Skip to main content
Documentation

Customers

customers.consent_standing

Check whether this shop may still message a customer, and until when
Read-onlyRead budget

REST

Shipping
POST /api/v1/customers/consent_standing

MCP tool

Live
customers.consent_standing

Exposed on: REST API · Shop MCP server · Claude connector · Dash (in-app copilot) · Zapier. Part of the Customers domain.

Operating contract

Reads three separate facts that are easy to confuse, and returns all three rather than folding them into one answer:

marketing_consent and sms_opt_out are the SWITCHES — what the shop is permitted to do right now. sms_opt_out wins over everything: somebody who replied STOP is not to be texted, whatever else is on file.

standing is the CASL provenance — WHY the shop may message them and whether that basis has aged out. 'implied_active' has a clock on it and implied_expires_on says when it stops; 'implied_lapsed' means it already has; 'undocumented' means nothing was ever recorded, which is not the same as a refusal.

THE IMPLIED WINDOW IS A CONSERVATIVE FLOOR. It runs from the transaction that was RECORDED, not necessarily the customer's most recent one, so it can report 'lapsed' for somebody a later purchase actually re-qualified. It never errs the other way.

REPORTING ONLY. Nothing in the send path reads standing, so a 'lapsed' answer does not block a message — it is the shop's judgement call, and this is the information they need to make it.

Who may call it

Permission
customers.accessThe caller must hold Customers at the ACT level. A read-only dashboard grant on the same section is refused.
Plan
Every planNo plan gate. Available on every Service VIN plan.
Retries
naturalNaturally idempotent — running it twice leaves the same world as running it once. A retrying integration needs no key.
Rate class
readCounted against the read budget — the widest of the four.

Input

FieldTypeDescription
customer_idrequiredstringuuid

The customer to check, as returned by customers.list or customers.get.

Output

FieldTypeDescription
marketing_consentboolean

sms_opt_outboolean

consent_sourcestring

consent_captured_atstring | null

standingstring

standing_labelstring

implied_expires_onstring | null

Examples

Built from this capability's own schema — required fields and the ones carrying a default, and nothing invented. Paste one and it validates.

curl
export SERVICEVIN_API_KEY=svk_live_…

curl -X POST https://www.servicevin.com/api/v1/customers/consent_standing \
  -H "Authorization: Bearer $SERVICEVIN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"customer_id":"9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"}'

TypeScript (fetch)
const res = await fetch("https://www.servicevin.com/api/v1/customers/consent_standing", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.SERVICEVIN_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "customer_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
  }),
});

// Success and failure are both envelopes. Switch on error.code, never
// on error.message — the codes are stable, the messages are for people.
const payload = await res.json();
if (!res.ok) throw new Error(payload.error.code);
const data = payload.data;

Python (requests)
import os, requests

res = requests.post(
    "https://www.servicevin.com/api/v1/customers/consent_standing",
    headers={"Authorization": f"Bearer {os.environ['SERVICEVIN_API_KEY']}"},
    json={
    "customer_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
},
    timeout=30,
)
payload = res.json()
if not res.ok:
    raise RuntimeError(payload["error"]["code"])
data = payload["data"]

MCP tools/call — https://www.servicevin.com/api/mcp
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "customers.consent_standing",
    "arguments": {
      "customer_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20"
    }
  }
}

Refusals

The four gates run in this order on every surface, and the order is not arbitrary — see Authentication.

StatusCodeWhen
404not_foundThe id is unknown, or the feature is not enabled for this account. Deliberately the same answer for both.
403forbiddenThis login does not hold customers.access.
422validation_errorAn argument was wrong. The message names the field.
429rate_limitedToo many read calls. Back off and retry.
500internal_errorSomething failed on our side. Nothing was changed.