Consent certificates
Some lead vendors give each lead a link to a consent certificate. This connection asks the certificate provider whether the certificate is real and matches the phone number. Only certificates the provider confirms are recorded as consent. See consent proof.
Do this
Section titled “Do this”- Open Setup, then Integrations, then Connections. Find Consent certificates and press Connect.
- Leave Provider as
trustedform. It is the only choice. - Check Certificate hosts we accept. The default is
cert.trustedform.com. Add another host only if your provider uses one. - Set Certificate is valid for (days). The default is 365. It sets when the recorded consent expires.
- Under Secrets, fill in API key with the key from your provider. It is required and never shown again.
- Press Connect, then Test. “It works.” means the key is saved. It does not call the provider, because a certificate is only checked when a lead brings one.
How certificates get checked
Section titled “How certificates get checked”There are two ways in.
- With a lead. Send
consent_cert_url(andconsent_at, when the form was filled in) on a lead to the inbound API. The first active consent connection checks it. A problem with a certificate never fails the lead import. It is reported in the answer underconsent. - On its own.
POST /api/integrations/v1/connectors/{id}/consent/verifytakes{"items": [{"phone": "+14155552671", "cert_url": "https://cert.trustedform.com/…"}]}, 1 to 500 items. Each may also havelead_id,consent_atandreference. This needs a signed-in admin session.
What happens to each certificate
Section titled “What happens to each certificate”- The address is checked. Its host must be one of your accepted hosts. The path must be a single certificate id of letters and digits. No user name or password. A numeric or private address is refused.
- VoDialer asks the provider about the certificate and the phone number, using your API key.
- The provider’s answer decides the result.
| Result | Meaning |
|---|---|
verified |
The provider confirmed it. The consent is sent to compliance. consent_recorded is true when compliance stored it. |
rejected |
The provider said no, or the certificate was not found or expired, or the address failed the checks. Nothing is recorded. The reason says why. |
failed |
We could not get an answer: the network, a provider error or a rejected key. Send it again later. |
not_configured |
No API key is saved. Nothing is recorded. |
A recorded consent has the type tcpa, the source trustedform, the certificate link, the time the provider says it was captured, and an expiry that many days later. If the provider gives no time, we use consent_at, and otherwise the time of the check.