Legal

Record the authenticated user's consent to a policy document type

Changed on

POST /consents/ — record acceptance of document_type for the current user.

Authenticated only. Captures client IP + User-Agent for audit-grade proof; delegates version resolution + persistence to ConsentService.

post/consents/

Request

  • The document declares no server URL.
  • Auth: one of:
    • HTTP bearer
    • API key in cookie sessionid

Request body

document_type'privacy_policy' | 'terms_of_use' | 'sms_consent' required
  • privacy_policy - Privacy Policy
  • terms_of_use - Terms of Use
  • sms_consent - SMS Messaging Consent
phone_numberstring

Response

idinteger required
document_typestring required
policy_documentinteger required
policy_document_versioninteger required
source'signup_form' | 'oauth_step' | 'api' required
  • signup_form - Signup Form
  • oauth_step - OAuth Consent Step
  • api - API
accepted_atstring date-time required
ip_addressstring nullable required
user_agentstring required
phone_numberstring required

Changes