Skip to main content
Members can be asked to accept the Expys terms of service inside your own app. Three calls: find out what they owe, fetch the text, record the acceptance.
These methods are available from 0.7.1. On earlier versions the endpoints work over raw HTTP but the SDKs carry no method for them.

Versions are immutable

Every published document is a version with its own id. A version is never edited: when the text changes, a new version is published and the old one stays exactly as it was. That is what makes an acceptance mean something. acceptedAt on its own tells you when someone tapped a button; an acceptance against a version tells you what they read. A member who accepted last year’s terms shows as outstanding against this year’s - which is the point.

What a member owes

GET /v1/terms is metadata only and safe to call on every launch. It does not return the document text, which is around 28kB.
string | null
required
When this member accepted this exact version. null means outstanding, including when they accepted an earlier version of the same document.

Fetching the text

The document names your organisation as counterparty, substituted in at render time. Because a version never changes and your organisation is fixed, this response is stable forever and is served with Cache-Control: immutable - fetch it once when the sheet opens, not on every launch. renderedHash is the sha256 of exactly the html returned, which is what we store against the acceptance.

Recording acceptance

The response is the same shape as GET /v1/terms, so you can render the outcome without a second call. Accepting a version already on file is a no-op, not an error.
Either credential works, and we record which. A member token means the member accepted in an app holding their own credential. An Org-API-Key with externalUserID means your server is asserting they accepted somewhere in your flow. Both are legitimate; they are not equally strong evidence, so we do not conflate them.We deliberately record no IP address. The caller is your backend or your app behind your infrastructure, so an IP would be yours or a proxy’s - evidentially worthless, and personal data neither of us needs to hold.

Requiring acceptance before redemption

Off by default. When Expys enables it for your organisation, POST /v1/redemptions refuses a member who has not accepted the current terms:
The error carries the version, so you can open the acceptance sheet straight from it without a second call to find out which document is missing. Nothing is created when this fires - no booking, no inventory held, no points debited. The member accepts and retries.
Only the terms of service gate a redemption. The privacy policy is listed and can be accepted, but never blocks a booking.

Errors