v3

latestOpenAPI 3.0.32026-08-05363479.3 KB

Prepare an authorization-attested action for a disclosed paid offer

Requires a committed organic search receipt and exact principal-consent v1 attestation. Accepts controlled constraints only; no name, email, contact detail, raw prompt, agent identity, or principal identity. Returns the raw ticket bearer and POST handoff endpoint, not the provider action URL. Creating a ticket charges neither party. See https://nothumansearch.ai/privacy#consent-v1.

post/action-tickets

Request body

offer_idstring uuid required
search_idstring required

Committed query-free organic search receipt

demand_topic'payments' | 'commerce' | 'jobs' | 'data' | 'search' | 'weather' | 'maps' | 'email' | 'messaging' | 'image' | 'video' | 'audio' | 'documents' | 'security' | 'finance' | 'health' | 'education' | 'news' | 'analytics' | 'automation' | 'productivity' | 'identity' | 'storage' | 'ai-tools' | 'developer-tools' | 'other' required
region_codestring
budget_band'unspecified' | 'under_100' | '100_499' | '500_1999' | '2000_plus'
urgency'unspecified' | 'now' | '7_days' | '30_days' | 'researching'
requirement_flagsstring[]
principal_consenttrue required

Caller attests it is authorized by the principal under the exact published v1 wording

consent_version'nhs-principal-consent-v1' required

Response

Exact replay with the attribution bearer reconstructed from the persisted ticket snapshot

preparation_contract_version'nhs-action-ticket-preparation-v2' required

Explicit breaking contract revision that withholds the provider URL until separately consented handoff

attribution_tokenstring required

Raw bearer returned in the no-store response. The raw string is not stored in ticket or handoff rows; NHS stores its SHA-256 hash and retains nonce/key metadata plus signing material that can reconstruct an exact replay.

handoff_endpointstring uri required
handoff_method'POST' required
handoff_event_contract_version'nhs-action-handoff-v1' required
handoff_consent_contract_urlstring uri required
controlled_intent_disclosure_optionaltrue required

The optional separate disclosure may be declined without blocking handoff or free direct provider access

controlled_intent_disclosure_consent_version'nhs-provider-controlled-intent-disclosure-consent-v1' required
controlled_intent_disclosure_consent_urlstring uri required
createdboolean required
idempotent_replayboolean required
attribution_token_stored_by_nhsfalse required
token_reconstructed_for_exact_replayboolean required
principal_consent_attestedtrue required
consent_contract_urlstring uri required
principal_chargedfalse required
provider_mor_contract_requiredtrue required
principal_charged_by_nhsfalse required
organic_rank_affectedfalse required
direct_provider_access_remains_freetrue required
disclosurestring required