Skip to main content

Overview

OneCLI connects AI agents to Timeless with an API token. Agents can search meetings, read transcripts and summaries, and send the note-taker to a call. The gateway injects the token into requests to api.timeless.day, so your agent never sees it. This suits agents that turn calls into follow-ups: drafting recaps, filing action items into a tracker, or answering “what did we agree with this customer last week?” Timeless has no OAuth for its public API, so an API token is the only connection method.

Setup

Timeless needs one field, an API token. The whole flow takes about a minute.
1

Generate an API token in Timeless

Sign in to Timeless and open my.timeless.day/api-token. Create a token and copy it.Tokens are 64-character hex strings and carry the same access as your Timeless account, so treat the token like a password.
2

Connect in OneCLI

In the OneCLI dashboard, open Connections > Timeless and paste the token into API token. Under Advanced you can set an optional connection label to tell several Timeless accounts apart, for example work or personal.
OneCLI connect dialog for Timeless, showing the required API token field, a Get your API token link, an Advanced section with an optional connection label, and the Connect Timeless button.

The Timeless connect dialog in OneCLI.

Click Connect Timeless. OneCLI verifies the token against the Timeless API and rejects it if Timeless returns a 401.

What agents can do

A token inherits your own Timeless access, so an agent reaches the meetings you can reach, and no more.

Quick example

No Authorization header is needed, the gateway adds it:
For filters, pagination, and response shapes, see the Timeless API reference.

Disconnecting

  • In OneCLI, open Connections > Timeless and remove the connection.
  • In Timeless, delete the token at my.timeless.day/api-token.
Removing the connection in OneCLI stops injection immediately. Deleting the token in Timeless is what actually revokes it, so do both.

Controlling access

Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked. Meeting content is sensitive, and some Timeless calls are not read-only. Sending the note-taker bot into a live call, changing automation settings, and granting public share links all have real-world effects, so those are worth putting behind approval while leaving reads free. Organization rules add guardrails on top, like rate limits. Everything is checked before credential injection, so a blocked request never reaches Timeless.