v1

latestOpenAPI 3.1.0Apache 2.02026-07-245981,1853.0 MB
Consent Receipts

Create Identified Consent Receipts

Use this API to create consent receipts for identified data subjects using non-cookie collection points. This endpoint is designed specifically for scenarios where data subjects are identified through explicit identifiers rather than cookies.

🗒 Things to Know

  • Each collection point must first be set up in the OneTrust Platform to generate a valid JWT, which must be present in the request payload. The JWT can be found on the Integrations tab of the Collection point details screen or via the Get Collection Point Token API.

  • When using this endpoint, you must include an identifier for the data subject, such as an email address or other unique identifier, in the request payload.

  • The identified endpoint creates a persistent record of consent for the data subject that can be managed and updated over time through the OneTrust preference center.

  • If you need to link multiple identifiers to the same data subject, use the additionalIdentifiers parameter in your request payload.

  • In most cases, further authorization is not required. However, additional information for setting up authenticated consent can be found here when needed.

  • OneTrust recommends including no more than 10 purposes per consent receipt, with an absolute maximum of 20 purposes.

  • Please validate all inputs before sending data to a Custom API collection point. This API does not perform data type validation to ensure high performance and fast response times. However, invalid data will not be passed to the data subject.

post/consentreceipts/identified

Headers

authorizationstring

The signed JWT that can be verified with the Public Key created in the OneTrust application. The value must include the type "Bearer" and should also include a "sub" claim that matches the identifier parameter value.

Example:Bearer eyJhbGciOiJSUxl1NiIsInT7xCI6IkpXVCIsImtpZCI6ImtleTIxMDQyABCyIn0.eyJwY3MiOiJiMzI2OWE3YmEzMTJjZjljM2YwODZmOTQ4Mjc5Zjc5MmY5NTc4ZjE4NWZkNzAzn2MwMzE5OTllZDMyZDU0MDFhIiwidmlydHVhbFJvbGUiOmZhbHNlLCJyb2xlIjoiU2l0ZSBBZG1pbiIsInVzZXJfbmFtZSI6Im90YXV0b3RlbmFudDAxQGdtYWlsLmNvbSIsImxhbmd1YWdlSWQABCsImZncHQiOiIkMmEkMTAkZzJIRHAuLy5ILkYuS3BGMlpZLkF2T0s0dHM1OUNvcWJZYnpmQzg3dEUyYzZ6anJuMVloblciLCJzZXNzaW9uSWQiOiI5ZmY5NTYzNi0yNTc2LTRmNGMtOWM1ZC0zODdjODYwZjhmMjgiLCJ0ZW5hbnRHdWlkIjoiZDQ0NGY0MGEtYmJiZS00NmMyLTgwODUtNmFkNjJkNThlMDJlIiwiYXV0aG9yaXRpZXMiOlsiU2l0ZSBBZG1pbiJdLCJjbGllbnRfaWQiOiJvbmV0cnVzdCIsInJ0ZWQiOjcsIm9yZ0dyb3VwqweiOiIxIiwib3JnR3JvdXBHdWlkIjoiMzBiODBmODEtMzlmYy00MzkxLTg4YWEtOWJjMjIxNDM5ZTcyIiwicGVybWlzc2lvbnMiOiJINHNJQUFBQUFBQUEveVdPTVVnRFFSQkY1eUtDWUJFRXhjSVVRbnBiYlNSTkxBVEJTa0d3MGtJUVJHME1KQ1FiaTlRcFVvaWdTU2tvZ3FBUUE4YlZTcXl1VVFRbG5oWWlJcmtMRWUrV2JIYS9lM0ZnEFGNdy8vM1puUmxJQWxBZm5sRkl0Zm1LbDNmVmNUajJMU0tLUGdyVzNFQ3NZOFBuSjA5MTMxVUl1cGxqcUt2Q1drWk1INmIyaGg3U1kyM3JWak1uSkZSREYxR29MWWJSWWw3YXpsS1ZjOEQ5cnZpNEF3SnpKZXlqUm5FZFlGbGRtNnBzRFZ1WDVUTlBNcFVOTktSdi9zQi8vYXg2bjcxQkd4L3pBeTRRN3dROFN2UUdiQitrYy9XVTAxVFF3Yms5MjRWSzVFenNUVTNISVYzSUABCh6NU5SYWlvQjFtTWt1b04wMFo0Z3lvdVNBQndHSHNMbkkzR1g2OU9LeStkR0ZqMG85aC9PazEvRjBzcENXWU5KZUwzbHIrbGw5Rm1SR05GNHZ3bkxVd0s0aGxkdDdTQlgrQVA4cWg4U1RRRUFBQT09LiIsInNjb3BlIjpbInJlAbciXSwicm9vdCI6IjMwYjgwZjgxLTM5ZmMtNDM5MS04OGFhLTliYzIyMTQzOWU3MiIsInRlbmFudElkIjo5MTExLCJndWlkIjoiNDRhYWY4OGEtNWU1NC00MzcxLWEzZGYtN2RhN2QABCVhMTAwIiwiZG9Ob3REZWxldGUiOmZhbHNlLCJleHAiOjE2ODU1MjM0OTAsImlhdCI6MTY4NTQzNzA5MCwianRpIjoid2FpMVRYRGtlMnU3LTZlRi16ZVgyV3hWTHU0IiwiZW1haWwiOiJvdGF1dG90ZW5hbnQwMUBnbWFpbC5jb20ifQ.HW2Q40LtN0HUHk2V1OOghG_rzGxPkua9ORT-P6vCtvpKT2vRss5vCfI5-2FaeDI7Wq4PoJXVaixcPC48EPqMWwSXavIR2-OMYJrDBYPxt8ABCAAOYC3nG5GFhv1Mhlk_1lFtf0mybkZLKv4mt0LduPqm4tNfpgOtzdumoUSr-5fLJ8mXJoKS961MkFIJSg0XP8rNQYcR7dzqViUpWLPHPkRRxyTSmXfRyfR7daSBnMx2WpoTIN00PIE8gDwMnCjDx83d2edENCg_STGJJQ6l36Ft1Wz3JOpUGU-lC6939XFO4CR7S4DPOVIl7WxHyXg7w1uj2R2opUr6j0RoZ0_IwA

