# List a client's cards

Returns the AI-generated cards (briefing, wins/traction, risks/frictions, topics) for the client, in the display order configured in the organization's card settings. Filtered to configs where both \`is_active\` and \`is_displayed\` are true; the column-only configs that surface on the clients-overview list are intentionally excluded here. \*\*Stale handling.\*\* When at least one card is stale, that card is returned with \`is_stale=true\` AND a regeneration is enqueued for the worker to pick up on its next tick. The read path is purely lazy — no synchronous LLM call is ever made on a partner request. Re-call the endpoint after a short delay to observe the refreshed value (\`is_stale=false\`, new \`last_update\`). Cross-tenant lookups and missing clients both return \`404 not_found\` so existence is never leaked.

GET

/`clients`/`{clientId}`/`cards`

## Authorization

`bearerAuth`` `

AuthorizationBearer \<token\>

Salfio API tokens start with the literal prefix `sk_live_` followed by 32 base62 characters (≈190 bits of entropy). Tokens are hashed at rest with argon2id and shown to the user only once at creation.

In: `header`

## Path Parameters

clientId\*string

Format`uuid`

## Response Body

### 

`application/json`

### 

`application/json`

### 

`application/json`

### 

`application/json`

### 

`application/json`

    curl -X GET "https://api.salfio.com/v1/clients/497f6eca-6276-4993-bfeb-53cbbbba6f08/cards"

    {
      "meta": {
        "cursor": "string",
        "hasMore": true
      },
      "data": [
        {
          "card_value_id": "ee642540-0aa0-4aac-8dff-12af99283b7e",
          "card_config_id": "9386630e-fb19-45e4-9a0b-aa4ae69d0172",
          "identifier": "briefing",
          "title": "Briefing",
          "display_order": 1,
          "value": "string",
          "last_update": "2019-08-24T14:15:22Z",
          "is_stale": true
        }
      ]
    }

    {
      "error": {
        "code": "invalid_argument",
        "message": "limit must be an integer between 1 and 100"
      }
    }

    {
      "error": {
        "code": "unauthorized",
        "message": "Authentication required"
      }
    }

    {
      "error": {
        "code": "not_found",
        "message": "client not found"
      }
    }

    {
      "error": {
        "code": "rate_limited",
        "message": "Rate limit exceeded",
        "details": {
          "retry_after_seconds": 30
        }
      }
    }

## Related pages

- [Administrator Tools](./administrator-tools.md)
- [Agent Tools](./mcp-external-servers.md)
- [Assign a Slack channel to a client over the API](./guides-assign-slack-channel.md)
- [Authenticated health check](./api-reference-gethealth.md)
- [Authentication](./api-authentication.md)
- [Cards](./cards.md)
- [Changelog](./changelog.md)
- [Changelog](../changelog.md)
- [Connect a workspace](./getting-started-connect-workspace.md)
- [Connect an integration](./getting-started-connect-integration.md)

# Agent Instructions

This portal answers questions programmatically. To receive a synthesized,
source-cited answer instead of crawling page by page, append the `?ask=`
query parameter to any page URL on this site:

    /guides/quickstart?ask=how+do+I+authenticate

Optional parameters:

- `&goal=<what-you-are-trying-to-do>` steers the answer toward your
  objective (e.g. `&goal=write+a+python+client`).
- `&version=<label>` scopes the answer to a mounted version when the
  portal publishes more than one.

The response is `text/markdown`: the answer followed by a `# Sources` list
of the portal pages it was grounded in. Status codes are the contract:

- `200` — the answer; `402` — the portal owner’s plan or answer credits are
  exhausted (surface this to your operator; do NOT retry); `429` — you are
  rate-limited; back off for the `Retry-After` seconds; `503` — the answer
  lane is temporarily unavailable; fall back to crawling the `.md` pages.

For the full corpus map read `llms.txt` at the site root; for the tool
surface (search + page fetch as MCP tools) see `/mcp`.
