Skip to main content

Endpoint

Authentication

Requires a developer API key in the Authorization header.

Request Headers

Path Parameters

Request Body

The body must be a JSON object; a missing or malformed body is 400. A Data Principal may withdraw consent at any time, and withdrawing is to be as easy as giving consent (DPDP Act s.6(4)); offering that means is the fiduciary’s user interface, which calls this endpoint. After a withdrawal the Data Fiduciary, and its processors, must cease processing within a reasonable time (s.6(6)). These provisions apply from 13 May 2027 (DPDP Rules 2025 r.1). Revoking the grant stops Grantex-mediated processing under that grant: it is marked revoked with revokedAt, the revocation cache is updated and a grant.revoked event is emitted. By default only the record’s own grant is revoked, as this endpoint always did; grants delegated from it keep working. A server that sets DPDP_REVOCATION_CASCADE=true revokes through the same cascade as DELETE /v1/grants/:id instead (delegated grants, credentials, wallet reservations). Only an active grant is revoked. A server operator who wants every withdrawal to revoke unless the caller says otherwise sets DPDP_WITHDRAWAL_REVOKES_GRANT=true; an explicit revokeGrant: false still wins. Grantex holds no personal data the fiduciary processed. deleteProcessedData therefore does not delete or rewrite anything in Grantex (the audit log is a tamper-evident hash chain and is never modified); it asks the developer, by webhook, to delete the data in its own systems. The withdrawal, the grant revocation and the audit entry (grantex.dpdp.consent_withdrawn) are one transaction. Only an active record can be withdrawn, so of two concurrent withdrawals exactly one succeeds.

Example Request

Response — 200 OK

Response Fields

Error Responses

SDK Examples

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Last modified on September 30, 2026