# Trello > Trello is a web-based kanban application from Atlassian for organising work as boards, > lists and cards. Its public REST API (v1, https://api.trello.com/1) exposes 261 > operations across boards, lists, cards, checklists, labels, custom fields, members, > workspaces, enterprises, actions, notifications, search, webhooks, tokens and Power-Up > plugins. Authorization is either a legacy API key + user token pair or, since > 15 September 2026, OAuth 2.0 3LO with ten granular scopes. Generated by API Evangelist from the Trello record at https://apis.io/trello. Trello does not publish an llms.txt of its own — https://trello.com/llms.txt returns the Trello single-page-app HTML shell, not a document. Atlassian publishes a corporate llms.txt at https://www.atlassian.com/llms.txt, which names Trello as a product but carries nothing about the Trello API. ## Machine-readable contract - [Trello REST API OpenAPI 3.0.0](https://developer.atlassian.com/cloud/trello/swagger.v3.json): The first-party specification, 191 paths / 261 operations / 63 schemas, published by Atlassian. Every operation carries an operationId and a summary. Servers: https://api.trello.com/1. - [Webhook event surface (AsyncAPI 2.6.0)](https://developer.atlassian.com/cloud/trello/guides/rest-api/webhooks/): Trello pushes an Action object to a registered callback URL for every change on a watched model, signed HMAC-SHA1 in X-Trello-Webhook. ## Authorization - [Authorization guide](https://developer.atlassian.com/cloud/trello/guides/rest-api/authorization/): Legacy Trello Auth — key + token in query params, Authorization header, or request body. Coarse scopes read / write / account. Token expiry 1hour, 1day, 30days or never. - [OAuth 2.0 3LO](https://developer.atlassian.com/cloud/trello/guides/rest-api/oauth-2-getting-started/): GA 15 September 2026. Authorization code grant at https://auth.atlassian.com/authorize. Ten scopes: read/write:board:trello, write:board:membership:trello, read/write:organization:trello, write:organization:membership:trello, read/write:member:trello, read/write:enterprise:trello. Short-lived tokens with refresh. - OAuth 1.0a is also still supported at https://trello.com/1/OAuthGetRequestToken. ## Runtime semantics an agent needs - **No idempotency.** Trello publishes no Idempotency-Key header, no client request id and no dedup window anywhere in its 261 operations. A retried create makes a second object. Verify before retrying. - **No rate-limit headers.** Limits are documented in prose only — 300 requests per 10 seconds per API key, 100 per 10 seconds per token, 100 per 900 seconds on /1/members, and stricter ceilings on /1/membersSearch and /1/search. There is no X-RateLimit-*, no RateLimit-* and no documented Retry-After. The only machine signal is the symbolic code in the 429 body: API_KEY_LIMIT_EXCEEDED, API_TOKEN_LIMIT_EXCEEDED, API_TOKEN_DB_LIMIT_EXCEEDED, API_TOO_MANY_CARDS_REQUESTED. Exceeding 200 429s on one key inside a 10s window locks the key out for the rest of that window. - **Removal is reversible, deletion is not.** Cards, lists and boards are archived with closed=true and restored with closed=false, with no time limit. DELETE operations are permanent. POST /1/lists/{id}/archiveAllCards has no bulk undo and does not return the ids it archived. - **No dry-run mode** on any write operation. - **Ids carry no type prefix.** Every id is a bare 24-character hex string, so the polymorphic idModel field (webhooks, custom fields, plugin data) is opaque without out-of-band knowledge. - **Errors are not RFC 9457.** The envelope is {"error","message"} JSON on rate limits, and bare text/plain such as "invalid token" on many auth failures. 247 of the 261 operations declare no error response at all in the spec. ## Documentation - [Trello developer home](https://developer.atlassian.com/cloud/trello/) - [REST API reference](https://developer.atlassian.com/cloud/trello/rest/) - [API introduction](https://developer.atlassian.com/cloud/trello/guides/rest-api/api-introduction/) - [Nested resources](https://developer.atlassian.com/cloud/trello/guides/rest-api/nested-resources/) - [Object definitions](https://developer.atlassian.com/cloud/trello/guides/rest-api/object-definitions/) - [Object limits](https://developer.atlassian.com/cloud/trello/guides/rest-api/limits/) - [Rate limits](https://developer.atlassian.com/cloud/trello/guides/rest-api/rate-limits/) - [Status codes](https://developer.atlassian.com/cloud/trello/guides/rest-api/status-codes/) - [Action types](https://developer.atlassian.com/cloud/trello/guides/rest-api/action-types/) - [Custom fields](https://developer.atlassian.com/cloud/trello/guides/rest-api/getting-started-with-custom-fields/) - [Automating exports](https://developer.atlassian.com/cloud/trello/guides/rest-api/automating-exports/) - [Changelog](https://developer.atlassian.com/cloud/trello/changelog/): the stated source of truth for Trello developer platform changes. ## Client-side surface - [client.js](https://developer.atlassian.com/cloud/trello/guides/client-js/client-js-reference/): Atlassian's only first-party client library. Browser-only, requires jQuery, loaded unversioned from https://api.trello.com/1/client.js?key={APIKey}. - [Power-Up client library](https://developer.atlassian.com/cloud/trello/power-ups/client-library/): iframe bridge for extending the Trello UI, loaded unversioned from https://p.trellocdn.com/power-up.min.js. - [Board Tile Component](https://developer.atlassian.com/cloud/trello/guides/components/board-tile-component/) and [Card Component](https://developer.atlassian.com/cloud/trello/guides/components/card-components/): embeddable renderings of live Trello objects. - There is NO first-party server-side SDK on npm, PyPI, RubyGems, NuGet, Maven Central, Packagist, crates.io or the Go module proxy. Every language binding is community-maintained. ## Agent surfaces - No MCP server. Atlassian operates a remote MCP server at https://mcp.atlassian.com/v2/mcp, but it covers Jira, Jira Service Management, Confluence, Bitbucket, Projects and Goals — not Trello. - No A2A agent card. The Atlassian Rovo card at https://a2a.atlassian.com/.well-known/agent.json declares two skills, work-in-jira and work-in-confluence, and mentions Trello nowhere. ## Operations - [Status page](https://trello.status.atlassian.com/) with a machine-readable Statuspage v2 API at /api/v2/status.json and /api/v2/summary.json. - [security.txt](https://trello.com/.well-known/security.txt): PGP-signed RFC 9116 document, canonical at https://www.atlassian.com/.well-known/security.txt. - [Atlassian Trust Center](https://www.atlassian.com/trust). Trello states SOC 2 Type 2, ISO/IEC 27001 and PCI DSS certification on its pricing page. ## Commercial - [Pricing](https://trello.com/pricing): Free (up to 10 collaborators per workspace, 10 boards), Standard $5/user/month annual, Premium $10/user/month annual, Enterprise $17.50/user/month annual. - [Terms of service](https://www.atlassian.com/legal/cloud-terms-of-service) - [Privacy policy](https://www.atlassian.com/legal/privacy-policy) - [Developer terms](https://developer.atlassian.com/cloud/trello/developer-terms/) ## Support - [Developer community](https://community.developer.atlassian.com/c/trello/) - [Help center](https://support.atlassian.com/trello/) - [Developer support](https://developer.atlassian.com/support)