Inth Subjects API
The Subjects API from Inth — 2 operation(s) for subjects.
The Subjects API from Inth — 2 operation(s) for subjects.
openapi: 3.1.0
info:
title: c15t Backend Consent Subjects API
version: 2.1.0
description: REST API for the c15t consent backend (@c15t/backend) that powers the c15t cookie banner, consent manager, and preference center. The same API runs whether self-hosted or used through the Inth (inth.com) managed platform. This specification was DERIVED faithfully from the published open-source Hono route handlers in packages/backend of github.com/c15t/c15t (the live runtime spec is generated by hono-openapi and served at /spec.json). Requests are authenticated with a Bearer API key; a subset of endpoints are public (init/status) and are called directly by the browser SDK.
contact:
name: c15t
url: https://c15t.com/docs/self-host
license:
name: GPL-3.0
url: https://github.com/c15t/c15t/blob/main/LICENSE.md
servers:
- url: https://your-instance.c15t.dev
description: Hosted c15t backend instance (per-tenant subdomain). Self-hosted deployments mount the same routes under a configurable basePath (e.g. /api/c15t).
security:
- bearerAuth: []
tags:
- name: Subjects
paths:
/subjects:
get:
tags:
- Subjects
operationId: listSubjects
summary: List subjects by external ID (API key required)
responses:
'200':
description: A list of subjects.
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/Subject'
'401':
$ref: '#/components/responses/Problem'
post:
tags:
- Subjects
operationId: recordConsent
summary: Record consent for a subject
requestBody:
required: true
content:
application/json:
schema:
type: object
responses:
'200':
description: Consent recorded.
content:
application/json:
schema:
$ref: '#/components/schemas/Consent'
'400':
$ref: '#/components/responses/Problem'
'422':
$ref: '#/components/responses/Problem'
/subjects/{id}:
get:
tags:
- Subjects
operationId: getSubject
summary: Get subject consent status
parameters:
- name: id
in: path
required: true
schema:
type: string
responses:
'200':
description: Subject consent status.
content:
application/json:
schema:
$ref: '#/components/schemas/Subject'
'404':
$ref: '#/components/responses/Problem'
patch:
tags:
- Subjects
operationId: linkSubjectExternalId
summary: Link external ID to subject
parameters:
- name: id
in: path
required: true
schema:
type: string
requestBody:
required: true
content:
application/json:
schema:
type: object
responses:
'200':
description: External ID linked.
content:
application/json:
schema:
$ref: '#/components/schemas/Subject'
'400':
$ref: '#/components/responses/Problem'
'404':
$ref: '#/components/responses/Problem'
components:
schemas:
Error:
type: object
properties:
error:
type: string
message:
type: string
code:
type: string
Subject:
type: object
description: A data subject (end user) whose consent is tracked. IDs are prefixed `sub_`.
properties:
id:
type: string
example: sub_1a2b3c
externalId:
type: string
nullable: true
identityProvider:
type: string
nullable: true
tenantId:
type: string
nullable: true
Consent:
type: object
description: A consent record. IDs are prefixed `cns_`.
properties:
id:
type: string
example: cns_1a2b3c
subjectId:
type: string
domainId:
type: string
policyId:
type: string
responses:
Problem:
description: Error response.
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
securitySchemes:
bearerAuth:
type: http
scheme: bearer
description: 'API key passed as a Bearer token in the Authorization header (e.g. `Authorization: Bearer sk_live_...`). Public endpoints (init, status) require no credential.'