> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getaptly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List cards (deprecated)

> Deprecated: use POST /api/board/{boardId}/list. Both endpoints use the same read-only listing implementation and response. GET remains supported.

Returns a paginated list of cards on the board.

Field values are keyed by field UUID — use the schema endpoint to map keys to labels.
Money fields are returned as `{ amount, currency }` where `amount` is a decimal.

All filter params are optional and ANDed together.

Supply segmentId OR rules (a JSON-encoded array), never both. Rules use the existing saved-segment format. Invalid rules fail with 400; missing, private-to-another-user, archived, or wrong-board segments return 404.

Auth: API key, delegate token (boards:* or boards:{boardId} read scope), or partner bearer token with board-admin. Mobile tokens are not accepted. Keys/delegates require API-enabled boards; partner access retains its existing API-enabled bypass. API keys/partners may supply userId for an active company member; delegates can only use their token user. Without userId only public segments are visible. Public means company-shared.




## OpenAPI

````yaml /openapi.yaml get /api/board/{boardId}
openapi: 3.0.3
info:
  title: Aptly API
  version: '1.0'
  description: |
    The Aptly API lets external systems work with boards, contacts, inboxes,
    tasks, files, and other Aptly resources.

    Most endpoints accept an API key in the `x-token` header. Some endpoints
    also accept a delegate token or partner bearer token, as shown in each
    operation's security requirements, and explicitly public endpoints require
    no credential. API keys are scoped to a company and may be restricted to
    specific boards and read, insert, or update permissions; requests outside
    those restrictions receive a 403 `FORBIDDEN` response.
servers:
  - url: https://core-api.getaptly.com
    description: Production
security:
  - ApiKeyHeader: []
paths:
  /api/board/{boardId}:
    get:
      tags:
        - Cards
      summary: List cards (deprecated)
      description: >
        Deprecated: use POST /api/board/{boardId}/list. Both endpoints use the
        same read-only listing implementation and response. GET remains
        supported.


        Returns a paginated list of cards on the board.


        Field values are keyed by field UUID — use the schema endpoint to map
        keys to labels.

        Money fields are returned as `{ amount, currency }` where `amount` is a
        decimal.


        All filter params are optional and ANDed together.


        Supply segmentId OR rules (a JSON-encoded array), never both. Rules use
        the existing saved-segment format. Invalid rules fail with 400; missing,
        private-to-another-user, archived, or wrong-board segments return 404.


        Auth: API key, delegate token (boards:* or boards:{boardId} read scope),
        or partner bearer token with board-admin. Mobile tokens are not
        accepted. Keys/delegates require API-enabled boards; partner access
        retains its existing API-enabled bypass. API keys/partners may supply
        userId for an active company member; delegates can only use their token
        user. Without userId only public segments are visible. Public means
        company-shared.
      operationId: listCards
      parameters:
        - name: boardId
          in: path
          required: true
          schema:
            type: string
          description: The board's UUID.
        - name: page
          in: query
          required: true
          schema:
            type: integer
            minimum: 0
            maximum: 9999
          description: >-
            Zero-based page number. Legacy GET parses the base-10 integer prefix
            (1.5 or 1e2 becomes 1).
        - name: pageSize
          in: query
          schema:
            type: integer
            minimum: 1
            maximum: 1000
            default: 20
          description: >-
            Number of cards per page. Legacy GET parses the base-10 integer
            prefix; omitted or empty defaults to 20.
        - name: updatedAtMin
          in: query
          schema:
            type: string
            format: date-time
          description: Only return cards updated after this ISO timestamp.
        - name: includeArchived
          in: query
          schema:
            type: boolean
            default: false
          description: >-
            Include archived cards. Legacy GET treats empty or the exact string
            false as false; any other nonempty string (including 1 or 0) as
            true. Omitted lets archive rules control selection.
        - name: relatedId
          in: query
          schema:
            type: string
          description: Only return cards where `references.value` contains this ID.
        - name: contactEmail
          in: query
          schema:
            type: string
          description: >-
            Resolves the email to contact IDs, then filters cards referencing
            those contacts.
        - name: keyTerm
          in: query
          schema:
            type: string
          description: >-
            Full-text autocomplete search on card title using the Atlas Search
            index.
        - name: assignee
          in: query
          schema:
            type: string
          description: Filter cards by assignee user ID.
        - name: segmentId
          schema:
            type: string
            maxLength: 256
          description: >-
            Existing accessible, active segment on this board; mutually
            exclusive with rules.
          in: query
        - name: rules
          schema:
            type: string
            maxLength: 64000
          description: >-
            JSON-encoded BoardFilterRule array, at most 100 rules. Prefer POST
            /list with a native JSON array.
          in: query
        - name: userId
          schema:
            type: string
            maxLength: 256
          description: >-
            Active company member whose private segments/currentUser values to
            use. API keys/partners may select a member; delegates cannot select
            another user.
          in: query
      responses:
        '200':
          description: Paginated list of cards.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/Card'
                  count:
                    type: integer
                    description: Total number of matching cards.
                  page:
                    type: integer
                  pageSize:
                    type: integer
        '400':
          description: Invalid rules, query parameters, or missing user context.
        '401':
          description: Invalid or missing API key.
        '403':
          description: >-
            Read access denied, API disabled, company mismatch, or invalid user
            selection.
        '404':
          description: Board or accessible active segment not found.
      deprecated: true
      security:
        - ApiKeyHeader: []
        - DelegateToken: []
        - PartnerBearer: []
components:
  schemas:
    Card:
      type: object
      properties:
        cardId:
          type: string
          description: Unique ID of the card.
        boardUuid:
          type: string
          description: UUID of the board this card belongs to.
        archived:
          type: boolean
        assignee:
          type: string
          description: Full name of the assigned user.
        lastActivity:
          type: object
          nullable: true
          description: >-
            Most recent conversation activity on the card (email, SMS or call),
            or null if the card has none.
          properties:
            content:
              type: string
              nullable: true
              description: Body/text preview of the most recent message.
            type:
              type: string
              nullable: true
              description: Activity type, e.g. `email`, `sms`, `voice`.
            direction:
              type: string
              nullable: true
              enum:
                - in
                - out
              description: Direction of the message — `in` (inbound) or `out` (outbound).
            publishedAt:
              type: string
              format: date-time
              nullable: true
            conversationUrl:
              type: string
              nullable: true
              description: >-
                Deep link to the conversation thread in Aptly. Null when the
                activity is not attached to a thread.
      additionalProperties:
        description: >-
          Additional properties are dynamic board fields keyed by their field
          UUID. Fields of type `files` come back as an array of file objects and
          type `file` as a single file object — `{ fileId, name, size, type,
          url, expiresAt }`, where `url` is a presigned download link valid
          until `expiresAt` (1 hour, or sooner if the signing session ends
          first). An id with no readable file record degrades to `{ fileId }`
          with no `url`.
  securitySchemes:
    ApiKeyHeader:
      type: apiKey
      in: header
      name: x-token
    DelegateToken:
      type: apiKey
      in: header
      name: Authorization
      description: 'Delegate token issued by the platform. Format: `DelegateToken <token>`'
    PartnerBearer:
      type: http
      scheme: bearer
      description: 'Partner token. Format: `Authorization: Bearer <token>`'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.