Chat on WhatsApp

API

A consent API for your own systems

Use API keys when a backend needs to record or read consent, and use signed webhooks when you want events pushed to you.

The browser SDK is not your server API

Public collection endpoints exist so the SDK can store a banner choice from the visitor’s browser. Server-to-server access is a different trust boundary and uses API keys.

Putting marketing content on /api would collide with those endpoints, so this overview lives at /consent-api. The live API stays under /api and is not indexed.

How developers use it

  1. Step 1

    Create a key

    Keys are issued inside the workspace and shown once. Store them in your secret manager.

  2. Step 2

    Call with the key

    Authenticated routes reject requests that have no session and no machine credential.

  3. Step 3

    Receive events

    Webhooks POST consent and rights events to an HTTPS endpoint you control.

  4. Step 4

    Verify

    Check the HMAC SHA-256 signature before you trust the body. Signing secrets are stored encrypted with AES-256-GCM.

Key capabilities

Consent records over the API

Record and look up decisions with the identifier, purposes, and policy context your integration needs.

Consent webhooks

Your endpoint gets the event. You decide what to update in a CRM, warehouse, or app profile.

Receipts

Evidence export can include cryptographic proof of the recorded decision and notice snapshot.

Rights events

Rights-request changes can be delivered on the same webhook channel when you subscribe to them.

What teams use it for

  • Backend consent state without scraping cookies.
  • A signature check on inbound events.
  • Keys that are separate from dashboard passwords.
  • A clear split between public SDK routes and private APIs.

Account portals

Show the same purposes in a logged-in settings page and write the choice back through the API.

Warehouses

Store webhook payloads you have verified, not unsigned copies.

Mobile or server rendering

Collect a choice in your app and record it server-side when the browser SDK is not the right surface.

Privacy considerations

Do not embed API keys in public websites. The browser should use the site key and SDK.

Rate limits and organization roles still apply. A key is not a bypass of retention or legal holds.

Questions

1.What is a consent management API?

It is the authenticated interface for recording and reading consent, and for configuring the events your systems receive.

2.How are consent webhooks signed?

Deliveries include an HMAC SHA-256 signature computed with the webhook signing secret. Reject requests that do not match.

3.Why isn’t this page at /api?

The /api path is the application’s endpoint namespace, including the public SDK. Indexing or replacing it would break the product.

Related pages

This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.