Skip to main content

Endpoint

Authentication

Requires a developer API key in the Authorization header.

Request Headers

Request Body

The grant must be the developer’s and active (not revoked, suspended or expired). dataPrincipalId is the end user who gave consent, which in the documented model is the grant’s principal (principal_id). With DPDP_ENFORCE_GRANT_PRINCIPAL=true a record whose dataPrincipalId differs from the grant’s principal is refused with PRINCIPAL_MISMATCH; with the flag off (the default) the two are not compared, and an integration that keys its data principals differently from its grant principals keeps working. Limits: grantId, dataPrincipalId and consentNoticeId up to 256 characters; consentNoticeVersion and each purpose code up to 128; each purpose description up to 1,000; at most 50 purposes.

Purpose Object

Example Request

Response — 201 Created

Response Fields

proofJwt is a compact JWS (RFC 7515) signed with EdDSA over Ed25519 (RFC 8037). Its payload carries recordId, grantId, dataPrincipalId, consentNoticeId, consentNoticeVersion, consentNoticeHash (the content hash), consentNoticeLanguage, noticeHash (the whole notice), the purpose codes, consentGivenAt, iss and iat, and no exp: the proof is evidence the Data Fiduciary may need for as long as it keeps the record (DPDP Act s.6(10) puts the burden of proving consent on the fiduciary). Verify it with the key the header’s kid names in the JWKS at jwksUri. Set ED25519_PRIVATE_KEY in production: without it each process generates its own key, and a proof cannot be verified after a restart or by another instance. keyPersistence says which kind of key signed the proof: A server started with DPDP_REQUIRE_PERSISTENT_PROOF_KEY=true refuses to create a record while its key is ephemeral (503 CONSENT_PROOF_KEY_NOT_PERSISTENT, nothing stored). If the proof cannot be signed, no record is created and the request fails with 503 CONSENT_PROOF_UNAVAILABLE. The creation is recorded on the developer’s audit chain as grantex.dpdp.consent_created.

Error Responses

SDK Examples

To pin consentNoticeVersion or consentNoticeLanguage, use the REST call above unless your SDK version lists those fields.

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Last modified on September 30, 2026