> ## Documentation Index
> Fetch the complete documentation index at: https://docs.atako.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Move a card to a column and a position

> The one gesture that changes a card's state, since the state IS the column. Kept apart from editing so that renaming a card never becomes a transactional write across the whole board. `position` is the rank the card takes among the live cards of the target column, counted without itself; a rank past the end simply lands it at the bottom.



## OpenAPI

````yaml /api-reference/openapi.json patch /projects/{projectId}/cards/{cardId}/move
openapi: 3.1.0
info:
  title: Atako API
  version: 0.1.0
  description: >-
    The Atako customer API — manage AI agents, their files, integrations,
    billing, and your company/team, programmatically.


    ## Authentication


    Every non-public endpoint takes a Bearer token that is either:

    - a **programmatic API key** (`aik_…`) — create one at
    [app.atako.ai](https://app.atako.ai) → Settings → API keys (company-admin
    only), or

    - a **Supabase session JWT** — what the web app itself sends; not practical
    to obtain outside a browser session.


    ```bash

    curl https://api.atako.ai/agents -H "Authorization: Bearer aik_..."

    ```


    An API key acts as its owning user, with all of that user's permissions —
    there is no separate key scope in this release.


    ## Other Atako HTTP surfaces (not covered by this spec)


    - **Atako MCP server** — `POST /mcp` (auth: same Bearer token as above)
    exposes a read-only Model Context Protocol tool catalogue for AI clients
    (Claude Code, Claude Desktop, Cursor, ChatGPT). See
    [docs.atako.ai/developers/mcp/overview](https://docs.atako.ai/developers/mcp/overview).

    - **Content API** (`cak_…` key, `/content/*`) — a separate, more restricted
    key type for headless CMS-style access to blog/news/use-case content. Not
    documented here.


    ## Errors


    Errors use a JSON envelope: `{ "error": string, "code"?: string }`. `error`
    is either a short human-readable message or a SCREAMING_SNAKE_CASE code,
    depending on the route — treat it as an opaque string to match against, not
    a stable enum across the whole API.


    ## Rate limits


    Authenticated routes: 6000 requests/min per user (`authRateLimit`). Public
    GET routes: 60/min per IP. A handful of sensitive public POST routes
    (newsletter signup, email-exists, invitation preview) are limited to 10
    requests / 15 min per IP.


    ## Pagination


    List endpoints use either simple `limit`/`offset` query params (marketing
    content — a plain JSON array response, capped at the documented max) or
    `page`/`limit` (credit transactions). Neither returns a total count today;
    fetch until a page comes back shorter than `limit`.
servers:
  - url: https://api.atako.ai
    description: Production
security: []
tags:
  - name: Agents
  - name: Messages
  - name: Activity
  - name: Agent Options
  - name: API Keys
  - name: Files
  - name: Cron Jobs
  - name: Sub-Agents
  - name: Interagent Messages
  - name: Integrations
  - name: Subscriptions
  - name: Users
  - name: Company
  - name: Teams
  - name: Floor
  - name: Projects
  - name: Public
  - name: Marketing Content
paths:
  /projects/{projectId}/cards/{cardId}/move:
    patch:
      tags:
        - Projects
      summary: Move a card to a column and a position
      description: >-
        The one gesture that changes a card's state, since the state IS the
        column. Kept apart from editing so that renaming a card never becomes a
        transactional write across the whole board. `position` is the rank the
        card takes among the live cards of the target column, counted without
        itself; a rank past the end simply lands it at the bottom.
      operationId: moveProjectCard
      parameters:
        - name: projectId
          in: path
          required: true
          description: Project id
          schema:
            type: string
            format: uuid
        - name: cardId
          in: path
          required: true
          description: Card id
          schema:
            type: string
            format: uuid
      requestBody:
        description: ''
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - columnId
                - position
              properties:
                columnId:
                  type: string
                  format: uuid
                  description: Target column — must belong to this project.
                position:
                  type: integer
                  minimum: 0
      responses:
        '200':
          description: >-
            The moved card, plus the new contents of the source and target
            columns (one entry when it stayed in the same column).
          content:
            application/json:
              schema:
                type: object
                properties:
                  card:
                    $ref: '#/components/schemas/ProjectCard'
                  columns:
                    type: array
                    items:
                      $ref: '#/components/schemas/ProjectColumnOrder'
                required:
                  - card
                  - columns
        '400':
