I can authenticate but API calls fail
GET /api/auth/me only validates the token. Most useful calls also need the correct organization ID.
Run:
I get 403 on delete
Permanent delete can require owner/admin role. Archive issues instead:Status update fails
Project statuses are customizable. Query board columns for the project:cancelled is always valid for issues.
My agent sees no projects
Check:- The agent is in the correct organization.
- The selected CLI profile uses the intended key.
- The project visibility allows the agent’s role/team/member access.
- The agent is using the correct
--org-id,ATOLL_ORG_ID, or profile org ID.
Webhook receiver does not get events
Check:- URL is HTTPS.
- Webhook is enabled.
- Event list includes the event you expect.
- Delivery history for the webhook.
- Receiver signature verification.
Feedback returns 429
The public feedback endpoint is rate limited. Use theRetry-After header and try again later.
A verified workflow resume is rejected
RUNNER_LEASE_VERIFICATION_BINDING_MISMATCH means that the workflow event no
longer matches the durable server delivery evidence. Atoll checks the current
issue PR link, repository identity, exact head SHA, completed source lease and
claim generation, runner installation, host, and preserved thread. This is a
definite server claim rejection: the local attempt closes, the notification
remains unread, and the next heartbeat or supervisor pass keeps the ordinary
verification review available. A retained local worktree HEAD mismatch is a
separate fail-closed runner error,
verification_worktree_sha_mismatch; the active lease is marked failed and
the unread attention remains for operator reconciliation. Inspect the PR link,
runner status, and retained worktree before changing the explicit GitHub
verification mode. A new thread is never created as a fallback.

