# investigator.consent.update

Allow or stop the investigator searching the caller's own connected inbox (inboxAllowed), with idempotencyKey and optional expectedRevision. Only ever changes the caller's own consent.

`POST /api/v1/accounting/investigator.consent.update`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance, contributor · Idempotency key required · Send `expectedRevision`

MCP tool: `accounting_investigator_consent_update`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `inboxAllowed` | boolean | Yes |  |
| `expectedRevision` | integer |  | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. 0 to 9007199254740991. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/investigator.consent.update \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "inboxAllowed": true
}'
```

Reference page: https://app.getoatmilk.com/docs/api/investigator.consent.update