          description: Validation error, malformed id, or `column_not_in_project`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing, malformed, or invalid bearer token / API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Not found, or the caller is not authorized to access this resource.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearerAuth: []
components:
  schemas:
    ProjectCard:
      type: object
      description: >-
        A unit of work on the board. It carries no status field: where the card
        stands IS its state, so read `column`. `blocked` and `due` are absent
        rather than null when unset — asking whether a card is blocked is asking
        for the reason.
      properties:
        id:
          type: string
          format: uuid
        title:
          type: string
          maxLength: 500
        description:
          type: string
          maxLength: 20000
        assignee:
          type: string
          format: uuid
          nullable: true
          description: >-
            A ProjectParticipant id (project_members row) — human or agent, both
            assignable — or null when nobody has taken the card.
        column:
          type: string
          format: uuid
          description: 'The column the card stands in: its state.'
        priority:
          $ref: '#/components/schemas/ProjectCardPriority'
        blocked:
          type: string
          maxLength: 500
          description: >-
            Why the card cannot move. Absent when it is not blocked — there is
            no blocked flag, only the reason.
        labels:
          type: array
          items:
            type: string
            maxLength: 40
        createdAt:
          type: string
          format: date-time
        updatedAt:
          type: string
          format: date-time
        due:
          type: string
          format: date-time
          description: Absent when the card has no deadline.
        checklist:
          type: array
          items:
            $ref: '#/components/schemas/ProjectCardChecklistItem'
        comments:
          type: array
          items:
            $ref: '#/components/schemas/ProjectCardComment'
          description: >-
            Oldest first — a discussion is read in the order it was written, not
            like an inbox.
      required:
        - id
        - title
        - description
        - assignee
        - column
        - priority
        - labels
        - createdAt
        - updatedAt
        - checklist
        - comments
    ProjectColumnOrder:
      type: object
      description: >-
        The up-to-date contents of one column, so a board can be redrawn after a
        move without reloading the project. Only the columns the move actually
        touched are reported — one when the card stayed in place, two when it
        changed column.
      properties:
        id:
          type: string
          format: uuid
        cardIds:
          type: array
          items:
            type: string
            format: uuid
          description: Live cards, top to bottom. Archived cards are never listed.
      required:
        - id
        - cardIds
    Error:
      type: object
      description: >-
        Atako's standard error envelope. `error` is either a short
        human-readable message or a SCREAMING_SNAKE_CASE code (routes are
        inconsistent about which — treat it as an opaque string and match on it
        exactly if you need to branch on error type). Some routes add extra
        fields alongside `error` (see the operation's own error responses).
      properties:
        error:
          type: string
        code:
          type: string
          description: >-
            Present on some routes; a stable machine-readable code duplicating
            or refining `error`.
      required:
        - error
      additionalProperties: true
    ProjectCardPriority:
      type: string
      enum:
        - low
        - normal
        - high
    ProjectCardChecklistItem:
      type: object
      description: >-
        One line of a card's checklist — the small steps a card is made of,
        ticked off without splitting it into more cards.
      properties:
        text:
          type: string
          minLength: 1
          maxLength: 500
        done:
          type: boolean
      required:
        - text
        - done
    ProjectCardComment:
      type: object
      description: >-
        A message on a card — where the discussion that led to a decision stays
        attached to the work it decided. `author` is the display name frozen
        when the comment was written, so someone leaving the company never
        empties the thread behind them. `id` is present on everything the card
        operations return; the copy embedded in GET /projects/{id} carries only
        author/at/text.
      properties:
        id:
          type: string
          format: uuid
        author:
          type: string
        at:
          type: string
          format: date-time
        text:
          type: string
          maxLength: 10000
      required:
        - author
        - at
        - text
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        An `aik_…` programmatic API key (app.atako.ai → Settings → API keys) or
        a Supabase session JWT.

````