v1

latestOpenAPI 3.1.0Apache 2.02026-07-245981,1853.0 MB
Consent Receipts

Create Consent Receipts

Use this API to create consent receipts from a collection point. This API is used by all collection points and allows external applications to submit requests to store data subject consent transactions.

🗒 Things to Know

  • Each collection point must first be set up in the OneTrust Platform to generate a valid JWT, which must be present in the request payload. The JWT can be found on the Integrations tab of the Collection point details screen within the platform or can be retrieved by calling the Get Collection Point Token API.

  • Once the test parameter is set to true, reverting it to false is not possible. However, transitioning from test=false to test=true is supported. For more information on how to remove the test flag in the OneTrust Platform, see Managing Data Subject Records.

  • In most cases, further authorization is not required. However, additional information for setting up authenticated consent can be found here when needed.

  • Please avoid passing privacy notices for regular Custom API collection points. OneTrust strongly recommends using privacyNotices only for those enabled with dynamic configuration, as they allow you to gather information about all purposes.

  • When passing the purposes parameter, the version for PrivacyNotices will be used based on the consent date.

  • OneTrust recommends including no more than 10 purposes per consent receipt, with an absolute maximum of 20 purposes.

  • Please validate all inputs before sending data to a Custom API collection point. This API does not perform data type validation to ensure high performance and fast response times. However, invalid data will not be passed to the data subject.

post/consentreceipts

Headers

authorizationstring

The signed JWT that can be verified with the Public Key created in the OneTrust application. The value must include the type "Bearer" and should also include a "sub" claim that matches the identifier parameter value.

Example:Bearer eyJhbGciOiJSUxl1NiIsInT7xCI6IkpXVCIsImtpZCI6ImtleTIxMDQyABCyIn0.eyJwY3MiOiJiMzI2OWE3YmEzMTJjZjljM2YwODZmOTQ4Mjc5Zjc5MmY5NTc4ZjE4NWZkNzAzn2MwMzE5OTllZDMyZDU0MDFhIiwidmlydHVhbFJvbGUiOmZhbHNlLCJyb2xlIjoiU2l0ZSBBZG1pbiIsInVzZXJfbmFtZSI6Im90YXV0b3RlbmFudDAxQGdtYWlsLmNvbSIsImxhbmd1YWdlSWQABCsImZncHQiOiIkMmEkMTAkZzJIRHAuLy5ILkYuS3BGMlpZLkF2T0s0dHM1OUNvcWJZYnpmQzg3dEUyYzZ6anJuMVloblciLCJzZXNzaW9uSWQiOiI5ZmY5NTYzNi0yNTc2LTRmNGMtOWM1ZC0zODdjODYwZjhmMjgiLCJ0ZW5hbnRHdWlkIjoiZDQ0NGY0MGEtYmJiZS00NmMyLTgwODUtNmFkNjJkNThlMDJlIiwiYXV0aG9yaXRpZXMiOlsiU2l0ZSBBZG1pbiJdLCJjbGllbnRfaWQiOiJvbmV0cnVzdCIsInJ0ZWQiOjcsIm9yZ0dyb3VwqweiOiIxIiwib3JnR3JvdXBHdWlkIjoiMzBiODBmODEtMzlmYy00MzkxLTg4YWEtOWJjMjIxNDM5ZTcyIiwicGVybWlzc2lvbnMiOiJINHNJQUFBQUFBQUEveVdPTVVnRFFSQkY1eUtDWUJFRXhjSVVRbnBiYlNSTkxBVEJTa0d3MGtJUVJHME1KQ1FiaTlRcFVvaWdTU2tvZ3FBUUE4YlZTcXl1VVFRbG5oWWlJcmtMRWUrV2JIYS9lM0ZnEFGNdy8vM1puUmxJQWxBZm5sRkl0Zm1LbDNmVmNUajJMU0tLUGdyVzNFQ3NZOFBuSjA5MTMxVUl1cGxqcUt2Q1drWk1INmIyaGg3U1kyM3JWak1uSkZSREYxR29MWWJSWWw3YXpsS1ZjOEQ5cnZpNEF3SnpKZXlqUm5FZFlGbGRtNnBzRFZ1WDVUTlBNcFVOTktSdi9zQi8vYXg2bjcxQkd4L3pBeTRRN3dROFN2UUdiQitrYy9XVTAxVFF3Yms5MjRWSzVFenNUVTNISVYzSUABCh6NU5SYWlvQjFtTWt1b04wMFo0Z3lvdVNBQndHSHNMbkkzR1g2OU9LeStkR0ZqMG85aC9PazEvRjBzcENXWU5KZUwzbHIrbGw5Rm1SR05GNHZ3bkxVd0s0aGxkdDdTQlgrQVA4cWg4U1RRRUFBQT09LiIsInNjb3BlIjpbInJlAbciXSwicm9vdCI6IjMwYjgwZjgxLTM5ZmMtNDM5MS04OGFhLTliYzIyMTQzOWU3MiIsInRlbmFudElkIjo5MTExLCJndWlkIjoiNDRhYWY4OGEtNWU1NC00MzcxLWEzZGYtN2RhN2QABCVhMTAwIiwiZG9Ob3REZWxldGUiOmZhbHNlLCJleHAiOjE2ODU1MjM0OTAsImlhdCI6MTY4NTQzNzA5MCwianRpIjoid2FpMVRYRGtlMnU3LTZlRi16ZVgyV3hWTHU0IiwiZW1haWwiOiJvdGF1dG90ZW5hbnQwMUBnbWFpbC5jb20ifQ.HW2Q40LtN0HUHk2V1OOghG_rzGxPkua9ORT-P6vCtvpKT2vRss5vCfI5-2FaeDI7Wq4PoJXVaixcPC48EPqMWwSXavIR2-OMYJrDBYPxt8ABCAAOYC3nG5GFhv1Mhlk_1lFtf0mybkZLKv4mt0LduPqm4tNfpgOtzdumoUSr-5fLJ8mXJoKS961MkFIJSg0XP8rNQYcR7dzqViUpWLPHPkRRxyTSmXfRyfR7daSBnMx2WpoTIN00PIE8gDwMnCjDx83d2edENCg_STGJJQ6l36Ft1Wz3JOpUGU-lC6939XFO4CR7S4DPOVIl7WxHyXg7w1uj2R2opUr6j0RoZ0_IwA