The signed JWT that can be verified with the Public Key created in the OneTrust application. The value must include the type "Bearer" and should also include a "sub" claim that matches the identifier parameter value.

Request body

requestInformationstring required

The JSON web token (JWT) for a collection point.

testboolean

This flag indicates whether the receipt is for testing purposes.

generateInstantLinkTokenboolean

This flag indicates whether to generate a data subject link token (JWT) that expires after 12 months. This operates independently from the Magic Link settings configured within Global Settings. This parameter is only supported for API-type collection points and cannot be used in conjunction with the shortLinkToken parameter.

shortLinkTokenboolean

This flag indicates whether to generate a data subject link token with a reduced character length. This parameter cannot be used in conjunction with the generateInstantLinkToken parameter.

languagestring

The language set for the data subject.

identifierstring required

The data subject identifier of the data subject.

dsDataElementsobject

The additional information about the data subject provided during their consent interaction.

customPayloadobject

This parameter can be used to store custom data in key value pairs against the receipt. The total size of the customPayload data should not exceed 4000 characters.

additionalIdentifiersobject

Additional identifiers for the request, such as secondary email addresses

interactionDatestring

The date and time that the data subject interacted with the collection point.

enableDataElementDateValidationboolean

This flag indicates whether interaction date validation is enabled when updating data element values. If set to true, data element values will be overwritten only if the interaction date of the receipt is later than the last updated date of the data subject.

identifierTypestring

The type of data subject identifier used for the data subject's primary identifier.

