Morffeus Docs
ENSR morffeus.com

Notifications & consent

Your app decides what to tell customers; the customer decides how they may be reached. These calls let a signed-in customer see and change their marketing consent, and let your mobile app register the device that receives push messages.

Who calls these#

The consent calls and the device registration act on the customer signed in to the session, and on nobody else: any customer id in the body is ignored. They need a signed-in customer's token in Authorization: Bearer; see Sessions & sign-in.

How consent works#

The consent object#

What every consent call returns in data.

FieldDescription
masterbooleanThe master marketing consent.
channelsobjectOne entry per channel, email, sms, push and viber.
channels.<channel>.statestringgranted or revoked. granted when the customer never set it.
channels.<channel>.effectivebooleanWhether the channel may be used for marketing now.
channels.<channel>.source, changed_atnullableWhere and when the channel was last changed. null when it never was.
preferredobjectThe channel the customer prefers to be reached on: notification_channel_id, and source, auto or manual.
viber_subscribedbooleanWhether the customer follows your Viber channel.
given_atdatetime · ISO 8601, UTCThe most recent consent change, or when the customer registered if nothing changed since.

Read and change consent#

PUT /api/v2/customer/consent

Three calls behind a consent screen. Each returns the whole consent object, so you can redraw the screen from the answer.

CallDescription
GET /customer/consentsThe customer's consent.
PUT /customer/consentSets one channel. Body: channel (email, sms, push or viber) and state (granted or revoked). Setting a channel to the state it already has changes nothing.
PUT /customer/consents/masterSets the master consent. Body: state, granted or revoked.

Errors

StatusWhen
401The token is not a signed-in customer's.
422API.CustomerChannelConsents.CustomerRequired: the session has no customer. API.CustomerChannelConsents.InvalidChannel or InvalidState: the value is not one of the allowed ones; fields names it.
PUT/customer/consent
curl -X PUT "https://api.morffeus.com/api/v2/customer/consent" \
  -H "Authorization: Bearer $SESSION_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{ "channel": "sms", "state": "revoked" }'
Response200 OK
{
  "data": {
    "master": true,
    "channels": {
      "email": {
        "state": "granted",
        "effective": true,
        "source": null,
        "changed_at": null
      },
      "sms": {
        "state": "revoked",
        "effective": false,
        "source": "mobile_app",
        "changed_at": "2026-10-01T10:02:11"
      },
      "push": { … },
      "viber": { … }
    },
    "preferred": { "notification_channel_id": null, "source": "auto" },
    "viber_subscribed": false,
    "given_at": "2026-10-01T10:02:11"
  }
}
Error422 Unprocessable Entity
{
  "errors": {
    "CustomerChannelConsents": ["API.CustomerChannelConsents.InvalidChannel"],
    "fields": { … }
  }
}

Register the device for push#

PUT /api/v2/notification_device

Tells us which push token reaches the signed-in customer on this device. Call it after sign-in and whenever the push provider gives your app a new token. The device is the one your app named when it started the session, and the customer is the session's.

Body parameters

ParameterDescription
notification_devicerequiredobjectThe device.
notification_device.messaging_tokenrequiredstringThe push token from Firebase Cloud Messaging.
notification_device.notification_channel_idrequiredintegerThe push channel: 3.
notification_device.device_type, device_vendor, mobile_infoOptional details about the device.

Sending the same push token again updates the device rather than adding one, and older copies of that token for the customer are removed.

Returns

data: the device as stored.

POST /api/v2/session/firebase/token with firebase_token stores the push token on the current session token instead. It answers 204, or 422 with API.Tokens.Firebase.UnableToUpdate.

PUT/notification_device
curl -X PUT "https://api.morffeus.com/api/v2/notification_device" \
  -H "Authorization: Bearer $SESSION_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "notification_device": {
      "messaging_token": "fcm-token-from-the-device",
      "notification_channel_id": 3
    }
  }'
Last updated 1 October 2026 · API v2 Something wrong on this page?