All endpoints

DocsAPIConsent records

GET/sites/{siteId}/consent-records

Read consent decisions

This site's consent records, oldest first.

Auth header

Authorization: Bearer tsk_live_…

The key needsconsent:read

Parameters

  • siteIdstringin pathrequired

    The site id, from GET /v1/sites.

  • fromstringin queryoptional

    ISO-8601. Inclusive lower bound on receivedAt.

  • tostringin queryoptional

    ISO-8601. Inclusive upper bound on receivedAt.

  • limitstringin queryoptional

    Row cap. Capped by the service's own ceiling.

  • subjectIdstringin queryoptional

    One visitor's decision history.

Example request

curl "https://app.tagsentry.ai/api/v1/sites/3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10/consent-records" \  -H "Authorization: Bearer tsk_live_…"

Response 200

  • dataarray of objectrequired
  • data[].recordVersionintegerrequired
  • data[].idstringrequired

    Deterministic and derived, not random -- the beacon may retry, and the legal record must not double-count.

  • data[].subjectIdstringrequired
  • data[].siteIdstringrequired
  • data[].rulesetIntegritystringrequired

    Ties the decision to the exact banner configuration that was shown.

  • data[].jurisdictionstringrequired
  • data[].jurisdictionReasonstringrequired

    How we placed the visitor. A no_signal fallback is a weaker claim than a determination, and this says which it was.

  • data[].methodstringrequired
  • data[].decidedAtstringrequired

    From the visitor's device. A CLAIM.

  • data[].receivedAtstringrequired

    Stamped by us. Authoritative for ordering and retention.

  • data[].grantedarray of stringrequired
  • data[].deniedarray of stringrequired
  • data[].signalsmap of stringrequired

    The Consent Mode v2 signals actually applied.

  • data[].shownanyrequired

    What banner the visitor was shown.

  • limitintegerrequired

    The row cap applied to the underlying read.

  • truncatedbooleanrequired

    True when the read came back at its cap. When true, this page is NOT the whole answer -- narrow the window. Consent records are returned oldest-first. Narrow the window with from/to.

  • truncationHintstringoptional

Example response

{  "data": [    {      "recordVersion": 0,      "id": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10",      "subjectId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10",      "siteId": "3f6c1b8e-2d4a-4c7e-9a51-0b8f2e6d7c10",      "rulesetIntegrity": "…",      "jurisdiction": "…",      "jurisdictionReason": "…",      "method": "…",      "decidedAt": "2026-09-26T14:02:00.000Z",      "receivedAt": "2026-09-26T14:02:00.000Z",      "granted": [        "…"      ],      "denied": [        "…"      ],      "signals": {        "key": "…"      },      "shown": null    }  ],  "limit": 50,  "truncated": false,  "truncationHint": "…"}
More about this endpoint

Served from the site's own region.

These are the legal record of what each visitor was shown and what they chose. They are never edited and never deleted inside their retention period.

If truncated is true this is a PARTIAL answer -- narrow from/to and page through by time. Do not treat a truncated response as a complete history; for a regulator-facing artifact use the export endpoint, not this one.

Only for a site whose domain is verified: otherwise the answer is 403 domain_not_verified, and verifying the domain is the fix.

Errors400 · 401 · 403 · 404 · 500
  • 400The request did not validate against this operation's schema.
  • 401Missing, malformed, unknown, revoked or expired API key. These are deliberately indistinguishable in the response -- distinguishing them would confirm to a caller that a token was once real.
  • 403The key authenticated but does not carry the scope(s) this operation requires, or (`domain_not_verified`) the site's domain is not verified, so its consent records are not released.
  • 404No such resource on this account. A site id belonging to a DIFFERENT account answers 404, never 403 -- a 403 would confirm the id exists somewhere.
  • 500Something failed on our side. The requestId in the body is what to quote.

Every error has the same body: { error: { code, message, requestId } }.

From the OpenAPI document, version 2026-08-26. Raw OpenAPI