Example request

{
  "requestInformation": "eyJhbGciOiJSUzVyMiJ9.eyJvdEp4gFZlcnNpb24iOjEsInByb2Nlc3NJZCI6Ijc2NTdkM2E5LTcwYWEtNGZjNy04MzE5LTgwYmU2OTkzNWQ0NiIsInByb2Nlc3NWZXJzaW9uIjo5LCJpYXQiOiIyMDIzLTAyLTAxVDA4OjIzOjUwLjg4MyIsIm1vYyI6IkhPU1RFRF9XRUJfRk9STSIsInBvbGljeV91cmkiOm51bGwsInN1YiI6IkVtYWlsIiwiaXNzIjpudWxsLCJ0ZW5hbnRJZCI6Ijk1MjE5ODkyLWVjZDEtNGI4Mi05MzQ0LWYyMjczMmY2YmJmOSIsImRlc2NyaXB0aW9uIjoiZGVzYyIsImNvbnNlbnRUeXBlIjoiT1BUSU5DSEVDS0JPWCIsImFsbG93Tm90R2l2ZW5Db25zZW50cyI6ZmFsc2UsImRvdWJsZU9wdEluIjpmYWxzZSwicHVycG9zZXMiOlt7ImlkIjoiNTEyNDI4YjctOTBkYS00YmQyLWE5MDEtNzM4NWUxMzM1ZWVlIiwidmVyc2lvbiI6MiwicGFyZW50SWQiOm51bGwsInRvcGljcyI6W10sImN1c3RvbVByZXSlcmVuY2VzIjpbeyJpZCI6ImViNTA1MGYzLWRmY2MtNDFmNi1iNzdiLTY1ODliYWRiNWUzZiIsImlzUmVxdWlyZWQiOmZhbHNlLCJvcHRpb25zIjpbIjg5NDJmMTMwLTc1YzUtNGE5Yi04YWJkLTdjZGEwMDZiZjMwMSIsIjJkOTkyZjJiLWYxNTUtNDdiOC04MzU3LTMxZTQxMmMyOGRjYSIsImQ2YzNmNDk3LTRkNzUtNDFkZi1iNzdhLTRiMTlmOTVhMGU2NiJdfV0sImVuYWJsZUdlb2xvY2F0aW9uIjpmYWxzZX0seyJpZCI6IjRkYWVkOTk0LTQxYzAtNDc2MS1hY2YwLTEzMzI5ZmM5YjVmOCIsInZlcnNpb24iOjMsInBhcmVudElkIjpudWxsLCJ0b3BpY3MiOltdLCJjdXN0b21QcmVmZXJlbmNlcyI6W10sImVuYWJsZUdlb2xvY2F0aW9uIjpmYWxzZX1dLCJub3RpY2VzIjpbXSwiZHNEYXRhRWxlbWVudHMiOlsiQWRkcmVzcyJdLCJhdXRoZW50aWNhdGlvblJlcXVpcmVkIjpmYWxzZSwicmVjb25maXJtQWN0aXZlUHVycG9zZSI6ZmFsc2UsIm92ZXJyaWRlQWN0aXZlUHVycG9zZSI6dHJ1ZSwiZHluYW1pY0NvbGxlY3Rpb25Qb2ludCI6ZmFsc2UsImFkZGl0aW9uYWxJZGVudGlmaWVycyI6W10sIm11bHRpcAblSWRlbnRpZmllclR5cGVzIjpmYWxzZSwiZW5hYmxlUGFyZW50UHJpbWFyeUlkZW50aWZpZXJzIjpmYWxzZSwicGFyZW50UHJpbWFyeUlkZW50aWZpZXJzVHlwZSI6bnVsbCwiYWRkaXRpb25hbFBhcmVudElkZW50aWZpZXJUeXBlcyI6W10sImVuYWJsZUdlb3fxY2F0aW9uIjpmYWxzZX0.tQvB9kNcmhKs05qFbXJdeBBSGFjvL2TyQVjuwaIaCs-Rr4r-sZsFzDeb9d0VPzSOLH15VPwgbCRgFfFO4WWHHnOExUiSFAgeo2PH4uNcCnocUQqHFxTD7CS7jKVgITgs0cf89_3cYBaevSUQz4NzG7QZLu8CAckTRyZfd15eN3D_9PzlvcJclj6Wu1zmcmMqXEXeyyCw9CCLp4Ss78eSptjd7aKOHmEtaXnXYym1qFvzvxn8vpEJS0fQ1OctSll0E0bt7N8AWSDDosBZU4f9YqZjpD_xc_1yoYbfxQFUbsc4zD_IEAN7ghwfpV4msUcCGXaNYnOOqrBtmhSaODAGrQ",
  "test": true,
  "shortLinkToken": true,
  "consentString": {
    "type": "GPP",
    "content": "DBACMYA~CQPftcAQPftcAPoABABGBkEAAAAAAAAAAAAAAAAAAAAA.QAAA.IAAA~BQPftcAQPftcAPoABABGB-CAAAAAAAAAAAAAAAAAAA.YAAAAAAAAAA"
  },
  "receiptOptions": [
    {
      "option": "ClearExpiration",
      "purposes": [
        "3fa85f64-5717-4562-b3fc-2c963f66afa6"
      ]
    }
  ],
  "source": {
    "type": "WEB",
    "content": "www.onetrust.com"
  },
  "language": "en-GB",
  "identifier": "mail@mail.com",
  "parentPrimaryIdentifiers": [
    {
      "ParentIdentifier": "+1(999)999-9999",
