Consent records over the API
Record and look up decisions with the identifier, purposes, and policy context your integration needs.
API
Use API keys when a backend needs to record or read consent, and use signed webhooks when you want events pushed to you.
Public collection endpoints exist so the SDK can store a banner choice from the visitor’s browser. Server-to-server access is a different trust boundary and uses API keys.
Putting marketing content on /api would collide with those endpoints, so this overview lives at /consent-api. The live API stays under /api and is not indexed.
Step 1
Keys are issued inside the workspace and shown once. Store them in your secret manager.
Step 2
Authenticated routes reject requests that have no session and no machine credential.
Step 3
Webhooks POST consent and rights events to an HTTPS endpoint you control.
Step 4
Check the HMAC SHA-256 signature before you trust the body. Signing secrets are stored encrypted with AES-256-GCM.
Record and look up decisions with the identifier, purposes, and policy context your integration needs.
Your endpoint gets the event. You decide what to update in a CRM, warehouse, or app profile.
Evidence export can include cryptographic proof of the recorded decision and notice snapshot.
Rights-request changes can be delivered on the same webhook channel when you subscribe to them.
Show the same purposes in a logged-in settings page and write the choice back through the API.
Store webhook payloads you have verified, not unsigned copies.
Collect a choice in your app and record it server-side when the browser SDK is not the right surface.
Do not embed API keys in public websites. The browser should use the site key and SDK.
Rate limits and organization roles still apply. A key is not a bypass of retention or legal holds.
It is the authenticated interface for recording and reading consent, and for configuring the events your systems receive.
Deliveries include an HMAC SHA-256 signature computed with the webhook signing secret. Reject requests that do not match.
The /api path is the application’s endpoint namespace, including the public SDK. Indexing or replacing it would break the product.
This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.