ranges, status and point stats. Resolves the iteration_id on a story, and answers "what is in the current sprint".
- list_membersread
List workspace members. Use it to turn the owner_ids / requested_by_id UUIDs on a story into people's names.
- list_workflowsread
List workflows and their states. Use it to turn the workflow_state_id on a story into a column name like "In Progress", and to learn the valid state names for search_stories.
Use it from any agent
The same Shortcut tools reach Claude Code, Cursor, Claude Desktop or your own agent through one MCP endpoint. The endpoint is scoped to a group, the token is issued per group and revocable from the dashboard, and an allowed-tool list and capability ceiling limit what it exposes. Reads run. Gated writes refuse unless an admin opens them. Destructive tools remain unavailable over MCP.
{
"mcpServers": {
"growth": {
"type": "http",
"url": "https://app.notara.ai/mcp/g/acme/growth",
"headers": {
"Authorization": "Bearer ntr_mcp_xxxxxxxxxxxxxxxxxxxx"
}
}
}
}The URL and token are placeholders. Real endpoints are issued per group from the dashboard.
Setup
- 01
Create a Shortcut API Token in your Shortcut account (where to find it). The key is yours: Notara stores it encrypted and never sees a bill.
- 02
Paste it into the Notara dashboard. Credentials can be scoped to the workspace or to one person.
- 03
The tools appear with their capability defaults already set. Tighten or open any of them per tool, then invite the agent to a channel or issue an MCP token.
Connect Shortcut once. Use it everywhere.
Use Notara directly, or bring us the workflow that needs to be redesigned and built.