Quick start
First-time setup creates your admin account and returns both token types:JWT tokens (HTTP API)
All API requests use atell_-prefixed JWT token in the Authorization header:
Login
Refresh
Extend a token’s expiry without re-entering credentials:Logout
Current user
Check who a token belongs to:401.
CLI login
The CLI stores credentials in your OS keyring (macOS Keychain, Windows Credential Manager, or Linux Secret Service):Streaming API keys (data ingestion)
SDKs and pipeline sources use 32-character hex keys to authenticate data ingestion:Sessions
Tell tracks sessions per device with IP address and user agent. You can be logged in from multiple devices simultaneously. Thelogout endpoint terminates all sessions at once.
Rate limiting
Auth endpoints are rate-limited to 10 requests per minute per IP address. If you exceed this, you’ll receive a429 Too Many Requests response with a Retry-After: 60 header.
List responses
Every endpoint that returns a list of one kind of resource uses the same shape:itemsholds one page of results.totalcounts every matching row across all pages, not just this page.limitandoffsetecho the page you got.has_moreistruewhen rows exist past this page.
limit and offset query parameters:
Boards, canvases, board groups, and workspace lists (
/boards, /canvases, /board-groups, /user/workspaces, /admin/workspaces) default to limit=200 so a plain request returns everything for typical workspaces. The maximum is still 200.
Some lists add fields beside these five. For example, /people also returns all_time and total_events_scope.
Single resources and analytics results (metric series, funnels, retention) don’t use this shape.
Token format
JWT tokens contain the user ID, email, role, and workspace ID. Streaming keys map directly to a workspace ID with no additional claims.
What’s next
- Roles & Permissions — what each role can do
- API Keys — managing streaming and programmatic keys
- Workspaces — multi-tenant workspace isolation