HTTP API and errors

The SDK wraps these endpoints. You only need them directly if you are building your own client.

Endpoints

EndpointAuthPurpose
GET /api/v1/consent?pk=NoneConsent presentation
POST /api/v1/attestationsServer credentialMint an attestation (backend only)
POST /api/v1/consents?pk=AttestationRecord an opt-in. Returns a contributor token and receipt
POST /api/v1/contributor-tokens?pk=AttestationRefresh the token for a consenting contributor
POST /api/v1/contributions?pk=Contributor tokenSubmit a batch. Requires Idempotency-Key
POST /api/v1/consents/withdraw?pk=Token or attestationWithdraw
POST /api/v1/deletion-requests?pk=Token or attestationRequest deletion
POST /api/v1/server/subjects/withdrawServer credentialWithdraw on behalf of a user
POST /api/v1/server/subjects/deletionServer credentialDelete on behalf of a user

Batches

POST /api/v1/contributions?pk=pk_live_…
Authorization: Bearer <contributor token>
Idempotency-Key: <batchId>

{
  "batchId": "b_8f2k1m9q",
  "sdkVersion": "0.1.0",
  "events": [ /* up to 50 events */ ]
}

Requests are limited to 64 KB. Rate limits apply per contributor and per environment.

Errors

error body
{ "error": { "code": "invalid_batch", "message": "…", "details": [{ "path": "events.0.payload.to", "message": "…" }] } }
CodeMeaningSDK behaviour
token_expired, invalid_tokenA new attestation is neededRe-attests once and retries the same batch
token_revoked, consent_withdrawnWithdrawn elsewhereMoves to withdrawn and clears the queue
consent_renewal_requiredThe consent scope changedMoves to renewal_required
collection_disabled, schema_not_approved, application_not_approvedNot permitted right nowMoves to unavailable
rate_limited (429), 5xxTemporaryBacks off, honours Retry-After, bounded retries
invalid_batch, payload_too_largeA client bugDrops the batch and calls onError