> ## Documentation Index
> Fetch the complete documentation index at: https://docs.chamelio.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Clickwrap

> Retrieve the active clickwrap content for a slug

## Endpoint

```
GET /v2/server/clickwrap/{slug}
```

## Authentication

This endpoint requires an OAuth access token. Send it as a bearer token:

```bash theme={null}
Authorization: Bearer your_access_token
```

**Required scope:** `clickwrap:read`

<Info>
  Clickwrap is the one `/v2` surface with no acting user. The subject of a clickwrap event is
  `user_identifier`, an opaque string you supply for your own end user, which is never resolved
  against Chamelio's users. These endpoints are authorized by organization and scope alone, so
  `client_credentials` tokens work here without restriction.
</Info>

## Path Parameters

| Parameter | Type   | Required | Description                         |
| --------- | ------ | -------- | ----------------------------------- |
| `slug`    | string | Yes      | Unique identifier for the clickwrap |

## Request Example

<CodeGroup>
  ```bash cURL theme={null}
  curl -X GET "https://platform.chamelio.ai/v2/server/clickwrap/privacy-policy" \
    -H "Authorization: Bearer your_access_token"
  ```

  ```python Python theme={null}
  import requests

  slug = "privacy-policy"

  url = f"https://platform.chamelio.ai/v2/server/clickwrap/{slug}"
  headers = {
      "Authorization": "Bearer your_access_token"
  }

  response = requests.get(url, headers=headers)
  print(response.json())
  ```

  ```javascript JavaScript theme={null}
  const slug = "privacy-policy";

  const response = await fetch(
    `https://platform.chamelio.ai/v2/server/clickwrap/${slug}`,
    {
      method: 'GET',
      headers: {
        'Authorization': 'Bearer your_access_token'
      }
    }
  );

  const data = await response.json();
  console.log(data);
  ```
</CodeGroup>

## Response

### Success Response

**Status Code:** `200 OK`

```json theme={null}
{
  "slug": "privacy-policy",
  "title": "Privacy Policy",
  "clickwrap_type": "click_to_accept",
  "content": "By clicking Accept, you agree to our Privacy Policy...",
  "content_html": "<p>By clicking Accept, you agree to our Privacy Policy...</p>",
  "clickwrap_version_id": 42,
  "version_number": 3
}
```

### Response Fields

| Field                  | Type           | Description                                                 |
| ---------------------- | -------------- | ----------------------------------------------------------- |
| `slug`                 | string         | Unique clickwrap identifier                                 |
| `title`                | string         | Human-readable title of the clickwrap                       |
| `clickwrap_type`       | string         | Presentation type: `click_to_accept` or `scroll_and_accept` |
| `content`              | string         | Plain-text content of the active version                    |
| `content_html`         | string or null | Sanitized HTML content of the active version                |
| `clickwrap_version_id` | integer        | Internal identifier for the active version                  |
| `version_number`       | integer        | Sequential version number of the active version             |

## Error Responses

### 401 Unauthorized

Returned when the access token is missing, unknown, revoked, or expired, or when an `X-API-Key` was
sent instead of a bearer token. See [OAuth error responses](/api-reference/oauth-apps#error-responses).

```json theme={null}
{
  "detail": "Invalid access token"
}
```

### 403 Forbidden

Returned when the token does not carry the required scope.

```json theme={null}
{
  "detail": "Insufficient scope; this endpoint requires: clickwrap:read"
}
```

### 404 Not Found

Returned when no active clickwrap exists for the given slug.

```json theme={null}
{
  "detail": "Not found"
}
```

### 429 Too Many Requests

Returned when your organization exceeds its per-minute request limit.

```json theme={null}
{
  "detail": "Rate limit exceeded"
}
```

### 500 Internal Server Error

Returned when the request fails due to a server error.

```json theme={null}
{
  "detail": "Failed to fetch clickwrap"
}
```

## Notes

<Info>
  This endpoint only returns the **active** (published) version. Draft versions are never exposed on
  externally authenticated endpoints.
</Info>

<Info>
  The result is organization-global. Every token issued for the same organization gets the same
  answer - the token's user is used only to authenticate and scope-check the request.
</Info>

<Tip>
  Use the `clickwrap_version_id` returned here when calling [Check Clickwrap Status](/api-reference/endpoint/v2/clickwrap/status) or [Capture Clickwrap Event](/api-reference/endpoint/v2/clickwrap/capture) to correlate acceptances with specific versions.
</Tip>

## Use Cases

This endpoint is useful for:

* **Headless consent flows** - Fetch clickwrap content server-side and render it in your own UI before capturing acceptance
* **Version awareness** - Read the current `version_number` to decide whether a returning user needs to re-accept
* **Content display** - Render `content_html` in embedded forms or modal dialogs
