Check a contact's consent

View as Markdown
Returns `hasConsent: true` when the contact has an active `granted` record of this type whose `expires_at` is empty or in the future. The check compares against the current UTC time. `revoked`, `erased` and `unknown` records never count. An id that matches no contact returns `false`, not 404. This is the same test the campaign dialer runs for `voice_call` when the workspace requires consent before calling. To pre-flight hours, suppression, DNC and attempt limits as well, use `POST /api/compliance/check-call`. **Consistency.** Results are cached for up to 120 seconds. Granting, revoking and erasing evict the cache, but a grant's natural expiry can take up to 120 seconds to show. **Access** - **Required scope:** `read` or `write`. Signed-in users with any of the `owner`, `admin`, `member` or `viewer` roles. - **Rate limit:** General API — 120 (Starter), 200 (Growth), 300 (Business) or 600 (Enterprise) requests/min per workspace. See [Rate limits](/rate-limits). - **Plan:** Available on every plan.

Authentication

AuthorizationBearer
Workspace API key: `jl_` followed by 64 lowercase hex characters, created by the workspace owner in the dashboard (**Settings → API Keys**) and sent as `Authorization: Bearer jl_...`. The plaintext is shown once, at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys. | Scope | GET / HEAD | POST / PUT / PATCH / DELETE | Admin-only routes | | --- | --- | --- | --- | | `read` | Yes | No | No | | `write` | Yes | Yes | No | | `full` | Yes | Yes | Yes | Operations restricted to admins or owners reject keys without the `full` scope with `403`, and say so in their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret — that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds. See [Authentication](/authentication).

Path parameters

contactIdstringRequiredformat: "uuid"
The contact's id. A value that is not a UUID returns 400.
consentTypeenumRequired
The consent type to test. Any other value, including the retired `sms`, returns 400. - `voice_call`: phone calls. - `email`: commercial email. - `data_processing`: storing and processing personal data.
Allowed values:

Response

Consent state.
dataobject

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
429
Too Many Requests Error