GRANSKA

Read the upload agreement

GEThttps://api.granska.cloud/v1/legal-agreement

Reads the upload agreement every uploaded document is submitted under: its current version, where it is read, and whether your organisation has accepted it. Read only: an administrator accepts it for the organisation in the GRANSKA app.

Bearer tokenSpends no quota

Two things before a document is accepted

Every document you send for analysis is submitted under one agreement: the GRANSKA Terms of Service at agreementUrl. Once the agreement is enforced, a document is accepted only when both of these hold:

  1. Your organisation has accepted the current version. A real administrator of your organisation does that, signed in to the GRANSKA app, where they read the agreement and confirm that they may bind the organisation. No API call can accept it, and an API key or an agent connection never accepts on anyone's behalf: it relies on the acceptance its administrator gave.
  2. Each request confirms its own document. uploadAttestation on POST /v1/upload-url, or on POST /v1/analyze for an inline or fetched document, is { "agreementVersion": "<agreementVersion>", "uploadAuthorised": true }. Send it only once the person or system you act for has confirmed that they may submit that document. uploadAuthorised: false is refused, never read as absent.

This call answers both questions before you upload anything. It spends nothing and changes nothing.

Reading the answer

agreementVersion is the version uploadAttestation must name. When it changes, a confirmation of the earlier version is refused with 409 STALE_AGREEMENT_VERSION: read the agreement again and confirm the new version.

organisationRequired and organisationAccepted say whether your organisation must accept, and whether it has accepted the current version. When the first is true and the second false, ask an administrator of your organisation to accept it in the app; until then every upload is answered 409 LEGAL_AGREEMENT_REQUIRED, whose details.missing names ORGANISATION_ACCEPTANCE.

mode is OFF before the agreement is collected, COLLECT while acceptances are being gathered and nothing is refused for a missing one, and ENFORCE once it is required. userAccepted and canAcceptOrganisation describe a person signed in with their own account; for an API key or an agent connection both are always false, because neither has an acceptance of its own.

Request
curl https://api.granska.cloud/v1/legal-agreement \
  -H "Authorization: Bearer $TOKEN"
Response
{
  "agreementVersion": "legal:2",
  "agreementUrl": "https://www.granska.cloud/legal",
  "mode": "ENFORCE",
  "userAccepted": false,
  "organisationRequired": true,
  "organisationAccepted": true,
  "canAcceptOrganisation": false
}

Errors

ErrorWhen
401
UNAUTHORIZED
The Authorization header is missing, is not a readable bearer token, or names no tenant.
401
TOKEN_EXPIRED
The access token was issued by this gateway and has since expired. Not probed: it needs a token older than its own lifetime.
500
INTERNAL_ERROR
An unexpected server-side failure. Not probable from outside — reaching it means something is wrong.
503
SERVICE_UNAVAILABLE
The agreement could not be checked; details.reason is AGREEMENT_UNAVAILABLE and a Retry-After header says when to try again. Not probed: it needs an injected infrastructure failure.