Endpoint
Authentication
Requires a developer API key in theAuthorization header.
Request Headers
Request Body
The grant must be the developer’s and active (not revoked, suspended or
expired).
dataPrincipalId is the end user who gave consent, which in the
documented model is the grant’s principal (principal_id). With
DPDP_ENFORCE_GRANT_PRINCIPAL=true a record whose dataPrincipalId differs
from the grant’s principal is refused with PRINCIPAL_MISMATCH; with the flag
off (the default) the two are not compared, and an integration that keys its
data principals differently from its grant principals keeps working.
Limits: grantId, dataPrincipalId and consentNoticeId up to 256
characters; consentNoticeVersion and each purpose code up to 128; each
purpose description up to 1,000; at most 50 purposes.
Purpose Object
Example Request
Response — 201 Created
Response Fields
Consent Proof
proofJwt is a compact JWS (RFC 7515) signed with EdDSA over Ed25519
(RFC 8037). Its payload carries recordId, grantId, dataPrincipalId,
consentNoticeId, consentNoticeVersion, consentNoticeHash (the content
hash), consentNoticeLanguage, noticeHash (the whole notice), the purpose
codes, consentGivenAt, iss and iat, and no exp: the proof is evidence
the Data Fiduciary may need for as long as it keeps the record (DPDP Act
s.6(10) puts the burden of proving consent on the fiduciary). Verify it with
the key the header’s kid names in the JWKS at jwksUri. Set
ED25519_PRIVATE_KEY in production: without it each process generates its
own key, and a proof cannot be verified after a restart or by another instance.
keyPersistence says which kind of key signed the proof:
A server started with
DPDP_REQUIRE_PERSISTENT_PROOF_KEY=true refuses to
create a record while its key is ephemeral (503 CONSENT_PROOF_KEY_NOT_PERSISTENT, nothing stored).
If the proof cannot be signed, no record is created and the request fails
with 503 CONSENT_PROOF_UNAVAILABLE.
The creation is recorded on the developer’s audit chain as
grantex.dpdp.consent_created.
Error Responses
SDK Examples
consentNoticeVersion or consentNoticeLanguage, use the REST call
above unless your SDK version lists those fields.