      "AdditionalParentIdentifierTypes": {
        "Mobile": "+1(999)999-9999"
      },
      "ParentTestDataSubject": true
    }
  ],
  "dsDataElements": {
    "DataElement1Name": "Value"
  },
  "customPayload": {
    "key1": "value1"
  },
  "additionalIdentifiers": {
    "Email": "test_secondary_identifier@test.com"
  },
  "attachments": [
    {
      "id": "aa978afe-bbe9-4419-8fa9-f3691f1046c3"
    }
  ],
  "purposes": [
    {
      "Id": "aa978afe-bbe9-4419-8fa9-f3691f1046c3",
      "Version": 1,
      "Preferences": [
        {
          "TopicId": "aa978afe-bbe9-4419-8fa9-f3691f1046c3",
          "TransactionType": "OPT_IN"
        }
      ],
      "CustomPreferences": [
        {
          "Id": "aa978afe-bbe9-4419-8fa9-f3691f1046c3",
          "Options": [
            "aa978afe-bbe9-4419-8fa9-f3691f1046c3"
          ],
          "Choices": [
            {
              "OptionId": "aa978afe-bbe9-4419-8fa9-f3691f1046c3",
              "TransactionType": "OPT_OUT"
            }
          ]
        }
      ],
      "PrivacyNotices": [
        {
          "Id": "18c07e52-689c-447c-b640-546385a3efcf",
          "Version": 1,
          "MinorVersion": 1
        }
      ],
      "TransactionType": "CONFIRMED",
      "ExpiryDate": "2020-01-01T12:00-05:00",
      "PurposeAttachments": [
        {
          "id": "aa978afe-bbe9-4419-8fa9-f3691f1046c3"
        }
      ],
      "PurposeNote": {
        "noteId": "aa978afe-bbe9-4419-8fa9-f3691f1046c3",
        "noteType": "UNSUBSCRIBE_REASON",
        "noteLanguage": "en-us",
        "noteText": "Reason 1"
      }
    }
  ],
  "interactionDate": "2019-05-14T01:34:33.000Z",
  "privacyNotices": [
    {
      "Id": "18c07e52-689c-447c-b640-546385a3efcf",
      "Version": 1,
      "MinorVersion": 1
    }
  ],
  "geoLocation": {
    "country": "US",
    "state": "GA",
    "stateName": "Georgia"
  },
  "enableDataElementDateValidation": true,
  "identifierType": "Email"
}

Response

OK

receiptstring

A JSON web token (JWT) which contains the record of the transaction.

instantLinkTokenstring

Instant link tokens operate independently from the magic link creation functionality under Global Settings and will expire after 12 months.

linkTokenstring

The magic link token can be appended to the Preference Center login URL for a data subject login.

Example response

[
  {
    "receipt": "625ba071-61b0-485f-81a0-a2245777b430",
    "instantLinkToken": "{JWT TOKEN}",
    "linkToken": "p4S2%2FKWgxNmOkf7Rz0%2FCxVrQR3o9HhvTgN2jgSU9pMk%3D"
  }
]