v3

latestOpenAPI 3.0.32026-08-05363479.3 KB

Record an NHS-observed handoff and reveal the provider action URL

Presents the raw ticket bearer and the separate exact nhs-provider-handoff-consent-v1 principal attestation only in a bounded JSON body, never in the NHS URL or query string; every response is private, no-store. NHS atomically records one append-only privacy-safe nhs-action-handoff-v1 receipt bound to the exact ticket, offer version, commercial-terms hash, and handoff-consent version before returning the attributed provider action URL. The principal may separately and optionally authorize the exact DNS-verified provider to resolve only the bounded controlled-intent bundle under nhs-provider-controlled-intent-disclosure-consent-v1; declining that disclosure does not block this handoff or free direct provider access. The receipt contains no query, agent or principal identity, contact data, network address, referrer, or user agent. This handoff and the optional resolver charge neither party; only the configured authenticated provider-reported downstream outcome can create the disclosed provider charge. Exact wording is at https://nothumansearch.ai/privacy#handoff-consent-v1 and https://nothumansearch.ai/privacy#controlled-intent-disclosure-consent-v1.

post/action-tickets/handoff

Request body

ticket_idstring uuid required
attribution_tokenstring required
principal_handoff_consenttrue required

Caller attests the exact published handoff-time principal authorization

handoff_consent_version'nhs-provider-handoff-consent-v1' required
principal_controlled_intent_disclosure_consentboolean

Optional separate authorization for the exact DNS-verified provider to resolve the bounded controlled-intent bundle after this observed handoff

controlled_intent_disclosure_consent_version'nhs-provider-controlled-intent-disclosure-consent-v1'

Required only when principal_controlled_intent_disclosure_consent is true; otherwise omit

Response

Exact replay of the existing durable handoff receipt and provider URL; neither party charged

action_urlstring uri required

Attributed HTTPS provider URL returned only after the durable receipt commits

observed_handofftrue required
idempotent_replayboolean required
principal_chargedfalse required
provider_chargedfalse required
organic_rank_affectedfalse required
direct_provider_access_is_freetrue required