OneCLI connects AI agents to Timeless with an API token. Agents can search meetings, read transcripts and summaries, and send the note-taker to a call. The gateway injects the token into requests to api.timeless.day, so your agent never sees it.This suits agents that turn calls into follow-ups: drafting recaps, filing action items into a tracker, or answering “what did we agree with this customer last week?”Timeless has no OAuth for its public API, so an API token is the only connection method.
Timeless needs one field, an API token. The whole flow takes about a minute.
1
Generate an API token in Timeless
Sign in to Timeless and open my.timeless.day/api-token. Create a token and copy it.Tokens are 64-character hex strings and carry the same access as your Timeless account, so treat the token like a password.
2
Connect in OneCLI
In the OneCLI dashboard, open Connections > Timeless and paste the token into API token. Under Advanced you can set an optional connection label to tell several Timeless accounts apart, for example work or personal.
The Timeless connect dialog in OneCLI.
Click Connect Timeless. OneCLI verifies the token against the Timeless API and rejects it if Timeless returns a 401.
No Authorization header is needed, the gateway adds it:
# Ten most recent meetingscurl -s "https://api.timeless.day/v1/meetings?limit=10"# Pull a transcript with speaker labelscurl -s "https://api.timeless.day/v1/meetings/mtg_abc123/transcript"# Include AI-generated documents inline instead of a second requestcurl -s "https://api.timeless.day/v1/meetings?expand=documents"
Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked.Meeting content is sensitive, and some Timeless calls are not read-only. Sending the note-taker bot into a live call, changing automation settings, and granting public share links all have real-world effects, so those are worth putting behind approval while leaving reads free. Organization rules add guardrails on top, like rate limits. Everything is checked before credential injection, so a blocked request never reaches Timeless.