The signed JWT that can be verified with the Public Key created in the OneTrust application. The value must include the type "Bearer" and should also include a "sub" claim that matches the identifier parameter value.

Request body

requestInformationstring required

The JSON web token (JWT) for a collection point.

testboolean

This flag indicates whether the receipt is for testing purposes.

generateInstantLinkTokenboolean

This flag indicates whether to generate a data subject link token (JWT) that expires after 12 months. This operates independently from the Magic Link settings configured within Global Settings. This parameter is only supported for API-type collection points and cannot be used in conjunction with the shortLinkToken parameter.

shortLinkTokenboolean

This flag indicates whether to generate a data subject link token with a reduced character length. This parameter cannot be used in conjunction with the generateInstantLinkToken parameter.

languagestring

The language set for the data subject.

identifierstring required

The data subject identifier of the data subject.

dsDataElementsobject

The additional information about the data subject provided during their consent interaction.

customPayloadobject

This parameter can be used to store custom data in key value pairs against the receipt. The total size of the customPayload data should not exceed 4000 characters.

additionalIdentifiersobject

Additional identifiers for the request, such as secondary email addresses

interactionDatestring

The date and time that the data subject interacted with the collection point.

enableDataElementDateValidationboolean

This flag indicates whether interaction date validation is enabled when updating data element values. If set to true, data element values will be overwritten only if the interaction date of the receipt is later than the last updated date of the data subject.

identifierTypestring

The type of data subject identifier used for the data subject's primary identifier.

