Chat on WhatsApp

Developers

Consent SDK, API, and webhooks

Install the browser SDK on a verified site, then use API keys and signed webhooks when your own systems need the same consent state.

Consent that lives only in the browser will not reach your backend

The banner can block a tag and still leave your server, app, or data warehouse unaware of the choice. Developer consent management means the same decision is available to those systems.

Consent Guru splits the public SDK, which runs on the customer’s website, from authenticated APIs used by your backend.

How a technical integration starts

  1. Step 1

    Register the site

    Add the website and verify the domain. A site key is meant for the host it was registered for.

  2. Step 2

    Publish

    The SDK configuration is served after a policy version is published. Until then, config requests do not describe a live banner.

  3. Step 3

    Install

    The embed runs a blocking bootstrap and loads the SDK so optional scripts can wait on the choice.

  4. Step 4

    Subscribe

    Point a webhook at your endpoint if you need server-side notice of consent or rights events.

Key capabilities

Consent SDK

A browser script that renders the published banner and preference center and applies the recorded choice.

Consent API

API keys authenticate server-side access. Browser collection uses separate public SDK routes.

Consent webhooks

Deliveries are signed with HMAC SHA-256 so your endpoint can reject unsigned bodies.

Workspace docs

Installation snippets, keys, and webhook setup live in the signed-in developer area after you create a workspace.

What teams use it for

  • A published policy as the runtime source of truth.
  • Domain checks that resist using a site key on the wrong host.
  • Signed events for systems you control.
  • A receipt and proof path for a recorded decision.

Marketing sites

Install the SDK and keep tags behind the published purposes.

Product backends

Read or record consent with an API key instead of scraping the banner.

Data pipelines

Consume webhooks when a choice changes, and verify the signature.

Privacy considerations

Public SDK endpoints are intentionally callable from browsers on allowed origins. Do not treat a site key as a secret that grants dashboard access.

API routes under /api are application endpoints. They are not marketing pages and are blocked for indexing.

Technical capabilities

Early blocking

The bootstrap can pause known optional script URLs. It cannot undo requests that already left the browser.

IAB signals

Where you enable them, the SDK can participate in IAB TCF and Global Privacy Platform style signaling alongside your purpose model.

Questions

1.What is a consent SDK?

It is the script you install on a website so the published banner, preference center, and enforcement rules run in the visitor’s browser.

2.Where is the API documented?

Start with the consent API overview, then open the developer area inside a workspace for keys and endpoint setup.

3.Are webhooks required?

No. The SDK can run without a webhook. Add one when a system outside the browser must hear about a new or updated choice.

Related pages

This page describes how Consent Guru supports privacy operations. It is not legal advice, and using the product does not by itself make an organization compliant with GDPR, CCPA, CPRA, the DPDP Act, or any other law.