Skip to main content

Brand Identity API

Brand Identity endpoints exposed by the Devotel CPaaS API Base path: /api/v1/brand-identity Endpoint count: 7

title: “Read the consolidated trust posture” description: “One brand-verification answer across 10DLC, toll-free, WhatsApp, RCS, branded calling, and number regulatory KYC — with a single trust score and the next actions to raise it.”

Read the consolidated trust posture

Brand verification is siloed per channel: 10DLC and toll-free live in messaging compliance, WhatsApp in channel settings, RCS in sender registration, branded calling in voice trust, and number KYC in regulatory records. This endpoint is for the operations or compliance owner who needs one answer to “what blocks our deliverability today,” and for dashboards that render a single trust hub instead of six channel pages. Every source read is fail-soft — one degraded subsystem never blanks the whole hub. The response carries three blocks. summary rolls the channels into counters plus a 0-100 trustScore (= verified channels / applicable channels) and an overallState. channels lists every trust surface with its state (not_started | in_progress | verified | action_required | unavailable), a short tenant-readable detail (“2 of 3 numbers verified”), the provider’s reason when action is required, and a manageHref the dashboard deep-links for that surface. nextActions prioritizes what to fix first, each entry pointing at the dashboard path for that channel (priority is urgent or todo). One GET poll is enough — the Node SDK has no typed helper here either, so the generic request() escape hatch keeps the envelope identical. Request
A channel with state: "unavailable" is excluded from the trustScore denominator (the feature is not hooked up in your account), so the score stays honest either way.

List brand-impersonation takedown cases

GET /api/v1/brand-identity/impersonation/cases
Lists the tenant’s takedown cases (newest first), optionally filtered to a single lifecycle status.
string (enum: open|evidence_ready|reported|resolved|dismissed)
—
string (enum: true|false)
Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.

Read the tenant’s brand-impersonation protected-asset watchlist

GET /api/v1/brand-identity/impersonation/watchlist
Returns the brand names, domains, and sender IDs the tenant has registered as ITS OWN assets to protect against impersonation. A never-configured tenant resolves to empty lists.
string (enum: true|false)
Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.

Unified cross-channel brand trust posture

GET /api/v1/brand-identity/status
Returns one consolidated brand-identity verification posture across every trust channel (10DLC, toll-free, WhatsApp, RCS, branded calling, number regulatory KYC), rolled up into a single trust score + prioritized next-action list. Every source read is fail-soft — one degraded subsystem never blanks the hub.
string (enum: true|false)
Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.

Open a brand-impersonation takedown case

POST /api/v1/brand-identity/impersonation/cases
Scores a candidate against the tenant’s brand watchlist, assembles a filing-ready takedown evidence pack (matched brand token, findings, a recommended abuse-desk recipient class, and a ready-to-send notice summary), and opens a case tracked through its lifecycle (open → evidence_ready → reported → resolved, or dismissed at any point). This ASSEMBLES the evidence pack only — actual submission to a registrar / carrier / platform abuse desk is a tenant/operator action; nothing is transmitted automatically and invariant #45 is untouched.
string
Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.
string (enum: true|false)
Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.

Scan candidate senders/domains for brand impersonation

POST /api/v1/brand-identity/impersonation/scan
Scores each candidate (a lookalike shortlink domain, a spoofed SMS/RCS sender ID, or a spoofed display name) against the tenant’s brand watchlist using typosquat edit-distance, homoglyph/leetspeak normalization, combosquatting, abused-TLD, and smishing lure-keyword signals. Read-only + advisory — nothing persists and nothing is transmitted; invariant #45 is untouched. To open a takedown case for a scored candidate, POST it to /impersonation/cases.
string
Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.
string (enum: true|false)
Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.

Replace the tenant’s brand-impersonation protected-asset watchlist

PUT /api/v1/brand-identity/impersonation/watchlist
Replaces the tenant’s protected brand names, domains, and sender IDs used by the impersonation scanner and takedown-case engine to recognize the tenant’s OWN legitimate assets (so they are never flagged) and to fuzzy-match lookalike candidates against.
string
Stripe-style idempotency token. Pass a stable, client-generated value (1-255 chars) to dedupe retries on transient timeouts. The same key+credential+path replays the original response for 24h on 2xx (5min on 4xx, 30s on 5xx). Returns 409 if a concurrent request with the same key is already in flight; replayed responses include the Idempotency-Replay: true response header.
string (enum: true|false)
Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.

Advance or dismiss a brand-impersonation takedown case

PATCH /api/v1/brand-identity/impersonation/cases/{caseId}
Transitions a takedown case through its lifecycle (open → evidence_ready → reported → resolved), or dismisses it (from any active state) / reopens a dismissed case. Returns 404 for an unknown case id and 409 for a disallowed transition.
string
required
—
string (enum: true|false)
Sandbox opt-in for Clerk-session-authenticated requests. Set to true to route the call through the test-mode pipeline: no real provider delivery, no credits deducted, response meta.test_mode: true. Ignored for live API keys (dv_live_sk_*) — server-to-server clients must use a test-prefixed key (dv_test_sk_*) to exercise sandbox. Test-prefixed keys unconditionally enable sandbox regardless of this header.