curl --request GET \
--url https://your-instance.example.com/api/sessions/{session}/client-rules \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://your-instance.example.com/api/sessions/{session}/client-rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://your-instance.example.com/api/sessions/{session}/client-rules"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://your-instance.example.com/api/sessions/{session}/client-rules"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-instance.example.com/api/sessions/{session}/client-rules",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"allowedActions": "send_message,send_reaction,send_typing",
"allowedOrigins": "https://myapp.com,https://staging.myapp.com",
"enabled": true,
"maxDaily": 100,
"rateLimit": 5,
"recipientMode": "conversation"
}{
"error": "missing or invalid API key"
}{
"docs": "https://docs.polymorfa.com/api/sessions",
"error": "session not found"
}{
"docs": "<string>",
"error": "<string>"
}Get client rules
Returns the client token rules configured for a session.
curl --request GET \
--url https://your-instance.example.com/api/sessions/{session}/client-rules \
--header 'Authorization: Bearer <token>'const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://your-instance.example.com/api/sessions/{session}/client-rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://your-instance.example.com/api/sessions/{session}/client-rules"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://your-instance.example.com/api/sessions/{session}/client-rules"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-instance.example.com/api/sessions/{session}/client-rules",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"allowedActions": "send_message,send_reaction,send_typing",
"allowedOrigins": "https://myapp.com,https://staging.myapp.com",
"enabled": true,
"maxDaily": 100,
"rateLimit": 5,
"recipientMode": "conversation"
}{
"error": "missing or invalid API key"
}{
"docs": "https://docs.polymorfa.com/api/sessions",
"error": "session not found"
}{
"docs": "<string>",
"error": "<string>"
}Authorizations
Scoped API key created via POST /api/account/keys.
Path Parameters
Session name
Response
OK
AllowedActions is a comma-separated list of actions client tokens can perform. e.g. "send_message,send_reaction,send_typing,send_seen,read_presence"
"send_message,send_reaction,send_typing"
AllowedOrigins is a comma-separated list of origins for CORS enforcement.
"https://myapp.com,https://staging.myapp.com"
Enabled controls whether client tokens are accepted for this session.
true
MaxDaily is the max messages per day per ephemeral session.
100
RateLimit is the max requests per minute per ephemeral session.
5
RecipientMode controls who client tokens can message. "conversation" = only reply to JIDs that messaged first. "any" = no restriction. "verified" = only message verified JIDs (future). "none" = read-only, no sending.
"conversation"