Skip to content

Consent certificates

Some lead vendors give each lead a link to a consent certificate. This connection asks the certificate provider whether the certificate is real and matches the phone number. Only certificates the provider confirms are recorded as consent. See consent proof.

  1. Open Setup, then Integrations, then Connections. Find Consent certificates and press Connect.
  2. Leave Provider as trustedform. It is the only choice.
  3. Check Certificate hosts we accept. The default is cert.trustedform.com. Add another host only if your provider uses one.
  4. Set Certificate is valid for (days). The default is 365. It sets when the recorded consent expires.
  5. Under Secrets, fill in API key with the key from your provider. It is required and never shown again.
  6. Press Connect, then Test. “It works.” means the key is saved. It does not call the provider, because a certificate is only checked when a lead brings one.

There are two ways in.

  • With a lead. Send consent_cert_url (and consent_at, when the form was filled in) on a lead to the inbound API. The first active consent connection checks it. A problem with a certificate never fails the lead import. It is reported in the answer under consent.
  • On its own. POST /api/integrations/v1/connectors/{id}/consent/verify takes {"items": [{"phone": "+14155552671", "cert_url": "https://cert.trustedform.com/…"}]}, 1 to 500 items. Each may also have lead_id, consent_at and reference. This needs a signed-in admin session.
  1. The address is checked. Its host must be one of your accepted hosts. The path must be a single certificate id of letters and digits. No user name or password. A numeric or private address is refused.
  2. VoDialer asks the provider about the certificate and the phone number, using your API key.
  3. The provider’s answer decides the result.
Result Meaning
verified The provider confirmed it. The consent is sent to compliance. consent_recorded is true when compliance stored it.
rejected The provider said no, or the certificate was not found or expired, or the address failed the checks. Nothing is recorded. The reason says why.
failed We could not get an answer: the network, a provider error or a rejected key. Send it again later.
not_configured No API key is saved. Nothing is recorded.

A recorded consent has the type tcpa, the source trustedform, the certificate link, the time the provider says it was captured, and an expiry that many days later. If the provider gives no time, we use consent_at, and otherwise the time of the check.