Skip to main content

Working with the Leanmote API

A bridge to the developer documentation for the Leanmote REST, Metrics, SCIM, and OTLP APIs.

Leanmote's data is reachable programmatically. This article is the entry point: which surfaces exist, how to authenticate against them, and what each one is for.


​

The four API surfaces


​

  • REST API — https://api.leanmote.com/v1. Organizations, teams, users, boards, tasks, interactions, calendars, saved views and alert rules.

  • Metrics API — https://api.leanmote.com/v1/metrics/. The analytical payloads behind the dashboards: DORA, flow, collaboration and financial views. Same domain, separate service.

  • SCIM — https://api.leanmote.com/scim/v2. User and group provisioning for enterprise identity providers, with /Users, /Groups and ServiceProviderConfig. Requests and responses use application/scim+json.

  • OTLP ingest — telemetry from AI coding tools. The endpoint is generated per organization rather than being a fixed URL, so you get it from the integration page instead of building it yourself.


​

Authenticating


​

Every request carries an Authorization header. The Bearer prefix is optional — the token is accepted with or without it.


​

Three kinds of credential work:


​

  • An API token, issued to a user by an Admin of the organization.

  • A browser session, when the call comes from a signed-in context.

  • An app credential, issued to an integration.


​

One rule catches people out. An API token also needs an Organization header, naming the organization you're reading. Sessions and app credentials don't: the organization is already part of the credential, so the header is ignored.


​

Getting a token


​

There is no self-service page for this. API tokens are issued per user by an Admin of that organization, through the API itself:


​

POST /admin/users/{user_id}/api-credentials


​

Leanmote records when each token was last used, so an Admin can list the tokens of a user and see which ones are still in play before revoking anything.


​

What you can read


​

The REST API is organized around the same objects you see in the product:


​

  • Organizations — the organization, its members, its teams, its connected apps.

  • Teams — a team, its members, its managers, its tasks and its interactions. Teams can be created and edited, and members added or removed.

  • Users — a user, the teams they belong to, the tools they're mapped to, and their saved views. GET /users/me resolves whoever the credential belongs to.

  • Work — boards and their tasks, plus the interactions (commits, pull requests, reviews, comments) that Leanmote ingested.

  • Calendars — connected calendars and their events.

  • Saved views — the dashboard views and custom filters an organization has configured, including the catalog of what can be built.

  • Alert rules — creating, editing and disabling them.

  • Org chart — the resolved team hierarchy, plus the import flow that proposes a hierarchy from team names and lets you apply or undo it.


​

GET /health answers without a credential, which makes it the right target for a connectivity check.


​

Common use cases


​

  • Embed metrics in your own dashboards — read from the Metrics API and render in whatever data tool you already use.

  • Automate user lifecycle — point your identity provider at SCIM to create, update and deactivate users.

  • Send AI tool telemetry — use the OTLP endpoint for Claude Code and other instrumented tools.

  • Build a custom integration — combine the REST and Metrics APIs to bring Leanmote data into internal tooling.


​

Related articles


​

  • Integrations overview

  • SSO and SCIM

  • Claude Code integration (OTLP)

Did this answer your question?