Tasks from an AI assistant or script
You can read, create and update tasks without the web page: from an AI assistant connected through MCP, or from a script that calls Hunto's API with an API key. Both do exactly what you could do yourself, as you, in your organisation, and nothing more.
There is no Tasks command in the Hunto command-line tool at present. Use the API or MCP, or the web page.
Before you start
- Decide the access. Reading tasks needs the
tasks:readpermission, and creating or changing them needstasks:write(write includes read). Requesting a review of a finding also needs Monitoring access on your account. - Create the key or connection as described in Connect an AI assistant to Hunto (MCP): open API Management, create a key, tick only the scopes the agent needs, choose an expiry, and copy the key when it is shown (it starts with
hnt_). For an assistant that supports sign-in, choose the tasks permissions on the Authorize access page. - A key or sign-in only ever acts with the access its owner already has, in the owner's organisation.
Through an AI assistant (MCP)
Once connected, the assistant sees these task tools.
| Tool | Permission | What it does |
|---|---|---|
tasksQuery |
tasks:read |
Lists tasks. Options: scope (all or mine), search (up to 200 characters, matched against title, task ID and linked record), limit (1 to 100) and skip for paging. It does not filter by status or severity; ask the assistant to read the rows and filter them itself. |
tasksViewTask |
tasks:read |
Reads one task by its ID (TSK-...), with its details. |
tasksReviewKinds |
tasks:read |
Lists the kinds of check you can ask for on a finding. |
tasksCreate |
tasks:write |
Creates a task. Options: title (required), description, assignee, severity, status, parent (to make a subtask) and dueDate. |
tasksPatch |
tasks:write |
Changes one task: give the id and a changes object. Can set title, description, assignee, team, status, severity, points, due date, notification model, linked record (ref), type and parent. |
tasksRequestReview |
tasks:write |
Asks for a check on a finding, as Ask for a check does. See Asking Hunto to check a finding. |
Things to know:
- Numbers are sent as text. Status and severity are the digits below, written as strings (for example
"0"), not words.
| Status | Value | Severity | Value |
|---|---|---|---|
| Not assigned | "0" |
Critical | "0" |
| Not started | "1" |
High | "1" |
| In progress | "2" |
Medium (default) | "2" |
| In review | "3" |
Low | "3" |
| Rejected | "4" |
||
| Completed | "5" |
- Assignee is a username for a person, or
gp:followed by the group ID for a group. Do not send a person asus:name. - Due date is a day; it runs to the end of that day.
- Creating with an assignee gives a Not started task; without one, Not assigned. Moving a task to Completed records the completion time.
tasksCreatecannot set the linked record, team, points or type. Create the task, then usetasksPatchto add them.- Archiving, restoring and comments are not offered as tools. Do those from the web page or the API.
Tell your assistant plainly what you want and give it the IDs; it will pick the tool. It is worth asking it to show you what it is about to create or change before it does, especially when it is acting on many tasks.
Through the API
Every action is a POST to https://<region>.hunto.ai/api/monitor/tasks/<action> with a JSON body, sent with your key:
curl -X POST https://in.hunto.ai/api/monitor/tasks/create \
-H "Authorization: Bearer hnt_…" \
-H "Content-Type: application/json" \
-d '{"title":"Renew the TLS certificate on portal.example.com","severity":"1","dueDate":"2026-10-15","assignee":"alice"}'| Action | Purpose |
|---|---|
query |
List tasks with counts. Parameters: scope, search, limit, skip. |
viewTask |
One task by id. |
create |
Create a task (fields as for the MCP tool). |
patch |
Change one task: id and changes. |
bulkPatch |
The same change on many tasks. |
archive and restore |
Soft-delete and bring back tasks (and their subtasks). Only an administrator, or the owner, creator or assignee of every task listed, can do this. |
addComment |
Add a comment, optionally internal (administrators only) or with notification. |
analytics |
The figures behind Task Analytics. |
import |
Upload a spreadsheet of tasks. |
reviewKinds, requestReview |
The review-request calls. |
query returns the matching rows, the total and counts for the scope; analytics returns the totals, the breakdowns by status, severity and assignee, the daily created and completed trend, the on-time rate, the cycle time and the three attention lists, for a 7, 30 or 90 day window and a scope of all or mine.
The full list of actions and their parameters is in your organisation's API reference under the tasks tag.
Good to know
- A change made with a key is recorded in the task's activity feed against the key's owner, like an edit made from the page.
- Prefer one
querywith alimitover manyviewTaskcalls. - Anyone with Tasks access can change any task, so a key with
tasks:writecan too. Give agent keys an expiry and the narrowest scope that works. - There is no permanent delete, so a mistake made by an assistant can be undone by restoring the tasks or changing the fields back.
Ideas
See Use cases and wiring tips, especially "Let an assistant open and triage tasks".