# List a client's cards

**GET** `/clients/{clientId}/cards`

Returns the AI-generated cards (briefing, wins/traction,
risks/frictions, topics) for the client, in the display order
configured in the organization's card settings. Filtered to
configs where both `is_active` and `is_displayed` are true; the
column-only configs that surface on the clients-overview list
are intentionally excluded here.

**Stale handling.** When at least one card is stale, that card
is returned with `is_stale=true` AND a regeneration is
enqueued for the worker to pick up on its next tick. The read
path is purely lazy — no synchronous LLM call is ever made on
a partner request. Re-call the endpoint after a short delay to
observe the refreshed value (`is_stale=false`, new
`last_update`).

Cross-tenant lookups and missing clients both return `404
not_found` so existence is never leaked.

Base URL: `https://api.salfio.com/v1`

Tags: `cards`

## Authorization

| Option | Scheme | Type | Sent as | Scopes |
| --- | --- | --- | --- | --- |
| Option 1 | `bearerAuth` | `http` | `Authorization: Bearer <token>` | — |

## Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `clientId` | `string` (uuid) | Yes | Client UUID. |

## Responses

| Status | Description | Media type |
| --- | --- | --- |
| `200` | Ordered list of the client's cards. | `application/json` |
| `400` | Request body / query parameters failed validation. | `application/json` |
| `401` | Missing or invalid bearer token. The message is intentionally opaque — do not rely on it to distinguish "missing" from "invalid". | `application/json` |
| `404` | The referenced resource does not exist, or belongs to a different organization than the one owning the API key. The public API does not distinguish between these cases — both return 404 to avoid leaking cross-tenant existence. | `application/json` |
| `429` | Per-organization or per-endpoint rate limit exceeded. | `application/json` |

### Example response: 200 — Ordered list of the client's cards.

```json
{
  "data": [
    {
      "card_config_id": "00000000-0000-0000-0000-000000000000",
      "card_value_id": "00000000-0000-0000-0000-000000000000",
      "display_order": 1,
      "identifier": "briefing",
      "is_stale": true,
      "last_update": "2026-06-09T00:00:00Z",
      "title": "Briefing",
      "value": "string"
    }
  ],
  "meta": {
    "cursor": "string",
    "hasMore": true
  }
}
```

### Example response: 400 — Request body / query parameters failed validation.

```json
{
  "error": {
    "code": "invalid_argument",
    "message": "limit must be an integer between 1 and 100"
  }
}
```

### Example response: 401 — Missing or invalid bearer token. The message is intentionally opaque — do not rely on it to distinguish "missing" from "invalid".

```json
{
  "error": {
    "code": "unauthorized",
    "message": "Authentication required"
  }
}
```

### Example response: 404 — The referenced resource does not exist, or belongs to a different
organization than the one owning the API key. The public API does not
distinguish between these cases — both return 404 to avoid leaking
cross-tenant existence.

```json
{
  "error": {
    "code": "not_found",
    "message": "client not found"
  }
}
```

### Example response: 429 — Per-organization or per-endpoint rate limit exceeded.

```json
{
  "error": {
    "code": "rate_limited",
    "details": {
      "retry_after_seconds": 30
    },
    "message": "Rate limit exceeded"
  }
}
```

## Related pages

- [activities](./tags/activities.md)
- [assignment-rules](./tags/assignment-rules.md)
- [Authenticated health check](./gethealth.md)
- [cards](./tags/cards.md)
- [clients](./tags/clients.md)
- [Create a client](./createclient.md)
- [Create a manual activity](./createactivity.md)
- [Create a note on a client](./createnote.md)
- [Delete a client](./deleteclient.md)
- [Delete or archive an activity](./deleteorarchiveactivity.md)

# Agent Instructions

This portal answers questions programmatically. To receive a synthesized,
source-cited answer instead of crawling page by page, append the `?ask=`
query parameter to any page URL on this site:

    /guides/quickstart?ask=how+do+I+authenticate

Optional parameters:

- `&goal=<what-you-are-trying-to-do>` steers the answer toward your
  objective (e.g. `&goal=write+a+python+client`).
- `&version=<label>` scopes the answer to a mounted version when the
  portal publishes more than one.

The response is `text/markdown`: the answer followed by a `# Sources` list
of the portal pages it was grounded in. Status codes are the contract:

- `200` — the answer; `402` — the portal owner’s plan or answer credits are
  exhausted (surface this to your operator; do NOT retry); `429` — you are
  rate-limited; back off for the `Retry-After` seconds; `503` — the answer
  lane is temporarily unavailable; fall back to crawling the `.md` pages.

For the full corpus map read `llms.txt` at the site root; for the tool
surface (search + page fetch as MCP tools) see `/mcp`.
