Skip to main content
Documentation

Customers

customers.record_consent

Record why this shop may message a customer, and since when
WritesSensitiveWrite budget

REST

Shipping
POST /api/v1/customers/record_consent

MCP tool

Live
customers.record_consent

Exposed on: REST API · Shop MCP server · Claude connector · Dash (in-app copilot) · Zapier. Part of the Customers domain.

Operating contract

Writes the CASL provenance on a customer record: WHY the shop may message them (consent_source) and SINCE WHEN (consent_captured_at). The burden of proof sits on the sender, so 'we think they said yes at some point' is not a defence and a dated basis is.

This does NOT turn messaging on or off — that is customers.marketing_consent, a different field with a different meaning. This records the evidence behind it.

Only record a basis you actually have. An integration posting a contact is not itself evidence of consent, and a bare timestamp with an unknown source is dropped rather than stored, so it cannot later read as proof.

consent_source values are the shop-facing vocabulary; ask the shop which applies rather than guessing between an express opt-in and an existing business relationship.

Who may call it

Permission
customers.accessThe caller must hold Customers at the ACT level. A read-only dashboard grant on the same section is refused.
Plan
Every planNo plan gate. Available on every Service VIN plan.
Retries
naturalNaturally idempotent — running it twice leaves the same world as running it once. A retrying integration needs no key.
Rate class
writeCounted against the write budget, which is tighter than a read.

Input

FieldTypeDescription
customer_idrequiredstringuuid

The customer to record consent for, as returned by customers.list or customers.get.

consent_sourcerequiredstring

The basis on which this shop may message them.

One of: express_written, express_verbal, online_booking, web_form, implied_existing_business, implied_inquiry, imported, unknown
consent_captured_atstringdate-time

When that basis was captured, ISO 8601 with an offset.

consent_notestringmax 500 chars

A short note about the basis, for the shop's own audit trail.

Output

FieldTypeDescription
idstring

namestring

emailstring | null

phonestring | null

citystring | null

regionstring | null

postal_codestring | null

tagsstring[]

is_vipboolean

created_atstring

Examples

Built from this capability's own schema — required fields and the ones carrying a default, and nothing invented. Paste one and it validates.

curl
export SERVICEVIN_API_KEY=svk_live_…

curl -X POST https://www.servicevin.com/api/v1/customers/record_consent \
  -H "Authorization: Bearer $SERVICEVIN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"customer_id":"9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20","consent_source":"express_written"}'

TypeScript (fetch)
const res = await fetch("https://www.servicevin.com/api/v1/customers/record_consent", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.SERVICEVIN_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "customer_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20",
    "consent_source": "express_written"
  }),
});

// Success and failure are both envelopes. Switch on error.code, never
// on error.message — the codes are stable, the messages are for people.
const payload = await res.json();
if (!res.ok) throw new Error(payload.error.code);
const data = payload.data;

Python (requests)
import os, requests

res = requests.post(
    "https://www.servicevin.com/api/v1/customers/record_consent",
    headers={"Authorization": f"Bearer {os.environ['SERVICEVIN_API_KEY']}"},
    json={
    "customer_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20",
    "consent_source": "express_written"
},
    timeout=30,
)
payload = res.json()
if not res.ok:
    raise RuntimeError(payload["error"]["code"])
data = payload["data"]

MCP tools/call — https://www.servicevin.com/api/mcp
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "customers.record_consent",
    "arguments": {
      "customer_id": "9b2f1c6e-4a77-4d2b-9f31-0f1c9a8e5d20",
      "consent_source": "express_written"
    }
  }
}

Refusals

The four gates run in this order on every surface, and the order is not arbitrary — see Authentication.

StatusCodeWhen
404not_foundThe id is unknown, or the feature is not enabled for this account. Deliberately the same answer for both.
403forbiddenThis login does not hold customers.access.
403insufficient_scopeThe credential is read-only and this capability writes.
422validation_errorAn argument was wrong. The message names the field.
429rate_limitedToo many write calls. Back off and retry.
500internal_errorSomething failed on our side. Nothing was changed.