> ## Documentation Index
> Fetch the complete documentation index at: https://omni.fireflo.au/llms.txt
> Use this file to discover all available pages before exploring further.

# GET /v1/cdp/contacts/{contact_id}/consent

> Where a contact stands on each channel, for marketing and for updates, with the history of changes.

Where a contact stands on each channel — for **marketing** (campaigns, promotional templates, offers) and **transactional** messages (replies, order and appointment updates) — and the changes that got them there.

<Note>Needs the `cdp.contacts:read` scope.</Note>

## Path parameters

| Field | Type | Required | Notes |
| :- | :- | :- | :- |
| `contact_id` | string | Yes | The contact's id. |

## Request

<CodeGroup>
  ```bash cURL theme={null}
  curl "https://api.fireflo.au/v1/cdp/contacts/3f6b2a1e-8c4d-4e2a-9b7f-5d1c0e8a9f42/consent" \
    -H "Authorization: Bearer $OMNI_API_KEY"
  ```

  ```python Python theme={null}
  import os

  import requests

  response = requests.get(
      "https://api.fireflo.au/v1/cdp/contacts/3f6b2a1e-8c4d-4e2a-9b7f-5d1c0e8a9f42/consent",
      headers={"Authorization": f"Bearer {os.environ['OMNI_API_KEY']}"},
  )
  print(response.status_code, response.json())
  ```

  ```javascript Node theme={null}
  const response = await fetch("https://api.fireflo.au/v1/cdp/contacts/3f6b2a1e-8c4d-4e2a-9b7f-5d1c0e8a9f42/consent", {
    headers: {
      Authorization: `Bearer ${process.env.OMNI_API_KEY}`,
    },
  });
  console.log(response.status, await response.json());
  ```
</CodeGroup>

## Response

`200 OK`.

`channels` has one row per channel people can stop, each with `marketing` and
`transactional`:

| Field | Meaning |
| :- | :- |
| `allowed` | Whether that kind of message may be sent to them on that channel now. |
| `status` | What they said for exactly that channel and purpose: `granted` (opted in), `revoked` (stopped) or `cleared` (nothing — the account's default). |
| `reason` | Why it isn't allowed: `stopped_all` (they stopped everything), `stopped`, or `no_opt_in` (the account requires an opt-in for marketing and there is none). Empty when allowed. |

`stopped_all` is true when they stopped everything; `require_marketing_opt_in` is the
account's setting. `history` is the last 50 changes, newest first, each with its
`source` — `keyword`, `preference_page`, `import`, `api`, `staff`, `merge` or `migration` —
and its `proof`.

```json theme={null}
{
  "contact": {
    "id": "3f6b2a1e-8c4d-4e2a-9b7f-5d1c0e8a9f42",
    "name": "Asha Rao",
    "phone": "+919876543210"
  },
  "stopped_all": false,
  "require_marketing_opt_in": false,
  "channels": [
    {
      "channel": "sms",
      "marketing": {
        "allowed": false,
        "status": "revoked",
        "reason": "stopped"
      },
      "transactional": {
        "allowed": true,
        "status": "cleared",
        "reason": ""
      }
    },
    {
      "channel": "whatsapp",
      "marketing": {
        "allowed": true,
        "status": "granted",
        "reason": ""
      },
      "transactional": {
        "allowed": true,
        "status": "cleared",
        "reason": ""
      }
    },
    {
      "channel": "rcs",
      "marketing": {
        "allowed": true,
        "status": "cleared",
        "reason": ""
      },
      "transactional": {
        "allowed": true,
        "status": "cleared",
        "reason": ""
      }
    }
  ],
  "history": [
    {
      "channel": "whatsapp",
      "purpose": "marketing",
      "status": "granted",
      "source": "api",
      "proof": "Ticked the WhatsApp offers box at checkout on acme.in",
      "at": "2026-10-06T10:42:17+05:30"
    },
    {
      "channel": "sms",
      "purpose": "marketing",
      "status": "revoked",
      "source": "keyword",
      "proof": "Replied STOP",
      "at": "2026-09-14T19:03:51+05:30"
    }
  ]
}
```

## Errors

Every refusal is `{"error": {"code", "message", "field"}}`; `field` is there when one input is at fault.

| Status | Error code | When |
| :- | :- | :- |
| 404 | `not_found` | No contact has that id on this account. |
| 403 | `scope_missing` | The key doesn't have the `cdp.contacts:read` scope. |
| 404 | `module_off` | The account doesn't have Customer data on. |

Any request can also be refused for its key, its account or its rate (`key_required`, `invalid_key`, `account_suspended`, `plan_excludes_api`, `address_not_allowed`, `rate_limited`); see [the overview](/api-reference/overview).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.