/sites/{siteId}/consent-exportDownload the proof-of-consent export
The regulator-facing document: every consent record in scope, oldest first, with its limitations and a completeness statement.
Auth header
Authorization: Bearer tsk_live_…The key needsconsent:export
Parameters
siteIdstringin pathrequiredThe site id, from GET /v1/sites.
fromstringin queryoptionalISO-8601 lower bound on receivedAt.
tostringin queryoptionalISO-8601 upper bound on receivedAt.
subjectIdstringin queryoptionalOne device's history.
Example request
curl "https://app.tagsentry.ai/api/v1/sites/3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10/consent-export" \ -H "Authorization: Bearer tsk_live_…"Response 200
exportVersionintegerrequiredgeneratedAtstringrequiredISO-8601 timestamp, UTC.
scopeobjectrequiredscope.siteIdstringrequiredscope.subjectIdstring | nullrequiredhistoryarray of map of anyrequiredcurrentmap of any | nullrequiredlimitationsarray of map of anyrequiredcompletenessobjectrequiredREAD THIS FIRST.
complete: falsemeans the document is partial and says by how much.completeness.completebooleanrequiredcompleteness.recordsInScopeintegerrequiredcompleteness.recordsOmittedintegerrequired
Example response
{ "exportVersion": 0, "generatedAt": "2026-09-26T14:02:00.000Z", "scope": { "siteId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10", "subjectId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10" }, "history": [ { "key": null } ], "current": { "key": null }, "limitations": [ { "key": null } ], "completeness": { "complete": false, "recordsInScope": 0, "recordsOmitted": 0 }}More about this endpoint
The same document the dashboard downloads.
READ completeness FIRST. Past its record cap the document keeps the newest and says exactly how many it left out; export in from/to windows to get the rest. The X-Consent-Export-Complete header carries the same fact.
Only for a verified domain: otherwise 403 domain_not_verified.
Errors400 · 401 · 403 · 404 · 429 · 500
400The request did not validate against this operation's schema.401Missing, malformed, unknown, revoked or expired API key. These are deliberately indistinguishable in the response -- distinguishing them would confirm to a caller that a token was once real.403The key authenticated but does not carry the scope(s) this operation requires, or (`domain_not_verified`) the site's domain is not verified, so its consent records are not released.404No such resource on this account. A site id belonging to a DIFFERENT account answers 404, never 403 -- a 403 would confirm the id exists somewhere.429A rate limit or quota was exceeded. The body names WHICH one.500Something failed on our side. The requestId in the body is what to quote.
Every error has the same body: { error: { code, message, requestId } }.
From the OpenAPI document, version 2026-08-26. Raw OpenAPI