A calmer Todoist client. Vercel serverless functions handle the OAuth dance and hold the session, so no access token ever reaches the browser.
Live: https://todoist-flow.vercel.app
Talking to the Todoist REST API straight from the front end would mean shipping a
personal access token to the client. Instead every call goes through a small
serverless layer under api/todoist/:
| Endpoint | Job |
|---|---|
auth-url |
builds the Todoist OAuth authorise URL |
callback |
exchanges the OAuth code for a token |
token-login |
alternative sign-in with a personal API token |
session / _session |
reads and stores the server-side session |
logout |
clears it |
profile |
current user |
projects |
project list |
upcoming |
tasks due ahead |
completed |
completed-task history |
_todoist.ts is the shared client wrapper; _session.ts the shared session helper.
The React app only ever talks to these routes.
React · TypeScript · Vite · Tailwind CSS · shadcn/ui · Vercel Functions · Todoist REST API
npm install
vercel dev # needed — plain `vite` won't serve the /api routesSet the Todoist OAuth client id and secret in your environment before signing in.