Skip to main content
PATCH

Authorizations

Authorization
string
header
required

An API token (pv_ut_…) as Authorization: Bearer pv_ut_…. X-Peeve-Key is accepted too. Never a query parameter — URLs end up in proxy logs and Referer headers.

The token carries its owner's live workspace role, re-read on every call.

Path Parameters

id
string<uuid>
required

Peeve's id for the contact — the id field on a contact object, a UUID. The code calls it the end-user id.

This is not your own external_user_id. Passing one returns 400 invalid_id. To go from your id to this one, look the contact up first: GET /v1/contacts?external_user_id=user_8412 and read data[0].id.

Body

application/json
vendor_token
string | null

The token to store, encrypted at rest. null revokes.

Response

The resulting vendor-token state. Never the token itself.

object
string
required

The resource type, e.g. lead.

data
object
required
request_id
string
required

Echoed in the X-Request-Id header. Quote it to support.