← Docket · FAQ · Security · Terms
Setup, per source
Docket connects with your own credentials, stored on your Mac, and there is no Docket account in the middle. Each source below says what it needs, what that credential can reach, and honestly so. First run opens the Connect wizard; this page is the same information for reading ahead.
Jira (the core source)
Works with Cloud and Data Center, several accounts at once; Docket routes every write to the account that owns the ticket.
Jira Cloud
- Create an API token: Atlassian account → Security → API tokens.
- In Docket: Settings → Sources → add your site URL, your login email and the token.
Jira Data Center / Server
- Create a Personal Access Token: your profile → Personal Access Tokens.
- Add the base URL and the PAT. No email needed, since DC authenticates the token alone.
What the token can do: whatever your Jira user can. Docket reads your assigned issues and writes only what you tell it to, whether that is a comment, a transition or an estimate, and every write lands in the in-app audit log.
Figma (comments and @mentions)
A personal access token, created in Figma → Settings → Personal access tokens. Honest disclosure: a Figma personal token reaches everything your Figma account can, all files and teams. Docket uses it to read comments (to find the mentions addressed to you and your teammates) and to post a reply when you answer from here. It is stored on this Mac only and sent to nobody but Figma; revoke it in Figma any time. A narrower OAuth app is on the roadmap, but until then this is the only way in. Check what your Figma account can see before you paste. FigJam files ride the same connection.
Calendar
The recommended route needs no setup at all: Docket reads your Mac's own calendars through Apple's EventKit, so it sees whatever Calendar.app has (Google, Exchange, iCloud, all at once). macOS asks for permission once, and focus blocks you accept are written back the same way. No OAuth client, no tokens, nothing to expire.
Confluence
Base URL plus a token (same token flow as Jira on the same instance). Docket pulls pages that mention you.
Obsidian
Point Docket at your vault folder. It reads open tasks (- [ ]) from
your notes; nothing is uploaded anywhere, because it's a folder on the same machine.
Dovetail
An API token from Dovetail's settings. Pulls your research highlights into the Research view.
Miro
A token from a Miro app (your profile → Your apps → create → install; scope
boards:read). Plan-dependent: Miro's API access differs
per subscription tier, so if your plan doesn't expose the REST API, the source card will
say the connection is refused rather than pretending it's quiet.
Slack (read-only)
Recent messages that mention you, per workspace. Create your own Slack app
(api.slack.com/apps → From scratch → OAuth & Permissions → User Token Scopes:
search:read → Install to workspace) and paste the user token.
Read-only: the app searches for your mentions and can never post, edit
or mark anything. Shown only, never counted.
Email (IMAP, read-only)
Any IMAP mailbox: server, address, password, though Gmail and iCloud require an
app-specific password (the add-form links the steps). Unread subjects and
senders appear on Today; rows open in Apple Mail when the message is there.
Read-only by protocol: the app opens the mailbox with EXAMINE and fetches
with PEEK, so it cannot mark anything read, move a message, or send. Headers only, with
one exception: the app fetches a calendar invitation's text/calendar part so
it can show the invite (title, time, "awaiting your reply"); prose bodies are never
fetched or stored. Shown only, never counted.
Your own feeds
Any JSON endpoint can become a card on Today: a URL, an optional auth header, and a small field map (which array, which field is the title, the date, the link). Feeds are shown only, never counted, so they can't distort what "needs you" means. A row that doesn't match your map is dropped and counted on the card, so a wrong map is visible instead of silently blank.
When a source looks empty
Docket distinguishes quiet from broken, and says which one it is:
- "This filter has returned work before — an empty list means an empty list." Genuinely quiet. Enjoy it.
- "This filter has never returned anything since it was set." Usually the filter, not the work, and the message links straight to the setting to check.
- A source that is down is named on its card with the actual error, and the views it feeds say the list is incomplete rather than showing a clean zero.
For anything deeper: Settings → System → Copy diagnostics produces a paste-safe report (names and hosts are pseudonymised) that shows exactly what each connection last returned. Support conversations start from that paste, so they start from facts.
Want it when it opens?
One short note when it opens, plus the occasional build update. Founding seats go in the order people join, and the first twenty-five pay €12/month for as long as they stay, against an €18 rate.