Connect Time Doctor
Time Doctor is a workforce analytics and time-tracking platform. Its agent records worked time, the applications and websites people use, screenshots and screen recordings, and idle or disconnected…
Written By Christopher Scaminaci
Last updated 6 days ago
Time Doctor is a workforce analytics and time-tracking platform. Its agent records worked time, the applications and websites people use, screenshots and screen recordings, and idle or disconnected periods; the platform reports productivity, payroll and project time on top of that. It is organized around companies, and one Time Doctor account can belong to many — which is how one connection in StackJack reaches every client that has invited you.
Connecting Time Doctor to StackJack gives your AI assistant a family of td_ MCP tools — MCP (Model
Context Protocol) tools are the standardized commands an AI assistant can call through StackJack.
With them, your AI can:
- Report on time — worked time and meeting time per person and per day, idle and disconnected periods, and the application and website breakdown behind them
- Answer productivity questions — totals, timelines, per-project and per-task summaries, productivity ratings, and application and licence spend
- Manage the work — projects, tasks, groups and who belongs to them, work schedules and shift adherence
- Run the roster — people and their details, invitations, pending approvals, group membership and the IP allow list
- Pull evidence — screenshots and screen recordings, with a temporary download link for each
- Adjust time and pay (on Pro plans) — manual time edits, worklog corrections, pay rates and payroll settings
- Reach across clients — list the companies your login belongs to and run any of the above against whichever one you name
- Check the sign-in itself — read which account StackJack is signed in as, what it is allowed to do and which companies it can reach, see its active sign-in sessions, and end one of them
- Reach anything else Time Doctor offers — two escape-hatch tools send a request you describe to any Time Doctor address, for the occasional thing no purpose-built tool covers
How StackJack signs in to Time Doctor
Time Doctor has no API key and no service account. Every way into its API starts from a real person's sign-in, so a connection is an email address and a password, and optionally the seed from that account's authenticator app.
StackJack exchanges those for a short-lived access token and a long-lived renewal token, keeps the access token fresh in the background, and renews carefully enough that two simultaneous requests can never invalidate each other's session. You never see either token.
Two consequences worth knowing before you start:
- The connection carries that person's authority. It sees exactly what that account sees, in exactly the companies that have invited it, with exactly the role it holds in each.
- The connection breaks when that account changes. A password change, a two-factor reset, or a client removing the account from their company all stop it until you re-enter the details.
For both reasons, use an account created for this purpose rather than an owner's personal login, and keep its password out of any rotation policy that would expire it silently.
Steps
- Choose or create the Time Doctor account StackJack will sign in as. A dedicated account is worth the seat: whoever holds it can see and change everything it can reach.
- Have each client invite that account into their Time Doctor company, with the role you want StackJack to have. An admin role gives full reporting and management; a manager role limits it to that manager's groups. A company that has not invited the account is invisible to StackJack, which is exactly the boundary you want.
- Note the authenticator seed if the account uses two-factor sign-in. StackJack needs the seed captured when two-factor was set up — the letters-and-digits string shown behind "Can't scan the code?" — not the six-digit code the app is displaying. Without it, an account with two-factor cannot sign in unattended. Push-approval two-factor cannot be automated at all.
- Enter the details in StackJack. Open Connectors, choose Time Doctor, and enter the email address, the password, the authenticator seed if there is one, and optionally a default company id. There is no address to configure.
- Run a Test Connection. StackJack signs in and lists the companies the account belongs to, so a success also tells you which clients this connection can reach.
Set a default company, or name one on every call
Nearly every Time Doctor operation names the company it applies to, because one account can belong to many. You have two ways to handle that, and you can use both:
- Save a default company id on the connection. Your AI can then leave it out, and anything else is still reachable by naming it on the call.
- Name the company on each call. Ask your assistant to list the companies first; every tool takes the company as an argument.
