Creates or updates a ban record for the visitor and also marks the visitor metadata as blocked. `reason` is optional. If a ban already exists for the visitor, the route updates the existing record instead of creating a duplicate. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `visitors:write` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Banning prevents the visitor from starting or continuing normal support interactions for the authenticated organization. Repeating the same ban updates or preserves the active ban according to the documented response. Retry behavior: Repeating the same request converges on the same resource state, but a retry may return a conflict or not-found response after the first request succeeds.
/api/visitors/{id}/banOrganization API key supplied as Authorization: Bearer convor_sk_....
In: header
application/json
TypeScript Definitions
Use the request body type in TypeScript.
application/json
curl --request POST \
'https://api.convor.io/api/visitors/550e8400-e29b-41d4-a716-446655440000/ban' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer convor_sk_...' \
--header 'Content-Type: application/json' \
--data '{
"reason": "Repeated spam submissions"
}'const response = await fetch("https://api.convor.io/api/visitors/550e8400-e29b-41d4-a716-446655440000/ban", {
method: "POST",
headers: {
"Accept": "application/json",
"Authorization": "Bearer convor_sk_...",
"Content-Type": "application/json"
},
body: JSON.stringify({
"reason": "Repeated spam submissions"
}),
});
const contentType = response.headers.get("content-type") ?? "";
const data = response.status === 204
? null
: contentType.includes("json")
? await response.json()
: contentType.startsWith("text/")
? await response.text()
: await response.blob();
if (!response.ok) {
const message = typeof data === "object" && data !== null
&& "error" in data && typeof data.error === "object"
&& data.error !== null && "message" in data.error
? String(data.error.message)
: "Convor API request failed (" + response.status + ")";
throw new Error(message);
}
console.log(data);Was this page helpful?
Apply an action to multiple visitors
Adds or removes a tag, or blocks or unblocks up to 100 visitors from the current organization in one transactional operation. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `visitors:write` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. The request validates every supplied visitor against the authenticated organization before applying the selected action. Inspect the returned counts or per-item results before retrying a partially observed request. Retry behavior: This operation is not idempotent. After an ambiguous timeout, read the resource state before retrying to avoid duplicate work, messages, files, bookings, exports, or events.
Block visitor
Marks the visitor as blocked in metadata and also creates an organization-scoped visitor ban record. User-backed operators are recorded as the actor; organization API-key bans use a null user actor. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `visitors:write` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Blocking is organization-scoped and affects the visitor record identified by the path; it does not disclose or modify similarly identified visitors in other organizations. Retry behavior: Repeating the same request converges on the same resource state, but a retry may return a conflict or not-found response after the first request succeeds.
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
{
"success": true,
"ban": {
"id": "660e8400-e29b-41d4-a716-446655440000",
"orgId": "770e8400-e29b-41d4-a716-446655440000",
"visitorId": "550e8400-e29b-41d4-a716-446655440000",
"reason": "Repeated spam submissions",
"bannedBy": "880e8400-e29b-41d4-a716-446655440000",
"createdAt": "2026-06-23T08:00:00.000Z"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}