/sites/{siteId}/consent-recordsRead consent decisions
This site's consent records, oldest first.
Auth header
Authorization: Bearer tsk_live_…The key needsconsent:read
Parameters
siteIdstringin pathrequiredThe site id, from GET /v1/sites.
fromstringin queryoptionalISO-8601. Inclusive lower bound on receivedAt.
tostringin queryoptionalISO-8601. Inclusive upper bound on receivedAt.
limitstringin queryoptionalRow cap. Capped by the service's own ceiling.
subjectIdstringin queryoptionalOne visitor's decision history.
Example request
curl "https://app.tagsentry.ai/api/v1/sites/3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10/consent-records" \ -H "Authorization: Bearer tsk_live_…"Response 200
dataarray of objectrequireddata[].recordVersionintegerrequireddata[].idstringrequiredDeterministic and derived, not random -- the beacon may retry, and the legal record must not double-count.
data[].subjectIdstringrequireddata[].siteIdstringrequireddata[].rulesetIntegritystringrequiredTies the decision to the exact banner configuration that was shown.
data[].jurisdictionstringrequireddata[].jurisdictionReasonstringrequiredHow we placed the visitor. A no_signal fallback is a weaker claim than a determination, and this says which it was.
data[].methodstringrequireddata[].decidedAtstringrequiredFrom the visitor's device. A CLAIM.
data[].receivedAtstringrequiredStamped by us. Authoritative for ordering and retention.
data[].grantedarray of stringrequireddata[].deniedarray of stringrequireddata[].signalsmap of stringrequiredThe Consent Mode v2 signals actually applied.
data[].shownanyrequiredWhat banner the visitor was shown.
limitintegerrequiredThe row cap applied to the underlying read.
truncatedbooleanrequiredTrue when the read came back at its cap. When true, this page is NOT the whole answer -- narrow the window. Consent records are returned oldest-first. Narrow the window with
from/to.truncationHintstringoptional
Example response
{ "data": [ { "recordVersion": 0, "id": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10", "subjectId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10", "siteId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10", "rulesetIntegrity": "…", "jurisdiction": "…", "jurisdictionReason": "…", "method": "…", "decidedAt": "2026-09-26T14:02:00.000Z", "receivedAt": "2026-09-26T14:02:00.000Z", "granted": [ "…" ], "denied": [ "…" ], "signals": { "key": "…" }, "shown": null } ], "limit": 50, "truncated": false, "truncationHint": "…"}More about this endpoint
Served from the site's own region.
These are the legal record of what each visitor was shown and what they chose. They are never edited and never deleted inside their retention period.
If truncated is true this is a PARTIAL answer -- narrow from/to and page through by time. Do not treat a truncated response as a complete history; for a regulator-facing artifact use the export endpoint, not this one.
Only for a site whose domain is verified: otherwise the answer is 403 domain_not_verified, and verifying the domain is the fix.
Errors400 · 401 · 403 · 404 · 500
400The request did not validate against this operation's schema.401Missing, malformed, unknown, revoked or expired API key. These are deliberately indistinguishable in the response -- distinguishing them would confirm to a caller that a token was once real.403The key authenticated but does not carry the scope(s) this operation requires, or (`domain_not_verified`) the site's domain is not verified, so its consent records are not released.404No such resource on this account. A site id belonging to a DIFFERENT account answers 404, never 403 -- a 403 would confirm the id exists somewhere.500Something failed on our side. The requestId in the body is what to quote.
Every error has the same body: { error: { code, message, requestId } }.
From the OpenAPI document, version 2026-08-26. Raw OpenAPI