Leave the default blank and every call has to name a company — a call that names none is refused with an explanation rather than silently answering for the wrong client.
What to know before your AI uses this connector
One connection reaches every client, so the company argument is the boundary
This is the most important thing about the Time Doctor connector. Unlike connectors where one credential means one customer, a Time Doctor login reaches every company that has invited it, and the company is chosen per call. Restricting which tools an assistant may use does not restrict which client it reaches.
If you want an assistant confined to a single client, add one connection per company and save that company as its default, then pin the endpoint to that connection. See Several connections of one connector.
Time edits and pay changes are the writes to think hardest about
Most write tools here are ordinary — create a project, rename a group, add a task. A handful change what people are paid, and they are marked destructive even though nothing is deleted:
- Manual time edits and worklog corrections rewrite recorded work time, which is the input to payroll.
- Pay rates, pay methods and company payroll settings replace what someone is paid against.
- Approving or blocking a person, adding a group manager, or granting project access are permission grants.
- Invitations, announcements and password-reset emails reach a real human, and that cannot be undone.
- Some updates replace rather than merge — publishing a private project clears its whole access list, and replacing work schedules removes the existing ones inside the window first.
- Updating a project, a task or a group can archive it. Time Doctor puts the archive switch in the same request body as the name and the description, so "update this task" and "archive this task" are one call with a different field set. All three update tools are marked destructive for that reason, even though most calls to them only rename something.
- Starting calendar notifications sends your customer's calendar changes to an address the caller chooses, and only a destructive tool can stop them again.
Whether your AI application asks you to confirm before running one of these depends on that application's own settings — see Destructive tools and confirmation.
The account tools act on the sign-in StackJack itself uses
A small group of tools is about the Time Doctor account behind the connection rather than about the people being tracked. Two of them just read: which account this is, what it is allowed to do, and which companies it reaches — the fastest way to answer "why can my assistant not see this client?".
The rest change how that account signs in, and they can break the connection you are reading this to set up:
- Ending a sign-in session ends it for whatever is holding it. If the session you name is the one StackJack is using, Time Doctor access stops until StackJack signs in again, which it does by itself on the next call.
- Generating a new authenticator seed replaces the old one. Any seed already saved — including the Authenticator Secret you pasted into this connector — stops producing valid codes, and the connection stays broken until you paste the new one in.
- Turning on two-factor sign-in makes every future sign-in need a code from the matching authenticator app, StackJack's included.
All of them are marked destructive so your AI application asks first, and each says in its own description what it will cost you. None of them tries to work out whether the session you named is StackJack's own — that is your call to make, not a guess for a tool to make on your behalf. If you have no reason to let an assistant manage the account's own sign-in, leave these tools out of the connection's tool selection.
Everything is in UTC
Time Doctor stores and returns times in UTC only. A report for a client's local working day has to be converted before it is asked for, and nothing converts it for you. Ask for the window in UTC and read the answer the same way.
Large reads skip rows, they do not turn pages
This API pages by row offset: the second page of a fifty-row read starts at row fifty, not at page two. StackJack's tool descriptions say so, and an assistant that walks pages 1, 2, 3 would re-read the same rows. Ask for a wide report in successive windows rather than in one call.
Screenshots arrive as a temporary link
Screenshot and screen-recording tools return a short-lived download link rather than the file itself. Fetch what you need when you ask for it; a link saved for later will have expired.
Some Time Doctor words differ from its API's words
Groups are called tags in the underlying API, screenshots and recordings are called files, and productivity ratings are called categories. StackJack's tools use the words you see in the product, so ask for groups, screencasts and productivity ratings.
Every filter Time Doctor documents is now an argument
Time Doctor's reports accept a very large number of filters — the summary reports alone document more than 150 each, one per metric and threshold. All of them are available as arguments on the matching tool, so a question like "who was idle more than thirty percent of tracked time last week" is one call rather than a wide read your assistant filters afterwards.
