---
title: "codespar consents"
description: "Consent tokens: mint the token whose URL the consumer opens to authorise an agent"
---

Consent tokens: mint the token whose URL the consumer opens to authorise an agent

4 commands in `@codespar/cli 0.16.0`.

Each one prints what its operation answered. [What a command prints](/docs/cli/reference#what-a-command-prints) has the rule, and [Configuration](/docs/cli/config#what-a-script-gets-when-a-command-fails) has the exit codes and the shape of a failure.

### `codespar consents create`

Start a hosted consent

```bash
codespar consents create --input-file body.json
```

```json title="body.json"
{
  "agent_id": "agt_0000000000000000",
  "consumer_email_hint": "person@example.com",
  "intent": {
    "purpose": "string",
    "cap_minor": 1,
    "per_tx_cap_minor": 1,
    "currency": "BRL",
    "mandate_ttl_seconds": 0,
    "merchant_allowlist": [
      "*"
    ],
    "merchant_pin_kind": "pix-key",
    "withdrawal_allowlist": [
      "string"
    ],
    "dda_allowlist": [
      "string"
    ],
    "periodic_cap": {
      "window": "day",
      "cap_minor": 1
    },
    "slots": [
      {
        "currency": "BRL",
        "rail": "string",
        "cap_minor": 1,
        "per_tx_cap_minor": 1
      }
    ],
    "display_name": "Example",
    "intent_note": "string",
    "shipping": {}
  },
  "callback_url": "https://example.com/hook",
  "surface": "hosted"
}
```

| option | what it does |
|---|---|
| `-q, --query <key=value>` | Query parameter (repeatable) (default: []) |
| `--timeout <ms>` | Per-request timeout in milliseconds |
| `-i, --input <json>` | Request body as a JSON string |
| `-f, --input-file <path>` | Request body from a JSON file |

`POST /v1/consents` · [parameters, responses and refusals](/docs/api/reference/consents#post-v1consents)

### `codespar consents init`

Start a hosted consent

> **Deprecated route.** The served document marks this operation as dead. The command still answers today and will go; the HTTP reference below names what took its place.

```bash
codespar consents init --input-file body.json
```

```json title="body.json"
{
  "agent_id": "agt_0000000000000000",
  "consumer_email_hint": "person@example.com",
  "intent": {
    "purpose": "string",
    "cap_minor": 1,
    "per_tx_cap_minor": 1,
    "currency": "BRL",
    "mandate_ttl_seconds": 0,
    "merchant_allowlist": [
      "*"
    ],
    "merchant_pin_kind": "pix-key",
    "withdrawal_allowlist": [
      "string"
    ],
    "dda_allowlist": [
      "string"
    ],
    "periodic_cap": {
      "window": "day",
      "cap_minor": 1
    },
    "slots": [
      {
        "currency": "BRL",
        "rail": "string",
        "cap_minor": 1,
        "per_tx_cap_minor": 1
      }
    ],
    "display_name": "Example",
    "intent_note": "string",
    "shipping": {}
  },
  "callback_url": "https://example.com/hook",
  "surface": "hosted"
}
```

| option | what it does |
|---|---|
| `-q, --query <key=value>` | Query parameter (repeatable) (default: []) |
| `--timeout <ms>` | Per-request timeout in milliseconds |
| `-i, --input <json>` | Request body as a JSON string |
| `-f, --input-file <path>` | Request body from a JSON file |

`POST /v1/consents/init` · [parameters, responses and refusals](/docs/api/reference/consents#post-v1consentsinit)

### `codespar consents get`

Read a pending consent

```bash
codespar consents get string
```

| argument | what it is |
|---|---|
| `<token>` | String. |

| option | what it does |
|---|---|
| `-q, --query <key=value>` | Query parameter (repeatable) (default: []) |
| `--timeout <ms>` | Per-request timeout in milliseconds |

`GET /v1/consents/{token}` · [parameters, responses and refusals](/docs/api/reference/consents#get-v1consentstoken)

### `codespar consents submit`

Submit a consent and receive the signed mandate

```bash
codespar consents submit string --input-file body.json
```

```json title="body.json"
{
  "consumer_id": "csm_0000000000000000",
  "rail": "pix-consent",
  "provider_token": "string",
  "display_label": "Example",
  "attestation": {
    "method": "partner_session",
    "asserted_at": 0,
    "reference": "string",
    "evidence": {
      "channel": "whatsapp",
      "message_id": "message_0000000000000000",
      "session_id": "ses_0000000000000000",
      "provider_ts": 0,
      "ip": "string",
      "user_agent": "string",
      "device_id_hash": "string",
      "geo": {
        "country": "string",
        "region": "string",
        "city": "string"
      },
      "contact": "string"
    }
  }
}
```

| argument | what it is |
|---|---|
| `<token>` | String. |

| option | what it does |
|---|---|
| `-q, --query <key=value>` | Query parameter (repeatable) (default: []) |
| `--timeout <ms>` | Per-request timeout in milliseconds |
| `-i, --input <json>` | Request body as a JSON string |
| `-f, --input-file <path>` | Request body from a JSON file |

`POST /v1/consents/{token}/submit` · [parameters, responses and refusals](/docs/api/reference/consents#post-v1consentstokensubmit)