Example request

{
  "requestInformation": "eyJhbGciOiJSUzVyMiJ9.eyJvdEp4gFZlcnNpb24iOjEsInByb2Nlc3NJZCI6Ijc2NTdkM2E5LTcwYWEtNGZjNy04MzE5LTgwYmU2OTkzNWQ0NiIsInByb2Nlc3NWZXJzaW9uIjo5LCJpYXQiOiIyMDIzLTAyLTAxVDA4OjIzOjUwLjg4MyIsIm1vYyI6IkhPU1RFRF9XRUJfRk9STSIsInBvbGljeV91cmkiOm51bGwsInN1YiI6IkVtYWlsIiwiaXNzIjpudWxsLCJ0ZW5hbnRJZCI6Ijk1MjE5ODkyLWVjZDEtNGI4Mi05MzQ0LWYyMjczMmY2YmJmOSIsImRlc2NyaXB0aW9uIjoiZGVzYyIsImNvbnNlbnRUeXBlIjoiT1BUSU5DSEVDS0JPWCIsImFsbG93Tm90R2l2ZW5Db25zZW50cyI6ZmFsc2UsImRvdWJsZU9wdEluIjpmYWxzZSwicHVycG9zZXMiOlt7ImlkIjoiNTEyNDI4YjctOTBkYS00YmQyLWE5MDEtNzM4NWUxMzM1ZWVlIiwidmVyc2lvbiI6MiwicGFyZW50SWQiOm51bGwsInRvcGljcyI6W10sImN1c3RvbVByZXSlcmVuY2VzIjpbeyJpZCI6ImViNTA1MGYzLWRmY2MtNDFmNi1iNzdiLTY1ODliYWRiNWUzZiIsImlzUmVxdWlyZWQiOmZhbHNlLCJvcHRpb25zIjpbIjg5NDJmMTMwLTc1YzUtNGE5Yi04YWJkLTdjZGEwMDZiZjMwMSIsIjJkOTkyZjJiLWYxNTUtNDdiOC04MzU3LTMxZTQxMmMyOGRjYSIsImQ2YzNmNDk3LTRkNzUtNDFkZi1iNzdhLTRiMTlmOTVhMGU2NiJdfV0sImVuYWJsZUdlb2xvY2F0aW9uIjpmYWxzZX0seyJpZCI6IjRkYWVkOTk0LTQxYzAtNDc2MS1hY2YwLTEzMzI5ZmM5YjVmOCIsInZlcnNpb24iOjMsInBhcmVudElkIjpudWxsLCJ0b3BpY3MiOltdLCJjdXN0b21QcmVmZXJlbmNlcyI6W10sImVuYWJsZUdlb2xvY2F0aW9uIjpmYWxzZX1dLCJub3RpY2VzIjpbXSwiZHNEYXRhRWxlbWVudHMiOlsiQWRkcmVzcyJdLCJhdXRoZW50aWNhdGlvblJlcXVpcmVkIjpmYWxzZSwicmVjb25maXJtQWN0aXZlUHVycG9zZSI6ZmFsc2UsIm92ZXJyaWRlQWN0aXZlUHVycG9zZSI6dHJ1ZSwiZHluYW1pY0NvbGxlY3Rpb25Qb2ludCI6ZmFsc2UsImFkZGl0aW9uYWxJZGVudGlmaWVycyI6W10sIm11bHRpcAblSWRlbnRpZmllclR5cGVzIjpmYWxzZSwiZW5hYmxlUGFyZW50UHJpbWFyeUlkZW50aWZpZXJzIjpmYWxzZSwicGFyZW50UHJpbWFyeUlkZW50aWZpZXJzVHlwZSI6bnVsbCwiYWRkaXRpb25hbFBhcmVudElkZW50aWZpZXJUeXBlcyI6W10sImVuYWJsZUdlb3fxY2F0aW9uIjpmYWxzZX0.tQvB9kNcmhKs05qFbXJdeBBSGFjvL2TyQVjuwaIaCs-Rr4r-sZsFzDeb9d0VPzSOLH15VPwgbCRgFfFO4WWHHnOExUiSFAgeo2PH4uNcCnocUQqHFxTD7CS7jKVgITgs0cf89_3cYBaevSUQz4NzG7QZLu8CAckTRyZfd15eN3D_9PzlvcJclj6Wu1zmcmMqXEXeyyCw9CCLp4Ss78eSptjd7aKOHmEtaXnXYym1qFvzvxn8vpEJS0fQ1OctSll0E0bt7N8AWSDDosBZU4f9YqZjpD_xc_1yoYbfxQFUbsc4zD_IEAN7ghwfpV4msUcCGXaNYnOOqrBtmhSaODAGrQ",
  "test": true,
  "shortLinkToken": true,
  "consentString": {
    "type": "GPP",
    "content": "DBACMYA~CQPftcAQPftcAPoABABGBkEAAAAAAAAAAAAAAAAAAAAA.QAAA.IAAA~BQPftcAQPftcAPoABABGB-CAAAAAAAAAAAAAAAAAAA.YAAAAAAAAAA"
  },
  "receiptOptions": [
    {
      "option": "ClearExpiration",
      "purposes": [
        "3fa85f64-5717-4562-b3fc-2c963f66afa6"
      ]
    }
  ],
  "source": {
    "type": "WEB",
    "content": "www.onetrust.com"
  },
  "language": "en-GB",
  "identifier": "mail@mail.com",
  "parentPrimaryIdentifiers": [
    {
