Skip to main content
GET
Get a contact

Authorizations

Authorization
string
header
default:Bearer brew_your_api_key
required

Send your Brew API key as Authorization: Bearer brew_xxx.

Headers

X-Brand-Id
string

The brand this request acts on. REQUIRED for organization-scoped credentials (otherwise 400 BRAND_ID_REQUIRED — there is no default brand); list ids with GET /v1/brands. Brand-scoped credentials may omit it, and sending a different brand returns 403 BRAND_SCOPE_MISMATCH. A brand outside your organization returns 404 BRAND_NOT_FOUND.

Required string length: 1 - 64

Path Parameters

email
string
required

The contact’s email address (URL-encoded). Email is the contact primary key.

Required string length: 1 - 320
Example:

"jane%40example.com"

Query Parameters

include
string

Expansions: openProfile attaches the contact's smart-send open-time profile (needs the emails permission as well).

Response

The contact row, with openProfile when include=openProfile.

email
string
required
createdAt
string<date-time>
required
updatedAt
string<date-time>
required
firstName
string
lastName
string
subscribed
boolean
default:true
validationStatus
enum<string>

The latest verdict. valid only ever comes from a deliverability check (validate: true on ingest, or POST /v1/contacts/validate), which also sets lastValidatedAt. Without a check the free format check on ingest stores risky (disposable or role address) or invalid, and leaves the field unset otherwise: not validated.

Available options:
valid,
risky,
invalid
suppressed
boolean
default:false
suppressedReason
string | null
unsubscribedDomains
string[]
lastValidatedAt
string<date-time>
validationDetails
object
importId
string | null
csvFileName
string | null
customFields
object
openProfile
object | null

With include openProfile: the contact's smart-send open-time profile (48 UTC half-hour open counts and the best send time derived from them), or null when they have no opens folded yet. Not bot detection: machine opens cannot be told apart here.