HeyGen avatar consent API: digital twin vs photo avatar

HeyGen asks for consent only for digital twins, via POST /v3/avatars/{group_id}/consent. The three levels, the 24-hour link, and what photo avatars skip.

5 min readSume
All posts

HeyGen asks for proof of consent only when you build a digital twin, and it collects it with POST /v3/avatars/{group_id}/consent. A photo avatar or a prompt avatar has no consent request and reports a consent_status of null. HeyGen adds that having no API step to complete is not permission to use someone's likeness.

HeyGen's flow is from its Avatar Consent and Photo to Avatar pages, read 2026-09-29. Sume's avatar inputs are from Create new avatar.

What are the three levels of consent access?

HeyGen offers three increasingly permissive flows, each unlocked for a narrower set of accounts.

Consent levels, from HeyGen's Avatar Consent page and the Sume avatar docs, read 2026-09-29.
LevelFlowWho can use it
1. Record via webcamThe subject records a short consent statement on HeyGen's hosted consent pageAll customers
2. Upload a consent videoYou supply a pre-recorded consent video with consent_videoEnterprise only
3. Skip the consent flowCollection is waived for accounts that signed an indemnity agreementEnterprise only, contact sales

How do I request consent through the API?

By default the endpoint starts the webcam flow and returns a url for the person being cloned. That link is valid for 24 hours; call the endpoint again for a fresh one. Send it to the subject, then read consent_status on the avatar group with GET /v3/avatars/{group_id} until it clears from pending.

curl -X POST "https://api.heygen.com/v3/avatars/group_xyz789/consent" \
  -H "X-Api-Key: $HEYGEN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "reroute_url": "https://example.com/consent-done" }'

What must an uploaded consent video contain?

For the enterprise upload path, the subject reads HeyGen's recommended statement clearly on camera. HeyGen validates it semantically, so small wording differences are fine, and the statement can be in any language. The face must match the training footage, one face must be clearly visible, and the audio must be audible. The status belongs to the avatar group, not to an individual look.

Where does consent sit in HeyGen's digital twin flow?

It is one step in the twin flow, after the group exists and before you generate video with it. HeyGen says you cannot generate video with a digital twin until the person depicted has agreed to be cloned. The webcam flow takes an optional reroute_url, the page the subject lands on once they finish, which defaults to HeyGen's own completion page. With an uploaded consent_video there is no hosted page, so the response contains the avatar group alone and no url.

What does a photo avatar skip, and what does Sume do?

HeyGen describes the photo route as needing no recording session and no consent step. Sume's avatar creation also takes a reference photo (a public HTTPS image URL), alongside a text prompt and structured traits, and the docs page checked describes no consent step. That leaves the permission question with you, which is HeyGen's own point too: if the image shows a real person, get their agreement first. See what an AI digital twin is for the difference between cloning someone and generating a new face.

Sources

Related posts

More in Sume Avatar 1.0

All Sume Avatar 1.0 posts

Written by Sume