Skip to main content
POST
Call contact.link

Authorizations

Authorization
string
header
required

An API key minted at Settings › API & MCP. Send it as Authorization: Bearer <key>. A key carries its holder's own permissions, resolved on every call — revoking a membership closes the key's reach immediately. Keep it in an environment variable (GOOSY_API_KEY), never in a committed file.

Headers

x-request-id
string

Your own id for this request, echoed back and recorded on the audit trail. 1–128 characters from A–Z a–z 0–9 . _ : -, starting with a letter or digit; anything else is replaced by a generated id.

Maximum string length: 128

Body

application/json
contact_id
string<uuid>
required

The customer this key belongs to. Read them with contact.get first — never a guess at who a key belongs to.

identity_kind
enum<string>
required

Which kind of key this is: an email address, a phone number, a Messenger id (meta_psid), an Instagram id (ig_id), a CRM record id (ghl_contact_id), or a Google reviewer id.

Available options:
email,
phone,
meta_psid,
ig_id,
ghl_contact_id,
gbp_reviewer
identity_value
string
required

The key exactly as you observed it. It is normalised before it is looked up, so capitals in an address are fine — but a phone number without its country code cannot be matched and will be refused rather than guessed at.

Required string length: 1 - 512
action
enum<string>
required

link attaches the key to that customer; unlink takes it off again. Both are recorded on their history.

Available options:
link,
unlink
identity_scope
string

The Meta PAGE id the key was seen on. REQUIRED for meta_psid and ig_id — those ids are only unique within one page, so without it nothing can be matched. Leave it out for every other kind.

Required string length: 1 - 256
confirmation_id
string<uuid>

Omit to propose: the first call says what would happen, returns a confirmation_id and changes nothing. To go ahead, send the same arguments again with that confirmation_id, on a member's own API key; a service account's key can propose but never confirm.

workspace
string

Which workspace to run in — its slug. Omit to use your default. With more than one reachable workspace and no default, the call is refused and the choices are listed.

Minimum string length: 1

Response

The call was admitted and dispatched. ok says whether the tool succeeded — a refusal the tool itself produced is still a 200, exactly as it is a successful JSON-RPC result over MCP.

The tool ran and answered.

ok
boolean
required
workspace
string
required

The slug of the workspace this call ran in.

working_in
object
required

Which workspace this call ran in, and how that was decided. Present on every workspace-scoped result.

state
string
Allowed value: "confirmation_required"
confirmation_id
string<uuid>
expires_in_seconds
integer
request_summary
string

What will happen, in one sentence, for a person to approve before confirming.

outcome
enum<string>
Available options:
proposed,
linked,
unlinked
contact_id
string
display_name
string | null
identity_kind
enum<string>
Available options:
email,
phone,
meta_psid,
ig_id,
ghl_contact_id,
gbp_reviewer
identity_masked
string
evidence
string
waiting_on
string | null
local_row_id
string | null