      "ParentIdentifier": "+1(999)999-9999",
      "AdditionalParentIdentifierTypes": {
        "Mobile": "+1(999)999-9999"
      },
      "ParentTestDataSubject": true
    }
  ],
  "dsDataElements": {
    "DataElement1Name": "Value"
  },
  "customPayload": {
    "key1": "value1"
  },
  "additionalIdentifiers": {
    "Email": "test_secondary_identifier@test.com"
  },
  "attachments": [
    {
      "id": "aa978afe-bbe9-4419-8fa9-f3691f1046c3"
    }
  ],
  "purposes": [
    {
      "Id": "aa978afe-bbe9-4419-8fa9-f3691f1046c3",
      "Version": 1,
      "Preferences": [
        {
          "TopicId": "aa978afe-bbe9-4419-8fa9-f3691f1046c3",
          "TransactionType": "OPT_IN"
        }
      ],
      "CustomPreferences": [
        {
          "Id": "aa978afe-bbe9-4419-8fa9-f3691f1046c3",
          "Options": [
            "aa978afe-bbe9-4419-8fa9-f3691f1046c3"
          ],
          "Choices": [
            {
              "OptionId": "aa978afe-bbe9-4419-8fa9-f3691f1046c3",
              "TransactionType": "OPT_OUT"
            }
          ]
        }
      ],
      "PrivacyNotices": [
        {
          "Id": "18c07e52-689c-447c-b640-546385a3efcf",
          "Version": 1,
          "MinorVersion": 1
        }
      ],
      "TransactionType": "CONFIRMED",
      "ExpiryDate": "2020-01-01T12:00-05:00",
      "PurposeAttachments": [
        {
          "id": "aa978afe-bbe9-4419-8fa9-f3691f1046c3"
        }
      ],
      "PurposeNote": {
        "noteId": "aa978afe-bbe9-4419-8fa9-f3691f1046c3",
        "noteType": "UNSUBSCRIBE_REASON",
        "noteLanguage": "en-us",
        "noteText": "Reason 1"
      }
    }
  ],
  "interactionDate": "2019-05-14T01:34:33.000Z",
  "privacyNotices": [
    {
      "Id": "18c07e52-689c-447c-b640-546385a3efcf",
      "Version": 1,
      "MinorVersion": 1
    }
  ],
  "geoLocation": {
    "country": "US",
    "state": "GA",
    "stateName": "Georgia"
  },
  "enableDataElementDateValidation": true,
  "identifierType": "Email"
}

Response

OK

instantLinkTokenstring

Instant link tokens operate independently from the magic link creation functionality under Global Settings and will expire after 12 months.

linkTokenstring

The magic link token can be appended to the Preference Center login URL for a data subject login.

receiptstring

A JSON web token (JWT) which contains the record of the transaction.

Example response

{
  "instantLinkToken": "{JWT TOKEN}",
  "linkToken": "p4S2%2FKWgxNmOkf7Rz0%2FCxVrQR3o9HhvTgN2jgSU9pMk%3D",
  "receipt": "{JWT TOKEN}"
}