Returns every consent record for the contact, newest first (created_at descending). This includes
revoked and erased records and the unknown records written by contact imports that carried no
evidence. A contact with no records, or an id that matches no contact, returns an empty list rather
than a 404. The list is not paginated.
Use it to answer a data-subject access request or an auditor’s question: “on what basis was this person called?”
Consistency. Results are cached for up to 120 seconds. Granting, revoking and erasing evict the cache.
Access
read or write. Signed-in users with any of the owner, admin, member or viewer roles.Workspace API key: jl_ followed by 64 lowercase hex characters, created by the workspace owner in the
dashboard (Settings → API Keys) and sent as Authorization: Bearer jl_.... The plaintext is shown once,
at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys.
Operations restricted to admins or owners reject keys without the full scope with 403, and say so in
their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret —
that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds.
See Authentication.