> ## Documentation Index
> Fetch the complete documentation index at: https://docs.closient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# TRMNL device setup

> Called by TRMNL firmware on first boot. The device presents its MAC in the ``ID`` header; the server responds with an ``api_key`` (used as ``Access-Token`` on every subsequent call), a 6-char ``friendly_id``, the URL of the device's first image, and a suggested filename for local caching.

If the MAC has never been seen, an unclaimed :class:`BYOSDevice` row is created — the device starts in the ``unclaimed`` state and renders the BYOS fallback image until an operator links it to an organization.

**Auth:** unauthenticated. The TRMNL firmware doesn't have an ``Access-Token`` yet at this call.

* ``200`` — setup succeeded; device may begin polling ``/api/display``.
* ``400`` — the ``ID`` header is missing or not a 12-char hex MAC.



## OpenAPI

````yaml /openapi/openapi-byos.json get /byos/api/setup/
openapi: 3.1.0
info:
  title: BYOS API
  version: 1.0.0
  description: >
    Closient's TRMNL-compatible **Bring Your Own Server** endpoints. Powers
    e-ink analytics displays — devices poll ``/api/setup/`` on first boot, then
    ``/api/display`` on a schedule to fetch the image they should paint. The
    wire protocol matches TRMNL's BYOS contract verbatim so off-the-shelf
    reTerminal firmware works without modification.


    ## Authentication


    All endpoints require an API key passed via the `X-API-Key` HTTP header,
    unless otherwise noted.


    ```

    X-API-Key: csb_<body>_<checksum>

    ```


    Generate API keys in **Settings > API Keys** in your dashboard, or via the
    Account API.

    Session-based (cookie) authentication is also accepted for browser-based
    access.


    ## Rate Limits


    | Tier        | Requests / minute | Requests / day |

    |-------------|-------------------|----------------|

    | Default     | 300               | 10,000         |

    | Custom      | Contact us        | Contact us     |


    Rate-limit headers are included on every response so callers can
    self-throttle without

    hitting our 429s ("informed governor"):


    - `RateLimit-Policy` — every active window, e.g. `300;w=60, 10000;w=86400`

    - `RateLimit-Limit` — quota for the **most-restrictive** currently-active
    window

    - `RateLimit-Remaining` — requests left in that window

    - `RateLimit-Reset` — seconds until that window resets (relative; clock-skew
    safe)


    Legacy `X-RateLimit-*` aliases are also emitted for back-compat.
    `X-RateLimit-Reset`

    keeps the absolute Unix-timestamp shape to avoid breaking existing
    consumers.


    When rate-limited, you receive `429 Too Many Requests` with a
    `retry_after_seconds` field

    in the error envelope and a `Retry-After` header.


    ## Pagination


    List endpoints return paginated results in this envelope:


    ```json

    {
      "data": [...],
      "pagination": {
        "page": 1,
        "page_size": 25,
        "total_count": 342,
        "total_pages": 14,
        "has_next": true,
        "has_previous": false
      }
    }

    ```


    Use `?page=2&page_size=50` query parameters. Maximum page size is 100.


    ## Error Responses


    All errors conform to [RFC 9457 Problem
    Details](https://www.rfc-editor.org/rfc/rfc9457)

    with `Content-Type: application/problem+json`:


    ```json

    {
      "type": "https://closient.com/docs/errors/not_found",
      "title": "Not Found",
      "status": 404,
      "detail": "The requested resource was not found.",
      "error_code": "not_found",
      "retryable": false,
      "timestamp": "2026-03-31T12:00:00+00:00"
    }

    ```


    Common error codes: `unauthorized` (401), `forbidden` (403), `not_found`
    (404),

    `validation_error` (422), `rate_limited` (429), `internal_error` (500).
  termsOfService: https://www.closient.com/terms/
servers:
  - url: https://www.closient.com
security: []
externalDocs:
  description: Closient Documentation
  url: https://docs.closient.com
paths:
  /byos/api/setup/:
    get:
      tags:
        - byos-trmnl
      summary: TRMNL device setup
      description: >-
        Called by TRMNL firmware on first boot. The device presents its MAC in
        the ``ID`` header; the server responds with an ``api_key`` (used as
        ``Access-Token`` on every subsequent call), a 6-char ``friendly_id``,
        the URL of the device's first image, and a suggested filename for local
        caching.


        If the MAC has never been seen, an unclaimed :class:`BYOSDevice` row is
        created — the device starts in the ``unclaimed`` state and renders the
        BYOS fallback image until an operator links it to an organization.


        **Auth:** unauthenticated. The TRMNL firmware doesn't have an
        ``Access-Token`` yet at this call.


        * ``200`` — setup succeeded; device may begin polling ``/api/display``.

        * ``400`` — the ``ID`` header is missing or not a 12-char hex MAC.
      operationId: apps_boards_api_trmnl_trmnl_setup
      parameters: []
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SetupOut'
        '400':
          description: Bad Request
          content:
            application/problem+json:
              schema:
                additionalProperties: true
                title: Response
                type: object
        '404':
          description: Not Found
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '405':
          description: Method Not Allowed
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
        '429':
          description: Too Many Requests
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/ErrorOut'
components:
  schemas:
    SetupOut:
      description: |-
        Response to ``GET /api/setup/``.

        The TRMNL firmware persists ``api_key`` to flash and uses it on every
        subsequent call. ``image_url`` is the first image to paint — for an
        unclaimed device this is the fallback "register me" screen.
      examples:
        - api_key: d51229662e86a29fe6ab11a4ca1a4a41d141fc8b
          filename: closient-A1B2C3-3f9a2c1d8e.png
          friendly_id: A1B2C3
          image_url: https://www.closient.com/byos/devices/A1B2C3/image.png
          message: ''
          status: 200
      properties:
        api_key:
          description: >-
            Opaque per-device access token. Firmware stores this in flash and
            sends it in the ``Access-Token`` header on every subsequent call.
          title: Api Key
          type: string
        friendly_id:
          description: >-
            Short 6-character human-readable device label (e.g. ``A1B2C3``).
            Shown on the panel during first-boot and used in dashboard URLs.
          title: Friendly Id
          type: string
        image_url:
          description: >-
            Absolute URL the device should fetch to paint its first image. For
            an unclaimed device this points to the BYOS fallback image.
          title: Image Url
          type: string
        filename:
          description: >-
            Suggested filename for the device to use when caching the fetched
            image locally.
          title: Filename
          type: string
        message:
          default: ''
          description: >-
            Optional human-readable message — currently always empty on success.
            Future: post-firmware-update notes.
          title: Message
          type: string
        status:
          default: 200
          description: >-
            TRMNL setup status code. Always 200 on success; 404 on devices that
            should refuse to operate (currently unused).
          title: Status
          type: integer
      required:
        - api_key
        - friendly_id
        - image_url
        - filename
      title: SetupOut
      type: object
    ErrorOut:
      title: ErrorOut
      type: object
      description: RFC 9457 Problem Details error body.
      properties:
        type:
          type: string
          format: uri
        title:
          type: string
        status:
          type: integer
        detail:
          type: string
        error_code:
          type: string
        retryable:
          type: boolean
        timestamp:
          type: string
          format: date-time
      required:
        - type
        - title
        - status
        - detail
      examples:
        - type: https://closient.com/docs/errors/not_found
          title: Not Found
          status: 404
          detail: The requested resource was not found.
          error_code: not_found
          retryable: false
          timestamp: '2026-03-31T12:00:00+00:00'

````