All endpoints

DocsAPIConsent records

GET/sites/{siteId}/consent-export

Download the proof-of-consent export

The regulator-facing document: every consent record in scope, oldest first, with its limitations and a completeness statement.

Auth header

Authorization: Bearer tsk_live_…

The key needsconsent:export

Parameters

  • siteIdstringin pathrequired

    The site id, from GET /v1/sites.

  • fromstringin queryoptional

    ISO-8601 lower bound on receivedAt.

  • tostringin queryoptional

    ISO-8601 upper bound on receivedAt.

  • subjectIdstringin queryoptional

    One device's history.

Example request

curl "https://app.tagsentry.ai/api/v1/sites/3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10/consent-export" \  -H "Authorization: Bearer tsk_live_…"

Response 200

  • exportVersionintegerrequired
  • generatedAtstringrequired

    ISO-8601 timestamp, UTC.

  • scopeobjectrequired
  • scope.siteIdstringrequired
  • scope.subjectIdstring | nullrequired
  • historyarray of map of anyrequired
  • currentmap of any | nullrequired
  • limitationsarray of map of anyrequired
  • completenessobjectrequired

    READ THIS FIRST. complete: false means the document is partial and says by how much.

  • completeness.completebooleanrequired
  • completeness.recordsInScopeintegerrequired
  • completeness.recordsOmittedintegerrequired

Example response

{  "exportVersion": 0,  "generatedAt": "2026-09-26T14:02:00.000Z",  "scope": {    "siteId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10",    "subjectId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10"  },  "history": [    {      "key": null    }  ],  "current": {    "key": null  },  "limitations": [    {      "key": null    }  ],  "completeness": {    "complete": false,    "recordsInScope": 0,    "recordsOmitted": 0  }}
More about this endpoint

The same document the dashboard downloads.

READ completeness FIRST. Past its record cap the document keeps the newest and says exactly how many it left out; export in from/to windows to get the rest. The X-Consent-Export-Complete header carries the same fact.

Only for a verified domain: otherwise 403 domain_not_verified.

Errors400 · 401 · 403 · 404 · 429 · 500
  • 400The request did not validate against this operation's schema.
  • 401Missing, malformed, unknown, revoked or expired API key. These are deliberately indistinguishable in the response -- distinguishing them would confirm to a caller that a token was once real.
  • 403The key authenticated but does not carry the scope(s) this operation requires, or (`domain_not_verified`) the site's domain is not verified, so its consent records are not released.
  • 404No such resource on this account. A site id belonging to a DIFFERENT account answers 404, never 403 -- a 403 would confirm the id exists somewhere.
  • 429A rate limit or quota was exceeded. The body names WHICH one.
  • 500Something failed on our side. The requestId in the body is what to quote.

Every error has the same body: { error: { code, message, requestId } }.

From the OpenAPI document, version 2026-08-26. Raw OpenAPI