Factuarea APIDevelopers

iCal feed

Subscribe to the tasks of a project, or your own, from any calendar app through a secret read-only iCal URL — how the URL works, rotation and revocation, privacy and what the feed includes.

An iCal feed publishes tasks as a read-only calendar that any calendar app can subscribe to. Tasks with a start or a due date show up as all-day events, and your calendar keeps them in sync on its own.

Feeds are managed only in the app, in the Share tab of the project settings, where the feeds of the project and your own personal feeds live. There is no operation for them in the API and no MCP tool, because the secret URL is a personal secret that must not travel through integrations. Project feeds are created, rotated and revoked by the owner and admin roles; owner, admin, member and user roles manage their own personal feeds, and the employee role cannot create any.

Two kinds of feed

FeedWhat it publishesFilter
ProjectThe tasks of one projectOptionally up to 100 task labels: a task shows up if it carries any of them
Personal (my tasks)The tasks assigned to you in any project of the companyNone

Every feed has a time zone (an IANA identifier such as Europe/Madrid; the app suggests the one of your browser). It decides the day used to drop old completed tasks, described below.

The secret URL

The feed is served without a session at a URL of the form /api/public/task-feeds/<token>.ics, so a calendar app can fetch it. The token is 32 random bytes; Factuarea keeps only its SHA-256 hash.

  • The URL is shown once, when you create or rotate the feed, with a copy button. No list or detail afterwards shows the token or the URL again.
  • If you lose it, rotate the feed. There is no way to read it back.
  • Treat it like a password. Whoever has the URL can read the tasks the feed includes, with no login. Do not paste it into a public ticket or a shared document.

Subscribing takes three steps:

Create the feed in the app

Choose the scope (project or personal), the labels if you want to filter, and the time zone.

Copy the URL

Copy it when it is shown: it will not be shown again.

Add it to your calendar app

Use the option to add or subscribe to a calendar from a URL in Google Calendar, Outlook, Apple Calendar or any other calendar app, and paste it. The app decides how often it refreshes, so a change to a task shows up at its next refresh.

Rotate and revoke

  • Rotate creates a new token, shown once, and keeps the scope, the project, the labels and the time zone. The previous URL stops working at once and answers 404, so existing subscriptions break until you paste the new URL. The app asks for confirmation.
  • Revoke is irreversible: the URL answers 404 and the feed leaves the list of active feeds. The app asks for confirmation.

A feed also answers 404, with no further detail, when the token is unknown or malformed, when its project was deleted, when the owner of a personal feed is no longer a member of the company or when the company no longer has the tasks module.

What the feed includes

Only tasks with a start date or a due date appear.

  • A project feed includes the tasks of the project and, if it filters by labels, only those carrying one of them, compared with the labels the task has now. Renaming a label keeps the filter working; if every label of the filter is deleted, the feed becomes empty and never widens to the whole project.
  • A personal feed includes the tasks assigned to its owner in any project of the company, and only that company: a user who belongs to several companies gets a different feed for each.
  • Backlog (planned) and active tasks are included. Archived tasks and tasks completed more than 30 days ago are left out, counting the days in the time zone of the feed.

Each task is an all-day event. The end date of an iCal all-day event is exclusive, while a due date is inclusive, so the event ends the day after:

The task hasDTSTARTDTEND
Only a due date, 2026-10-152026101520261016
A start date 2026-10-13 and a due date 2026-10-152026101320261016
Only a start date, 2026-10-132026101320261014
BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//Factuarea//Tareas//ES
CALSCALE:GREGORIAN
X-WR-CALNAME:Web redesign
BEGIN:VEVENT
UID:0193a4f2-8f53-7d44-8e85-7a9b1c3d5f16@factuarea
DTSTAMP:20260928T082044Z
LAST-MODIFIED:20260928T082044Z
CREATED:20260928T082044Z
DTSTART;VALUE=DATE:20261013
DTEND;VALUE=DATE:20261016
SUMMARY:Call the customer about the checkout demo
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR

The UID of an event is the id of the task plus @factuarea, so it stays the same every time the feed is served and your calendar updates the event instead of duplicating it. The events are transparent: they do not mark you as busy. The DESCRIPTION appears only when the task has one, as plain text (mentions become the name of the person, and the editor's internal tags and HTML are removed), and long titles and descriptions are cut at 1,024 and 4,096 characters.

Privacy

  • A feed only reads the tasks of the company it belongs to. A personal feed never shows tasks of your other companies.
  • The events carry the title, the dates and the plain-text description of each task. They carry no assignee, labels, status, comments, attachments or link back to the task.
  • The response is sent with Cache-Control: private, no-store, and every access updates the last access of the feed, which the app shows next to it.
  • If the URL leaks, rotate the feed. If you no longer need it, revoke it.

Next steps

On this page

Need a hand?Contact support