Search consents
Searches contact-grain consent observations for the credential’s scope, ordered by created_at (newest first). Filters combine with AND. Email and SMS consents for the same guest are separate rows. The API returns individual observations; when multiple rows exist for the same contact×purpose within a property group, effective eligibility is the most restrictive status among them. Paginated via limit/cursor. Requires scope read:consents.
Authorizations
Authorization: Bearer <token>. Token types resolve to the same scoped credential: a user-generated API key (casa_…, from Account settings — recommended for machines and MCP clients), a WorkOS AuthKit session JWT (the web app; org and role come from verified token claims), or a static token. API keys are group-scoped, optionally pinned to one property at creation. MCP OAuth connector tokens authenticate the MCP server only and are rejected on these REST routes.
Headers
Optional single-property drill-down. When set, narrows the request to this property; it must belong to the caller's group, else 403. A property-pinned API key is already narrowed and ignores this header.
Query Parameters
Exact match on normalized contact value (e.g. email address or E.164 phone).
email, sms, phone, postal, whatsapp, unknown marketing, marketing_partner, transactional, payment_storage, biometric_capture, other granted, denied, withdrawn Filter to observations linked to this guest profile at ingest time (provenance only).
Page size — rows returned per call (1–500). This is NOT a cap on the total dataset: follow next_cursor to retrieve every matching row.
1 <= x <= 500Opaque pagination token from a previous response's next_cursor. Omit for the first page. A malformed token returns 400 invalid_cursor.
Response
Matching consent observations.
Keyset-pagination fields present on every list/search response. When has_more is true, re-request with cursor set to next_cursor; repeat until next_cursor is null to retrieve the full result set.