# Create a note on a client

**POST** `/clients/{clientId}/notes`

Records a note against the client and returns it as an activity of
`type: "note"`. Unlike the generic activity create, the note path
attributes the note to a user author (added as a participant contact)
and marks the client's AI cards stale so they regenerate.

**Author attribution.** With a **user-scoped** key the note is authored
by the authenticated user automatically. With a **service-scoped** key
(which carries no user) you MUST supply `authorUserId` referencing a
member of your organization — otherwise the request is rejected with
`400 invalid_argument`. A cross-organization or unknown `authorUserId`
is likewise `400 invalid_argument`.

`content` is required. `participants` are people present on the note
besides the author; each is linked to (or created as) an org contact by
email. `occurredAt` defaults to now when omitted.

Base URL: `https://api.salfio.com/v1`

Tags: `notes`

## Authorization

| Option | Scheme | Type | Sent as | Scopes |
| --- | --- | --- | --- | --- |
| Option 1 | `bearerAuth` | `http` | `Authorization: Bearer <token>` | — |

## Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `clientId` | `string` (uuid) | Yes | Client UUID. |

## Request body

Required. Media type: `application/json`

### Example request body

```json
{
  "authorUserId": "00000000-0000-0000-0000-000000000000",
  "content": "string",
  "occurredAt": "2026-06-09T00:00:00Z",
  "participants": [
    {
      "email": "user@example.com",
      "name": "string"
    }
  ],
  "subject": "string"
}
```

## Responses

| Status | Description | Media type |
| --- | --- | --- |
| `201` | The created note, as an activity of type "note" (content included). | `application/json` |
| `400` | Request body / query parameters failed validation. | `application/json` |
| `401` | Missing or invalid bearer token. The message is intentionally opaque — do not rely on it to distinguish "missing" from "invalid". | `application/json` |
| `404` | The referenced resource does not exist, or belongs to a different organization than the one owning the API key. The public API does not distinguish between these cases — both return 404 to avoid leaking cross-tenant existence. | `application/json` |
| `429` | Per-organization or per-endpoint rate limit exceeded. | `application/json` |

### Example response: 201 — The created note, as an activity of type "note" (content included).

```json
{
  "data": {
    "archivedAt": "2026-06-09T00:00:00Z",
    "clientId": "00000000-0000-0000-0000-000000000000",
    "content": "string",
    "createdAt": "2026-06-09T00:00:00Z",
    "id": "00000000-0000-0000-0000-000000000000",
    "immutable": true,
    "occurredAt": "2026-06-09T00:00:00Z",
    "participants": [
      "user@example.com"
    ],
    "source": "fireflies",
    "subject": "string",
    "type": "chat",
    "updatedAt": "2026-06-09T00:00:00Z"
  },
  "meta": {
    "cursor": "string",
    "hasMore": true
  }
}
```

### Example response: 400 — Request body / query parameters failed validation.

```json
{
  "error": {
    "code": "invalid_argument",
    "message": "limit must be an integer between 1 and 100"
  }
}
```

### Example response: 401 — Missing or invalid bearer token. The message is intentionally opaque — do not rely on it to distinguish "missing" from "invalid".

```json
{
  "error": {
    "code": "unauthorized",
    "message": "Authentication required"
  }
}
```

### Example response: 404 — The referenced resource does not exist, or belongs to a different
organization than the one owning the API key. The public API does not
distinguish between these cases — both return 404 to avoid leaking
cross-tenant existence.

```json
{
  "error": {
    "code": "not_found",
    "message": "client not found"
  }
}
```

### Example response: 429 — Per-organization or per-endpoint rate limit exceeded.

```json
{
  "error": {
    "code": "rate_limited",
    "details": {
      "retry_after_seconds": 30
    },
    "message": "Rate limit exceeded"
  }
}
```

## Related pages

- [activities](./tags/activities.md)
- [assignment-rules](./tags/assignment-rules.md)
- [Authenticated health check](./gethealth.md)
- [cards](./tags/cards.md)
- [clients](./tags/clients.md)
- [Create a client](./createclient.md)
- [Create a manual activity](./createactivity.md)
- [Delete a client](./deleteclient.md)
- [Delete or archive an activity](./deleteorarchiveactivity.md)
- [docs](./tags/docs.md)

# Agent Instructions

This portal answers questions programmatically. To receive a synthesized,
source-cited answer instead of crawling page by page, append the `?ask=`
query parameter to any page URL on this site:

    /guides/quickstart?ask=how+do+I+authenticate

Optional parameters:

- `&goal=<what-you-are-trying-to-do>` steers the answer toward your
  objective (e.g. `&goal=write+a+python+client`).
- `&version=<label>` scopes the answer to a mounted version when the
  portal publishes more than one.

The response is `text/markdown`: the answer followed by a `# Sources` list
of the portal pages it was grounded in. Status codes are the contract:

- `200` — the answer; `402` — the portal owner’s plan or answer credits are
  exhausted (surface this to your operator; do NOT retry); `429` — you are
  rate-limited; back off for the `Retry-After` seconds; `503` — the answer
  lane is temporarily unavailable; fall back to crawling the `.md` pages.

For the full corpus map read `llms.txt` at the site root; for the tool
surface (search + page fetch as MCP tools) see `/mcp`.
