Consent capture is one call. Making withdrawal arrive is the hard part.
- Endpoints
- 6
- Webhook events
- 6
- API version
- v1
Capture, withdraw and evidence consent across your stack — embed the widget, call the REST API, or install the SDK. The propagation downstream is the part we do for you.
Quickstart
Everything on this page, in one file
Initialise, create a purpose-scoped receipt, and wire the two events that carry a statutory obligation — granted, and withdrawn.
import { MyConsent, ConsentLevel } from '@myconsent/sdk';
// Initialize the SDK
const client = new MyConsent({
tenantId: process.env.MYCONSENT_TENANT_ID,
region: 'IN',
apiVersion: 'v1'
});
// Create a contextual consent receipt
const receipt = await client.consent.create({
userId: 'user_abc123',
purposes: [
ConsentLevel.GRANULAR_BIO,
ConsentLevel.SENSITIVE_DATA,
ConsentLevel.CROSS_BORDER
],
retention: {
period: '1Y',
autoDelete: true,
onWithdrawal: 'immediate'
},
context: {
ipAddress: 'request.ip',
userAgent: 'request.userAgent',
timestamp: new Date().toISOString()
}
});
// Subscribe to consent events
client.events.on('consent.granted', (evt) => {
console.log('Consent granted:', evt.receiptId);
receipt.audit(evt); // Immutable logging
});
client.events.on('consent.withdrawn', async (evt) => {
await client.data.erase(evt.userId, {
scope: 'all',
proof: true // Returns deletion certificate
});
});
RESTful API
Full GraphQL & REST API for every consent operation. Webhooks for real-time event streaming.
Multi-Platform SDKs
Native support for React, Vue, iOS, Android, and IoT devices. Zero-config deployment.
Enterprise Security
OAuth2, JWT and mTLS, with envelope-encrypted key management and rotation.
REST
Six endpoints
Every consent operation, plus the audit trail and the rights request. GraphQL covers the same surface.
| Method | Path | What it does |
|---|---|---|
| POST | /api/v1/consent | Create a new consent receipt |
| GET | /api/v1/consent/{id} | Retrieve consent details |
| DELETE | /api/v1/consent/{id} | Withdraw and erase consent |
| GET | /api/v1/audit/{id} | Retrieve audit trail |
| POST | /api/v1/dsr/{userId} | Process data subject request |
| POST | /api/v1/webhook/subscribe | Register event webhook |
Webhook events
Priority is what a missed delivery costs you, not how often the event fires.
consent.grantedHIGHUser has granted consentconsent.withdrawnCRITICALUser has withdrawn consentconsent.expiringMEDIUMConsent expiring within 30 daysdsr.completedHIGHData subject request fulfilledbreach.detectedCRITICALPotential data breach detectedaudit.updatedLOWAudit log entry created
Want the sandbox keys?
We will provision a tenant against your own purposes so you can exercise capture, withdrawal and the evidence export before anything touches production.
What the endpoints sit on top of is the consent management platform, and what it costs is on pricing.
Questions people ask
- Is there a consent management API for the DPDP Act?
- Yes. Six REST endpoints cover capture, withdrawal, receipt retrieval and evidence export, and six webhook events carry state changes outward. Consent is purpose-scoped at the API level, so withdrawal from one purpose does not touch the others.
- Which SDKs are available?
- React and Vue for web, iOS and Android for mobile, and a server-side client for backend capture. Each wraps the same endpoints, so a consent captured through a widget and one captured through the API produce the same record.
- How do I record which notice version a Data Principal saw?
- Pass the notice version and language with the capture call. Both are stored on the receipt, so the record shows which text was shown, in which language, before consent — which is the question Sec. 5 turns on in a dispute.
- What happens when a Data Principal withdraws consent?
- The consent.withdrawn event fires to every subscribed endpoint with the purpose and a cessation timestamp. Each acknowledgement is written to the ledger, so propagation is provable rather than assumed.
- Is there a sandbox?
- Yes. Sandbox keys issue against a test tenant with the same endpoints, webhooks and receipt format as production, so integration work does not run against real personal data.