Two things follow from that. A handful of report tools carry a very long argument list, and a few AI clients cap how much tool detail they will load; if yours truncates, the escape hatch below is the way through. And Time Doctor documents a few of its people filters under two spellings for the same thing; StackJack gives you one argument for each, and its description names the other spelling so a filter you read about in Time Doctor's own documentation is never missing.
The escape hatch, for anything else
Two tools send a request you describe to any Time Doctor address rather than to one purpose-built endpoint. They exist for the occasional thing the purpose-built tools do not cover — a report only Time Doctor's own documentation describes, or something the vendor added recently.
- The read half is on the Free tier and can only send a fetch request. It is not labelled read-only, and that is deliberate: three Time Doctor addresses do something when you fetch them — one emails a password-reset link to a person, one issues a new authenticator code and cancels the old one, and one ends someone's sign-in session. There are purpose-built tools for all three, and those are labelled so your assistant asks you first. This one cannot tell in advance which address you named, so it does not claim to be read-only.
- The write half is Pro, is labelled destructive, and will do whatever the address you name does — including deleting a person along with their tracked time, screenshots and payroll history.
Neither tool widens what your connection can do. Your subscription, your endpoint's tool selection, your plan and your assistant's consent prompts all still apply, and Time Doctor still checks the signed-in account's own role. Prefer a purpose-built tool whenever one exists: it names its filters, fills in the company for you and tells your assistant what the answer means.
Plans and limits
Read tools are on the Free tier. Everything that changes data — projects, tasks, groups, schedules, people, time edits and payroll — is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated Time Doctor tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Time Doctor publishes no request limit, so StackJack paces requests conservatively and backs off on its own if it is throttled, which usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Several customers
One Time Doctor login already reaches every company that invited it, so a single connection can serve every client. Add separate connections when you want each one confined to a single client — each with that client's company saved as its default — or when different clients require different Time Doctor accounts. Your AI names the connection on each call, and omitting the name runs against your default connection. See Several connections of one connector.
Troubleshooting
"Time Doctor rejected the sign-in" — the account's password changed, its two-factor settings changed, or the account was deactivated. Re-enter the email and password, and add the authenticator seed if the account now uses two-factor sign-in.
"Time Doctor asked for a two-factor code" — the account signs in with an authenticator app and no seed is saved. Paste the setup seed, not the six-digit code. If the seed is lost, reset two-factor on the Time Doctor account and save the new one.
"That looks like the six-digit code rather than the setup seed" — StackJack refuses to save a code as a seed, because a code expires in thirty seconds and would produce sign-in failures that explain nothing. Find the seed behind "Can't scan the code?" in the two-factor setup screen.
"Time Doctor has this feature turned off for that company" — the modern sign-in method is disabled on that one company's account. Your credentials are fine and every other company keeps working. Ask that company's Time Doctor owner to enable it, or contact Time Doctor support.
"Time Doctor denied the request" — the account does not hold the role that action needs inside that company. Time Doctor decides by role — owner, admin, manager, user — and a manager only ever reaches their own groups. Ask the client to raise the account's role.
A request is refused for a missing value — almost always the company. Save a default company on the connection, or name one on the call.
Not found, when the thing plainly exists — check which company was asked about. An id from one company does not exist in another, so a request that named the wrong company reads as not-found.
Too many attempts — Time Doctor locks an account out after repeated failed sign-ins. Wait a few minutes, and if it keeps happening after a password change, re-enter the password: every retry with the old one counts toward the lockout.
Time Doctor tools
td_ · 147 tools · Free 81 · Pro 66
Companies
Company payroll
Profile
Account and sessions
Invitations
Payroll
Pending approvals
Users
Breaks
Time edits
Worklogs and activity
Productivity ratings
Software cost insights
Statistics
Groups
Projects
Tasks
Work schedules
Screencasts
IP allow list
Notifications
Calendar integration
Raw Requests
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team