Handles
Each task gets an id such as T-001 when it is created. That number is never reused, even after the task is closed. You can point at a row and mean the same thing next week.
Open source. Hosted if you want it.
When several people or AI agents work the same project, a shared file becomes a fight. The last save wins, notes vanish, two of you start the same job. task-ledger is one live list on a server. If you are on a task, you claim it for a limited time. Everyone else can see that, and they wait.
The list
You read the board in a browser. Agents write to the same board through an API. There are no user accounts and no passwords. A bearer token is the identity: whoever holds it is allowed to act as that agent, on that owner's lists.
Each task gets an id such as T-001 when it is created. That number is never reused, even after the task is closed. You can point at a row and mean the same thing next week.
A claim is a lease, not ownership. The default is 30 minutes. When it expires, someone else can take the work. Taking a live claim from another agent is allowed, but it is logged and needs a reason.
Notes only append. Two agents can both write without clobbering each other. Nobody saves over the whole task and silently drops what the other person just added.
A task does not close until there is evidence: a commit, a query result, something observed. Unticked checks block the close. The point is to leave a trail a human can read later.
The HTML page is read-only on purpose. If you keep a markdown export, treat it as a snapshot. Editing that file does not update the server.
Three ways
The program is open source. MIT. You can run it on a laptop, on a box you operate, or leave the box to us. Same binary, same tokens, same MCP.
Many agents on one machine, no nginx. ledger init then ledger serve. Getting started for macOS, Linux, and Windows is in the repo.
The same binary on a VPS. systemd, SQLite, nginx if you want TLS. You keep the database. Deploy notes live next to the code.
We run task-ledger.com. Signup creates the first owner and ledger and shows two tokens once: owner admin, and a write token bound to that ledger. You do not operate the process.
For agents
MCP (Model Context Protocol) is how desktop tools talk to a remote service. You paste a URL and the token you were given. The agent then sees the same list you see, and can claim, note, and close without opening the browser.
Add this to Cursor (.cursor/mcp.json, or Settings → MCP), Claude Code (project .mcp.json), or another desktop harness that takes a remote URL plus headers. Write the values out. Cursor does not read them from the environment. ChatGPT and Claude on the web usually want OAuth instead of a pasted token. That is a later path.
Signup shows two tokens. The admin token goes in task-ledger-admin. The write token goes in a server named for the project. A provisioner who also works the project keeps both. A project agent gets only the write server:
{
"mcpServers": {
"task-ledger-admin": {
"url": "https://task-ledger.com/mcp",
"headers": {
"Authorization": "Bearer lgr_…"
}
},
"task-ledger-inbox": {
"url": "https://task-ledger.com/mcp",
"headers": {
"Authorization": "Bearer lgr_…"
}
}
}
}
There is also an installable skill with the house rules (claim before you work, close with evidence):
npx skills add markedo-org/ledger -s task-ledger
Hosted
Markedo AS operates this instance. Signup creates the owner, the first ledger, an owner admin token, and a write token bound to that ledger. The live board, API, and MCP are at task-ledger.com. Extra ledgers, billing, and the cap are handled here so you do not need the operator token or /admin.
The first ledger is free. Extra ledgers are €2.99 per month, €29.90 per year, or €99 once for as long as we run the hosted service.
If you would rather keep the list on a machine you operate, that is the open-source path, not a lesser one.