TimeTracker ships with several built-in integrations that you can
enable per user from Settings β Integrations. Each integration is
stored in the existing Integration model β there are no
integration-specific tables β and all secrets are encrypted at rest
when SETTINGS_ENCRYPTION_KEY is configured.
These are independent of the workspace-wide connectors and can be enabled or disabled by each user without affecting anyone else.
- GitHub β Webhook-driven task creation, optional auto-start timer on issue assignment, manual pull of open issues. Personal access token + HMAC-signed webhook.
- Google Calendar β OAuth2 connector with import / export / both directions, auto token refresh, and a 30-minute scheduled sync.
- Slack β Timer start/stop notifications,
/ttslash command (start,stop,status,today), and an optional daily summary post.
- Slack Attendance β Workspace-level
/in,/brb,/back,/outslash commands in a dedicated channel for clock-in/out and breaks. Maps Slack users by ID or profile email. Configured under Integrations β Workspace integrations.
- ActivityWatch β Local-first automated time
tracking imported as
source='auto'time entries. - Linear β Pull Linear issues as tasks via Personal API key.
- Xero β Sync invoices and clients with Xero.
All connectors subclass app/integrations/base.py:BaseConnector,
implement at minimum sync() and handle_webhook() where applicable,
and follow the same operational guarantees:
- HTTP calls use the
requestslibrary with a 10-second timeout, all wrapped intry/except requests.RequestException. - Secrets are never logged in raw form β they are truncated to a short
prefix (
xoxb-...,ghp_...). - When an integration row is missing or
is_active=False, every method returns{"ok": false, "error": "Integration not configured"}without raising. Existing UI screens (timers, exports, dashboards) keep working when a connector is disabled or broken. - Webhook receivers verify provider signatures before reading the body and return 401 on any verification failure.