Skip to main content

Allow PII access scoping on API tokens for DFY use cases

By default the API returns contacts anonymized, with PII (name, email, phone) excluded unless the token holds a specific reviews.pii ability.

For a DFY agencies who legitimately manages the client's own contacts, this means they can't match API results back to the real people my client is asking about. I had to fall back on a manual CSV export to identify contacts.

Request: make reviews.pii cleanly grantable on white-label/agency tokens (with appropriate consent and audit), so DFY operators can run contact-level verification programmatically without exporting CSVs.

1 comment

Log in to comment and vote

Comments1

  • Daniel Fawcett

    •

    Jun 8

    Seems like an obvious addition 👍