Developer quickstart
Check rights before generation.
Send a Rights ID and what you intend to do, and get back one decision based on the scopes the rights holder set. A decision is not a licence. The licence is agreed with the rights holder separately.
Three steps to your first decision
- 01
Get a sandbox key
Sign up as a developer and the console issues a sandbox key right away. It starts with brk_test_, and sandbox calls are not billed. Keep the key in a server environment variable, never in browser code.
.env.local RIGHTIS_SECRET_KEY=brk_test_… - 02
Make one request
Send the Rights ID, the intended use (use_type) and the assets you want to use (asset_types). The sandbox uses made-up sample people instead of real ones. Their Rights IDs are in the list you fetch with the same key.
Sample people curl https://rightis.org/api/v1/sandbox/people \ -H "Authorization: Bearer $RIGHTIS_SECRET_KEY"Rights check request curl -X POST https://rightis.org/api/v1/rights/check \ -H "Authorization: Bearer $RIGHTIS_SECRET_KEY" \ -H "Content-Type: application/json" \ -d '{ "rights_id": "BR-SANDBOX-…", "use_type": "instagram ad", "asset_types": ["face"] }' - 03
Read decision and next_action
decision is one answer for the use you asked about. When the use touches several scopes, the most restrictive one wins. next_action tells you what to do next.
Example response { "rights_id": "BR-SANDBOX-…", "registered": true, "decision": "allowed", "scopes": [ { "scope": "social_media_ad", "state": "allowed" } ], "unmapped": [], "next_action": { "type": "request_license", "url": "https://rightis.org/…", "auto_approves": true } }
How to read decision
- allowed
- The rights holder pre-authorised these scopes. It does not mean free use. It means a licence request can be approved without the holder reviewing it, which is why next_action is request_license here too.
- requires_approval
- The rights holder decides. You also get this when some of your words did not map to a scope. next_action is request_license.
- unspecified
- The rights holder has never said anything about this use. Do not read it as allowed. next_action is request_license.
- denied
- The rights holder refuses at least one scope this use touches. next_action is stop. Do not generate.
A Rights ID that is not in the registry comes back without a decision and with next_action not_registered. Not registered is not permission.
Try it before you sign up
The public endpoint needs no key and answers the same way. It only knows real people listed in the public registry. The sandbox sample people are not found there.
curl -X POST https://rightis.org/api/public/v1/rights/resolve \
-H "Content-Type: application/json" \
-d '{
"rights_id": "BR-XV7E-8X7Z-ERB7",
"use_type": "instagram ad",
"asset_types": ["face"]
}'CLI and SDK
The CLI takes you from a key to your first check in a few terminal lines, and the SDK makes that check in three lines of code. Both are published on npm, with the source on GitHub.
npx rightis login
npx rightis init
npx rightis people
npx rightis check BR-SANDBOX-ALLW --use "social media ad" --asset facenpm install @rightis/sdk
import { Rightis } from '@rightis/sdk';
const rightis = new Rightis(); // RIGHTIS_SECRET_KEY 를 읽는다
const result = await rightis.rights.check({ rights_id: 'BR-SANDBOX-ALLW', use_type: 'social media ad', asset_types: ['face'] });
console.log(result.decision, result.next_action.type);Building a feature with real people in it
For avatars, face swap, voice clone, celebrity chatbots and anything else that uses a real person's face or voice: what to check and what to do with each decision. The relevant laws are listed with in-force and bill status kept apart.
Before writing code, you can look a person up by name or Rights ID with the Rightis app in ChatGPT. Try a lookup in ChatGPT
Add it to your AI coding tool
The GitHub repository holds rule files that tell coding tools such as Claude Code and Cursor to add a Rightis check when they build a generation feature. Tools do not fetch these files from the repository on their own. Copy the file into your project to use it.