# Notes

> List, add, change and delete the notes on a lead through the Fondaro API.

Notes are the written record on a lead. Reading needs `crm:read`; adding, changing and deleting need `crm:write` and an active plan.

A member reaches the notes of their own leads; an admin reaches every note. A lead or note you cannot reach answers `404` with "Lead not found." or "Note not found.", the same as one that does not exist. Anyone with access to the lead may edit its notes; a member may delete only notes they wrote, and an admin may delete any.

## List the notes on a lead

`GET /v1/leads/{leadId}/notes`

Every note on the lead, newest first, in one response with `hasMore: false`.

| Parameter | In | Type | Required | Description |
|-----------|----|------|----------|-------------|
| `leadId` | Path | integer | Yes | The id of the lead |

```bash
curl https://api.fondaro.com/v1/leads/1042/notes \
  -H "Authorization: Bearer $FONDARO_API_KEY"
```

```json
{
  "data": [
    {
      "id": "3f6c2a10-0000-4000-8000-000000000009",
      "leadId": 1042,
      "authorId": "user_2abcDEF1234567890ghiJKL",
      "content": "Call back on Friday",
      "isPinned": false,
      "occurredAt": null,
      "createdAt": "2026-10-04T12:02:10.064Z",
      "updatedAt": "2026-10-04T12:02:10.064Z"
    }
  ],
  "hasMore": false
}
```

## Add a note to a lead

`POST /v1/leads/{leadId}/notes`

Adds a note written by the key's person. Accepts an `Idempotency-Key` header.

| Parameter | In | Type | Required | Description |
|-----------|----|------|----------|-------------|
| `leadId` | Path | integer | Yes | The id of the lead |
| `content` | Body | string | Yes | The text of the note |

```bash
curl -X POST https://api.fondaro.com/v1/leads/1042/notes \
  -H "Authorization: Bearer $FONDARO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "content": "Call back on Friday" }'
```

The `201` response is the note, as in the list above.

## Change a note

`PATCH /v1/notes/{noteId}`

Replaces the note's text.

| Parameter | In | Type | Required | Description |
|-----------|----|------|----------|-------------|
| `noteId` | Path | UUID | Yes | The id of the note |
| `content` | Body | string | Yes | The new text |

```bash
curl -X PATCH https://api.fondaro.com/v1/notes/3f6c2a10-0000-4000-8000-000000000009 \
  -H "Authorization: Bearer $FONDARO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "content": "Call back on Friday, edited" }'
```

The response is the note with the new `content` and a later `updatedAt`.

## Delete a note

`DELETE /v1/notes/{noteId}`

Permanently deletes the note.

| Parameter | In | Type | Required | Description |
|-----------|----|------|----------|-------------|
| `noteId` | Path | UUID | Yes | The id of the note |

```bash
curl -X DELETE https://api.fondaro.com/v1/notes/3f6c2a10-0000-4000-8000-000000000009 \
  -H "Authorization: Bearer $FONDARO_API_KEY"
```

The response is `204` with no body. Errors: `404` "Note not found."

Source: https://www.fondaro.com/docs/api/v1/notes
