REAL-TIME DATA PIPELINE

Signed webhooks for every consent event.

Stream consent grants, withdrawals, and citizen rights requests directly into your AWS S3 bucket, Snowflake warehouse, or CRM in real time. Every payload is HMAC-SHA256 signed with replay-proof timestamps.

SIGNATURE SCHEME
HMAC-SHA256 & Ed25519

Cryptographically verify origin authenticity on every incoming request with standard timing-safe comparisons.

DELIVERY GUARANTEE
At-Least-Once Delivery

Automatic exponential backoff retries across 72 hours with full HTTP payload preservation in your DLQ.

DATA SOVEREIGNTY
Your Private Data Lake

We store pseudonymous consent records only. Full downstream event logs stream straight into your private cloud.

SYSTEM GUARANTEES

Engineered for mission-critical ingestion.

Zero data loss, strict replay prevention, and seamless integration with existing data warehouses.

INTEGRITY GUARANTEE

Cryptographic Signature Verification

Every webhook request carries an X-ConsentPlix-Signature header containing an HMAC-SHA256 signature computed using your secret signing key. Replay attacks are rejected via timestamp validation.

STREAMING ARCHITECTURE

At-Least-Once Guaranteed Delivery

Failed endpoints trigger exponential backoff retries across 72 hours. Dead-letter queues (DLQ) preserve failed attempts for manual redelivery with full HTTP trace history.

PRIVATE INFRASTRUCTURE

Direct S3, BigQuery & Snowflake Sync

Stream consent signals straight into your own cloud data warehouse. We store zero customer profiles; your team retains 100% of the operational intelligence.

DEVELOPER EXPERIENCE

Local CLI Testing & Webhook Sandbox

Simulate consent grants, rights revocations, and SLA alerts locally using the ConsentPlix CLI or trigger signed test payloads directly from the developer dashboard.

EVENT CATALOG

Structured statutory event catalog.

Select an event to inspect its canonical JSON payload schema, statutory parameters, and signature header commitment.

PAYLOAD SCHEMA: consent.granted
application/json
{
  "event": "consent.granted",
  "receipt_id": "rcpt_7f3a91e4b82c",
  "subject_token": "sub_8f9c2a014e7b",
  "jurisdiction": "IN_DPDP",
  "purposes": {
    "analytics_storage": true,
    "ad_storage": true,
    "functional": true
  },
  "notice_version": "v2.1",
  "notice_hash": "sha256:d8a1c4...",
  "timestamp": "2026-10-08T10:42:00Z",
  "signature": "hmac_sha256:9f8e7d..."
}
Verified against KMS Hardware Security ModulesHMAC-SHA256 ACTIVE
INTEGRATION RECIPES

Cryptographic verification in 5 lines.

Node.js / Express — Signature Verifier
import express from 'express';
import crypto from 'crypto';

const app = express();
const WEBHOOK_SECRET = process.env.CONSENTPLIX_WEBHOOK_SECRET!;

// 1. Ingest raw body for cryptographic signature verification
app.post('/api/webhooks/consent', express.raw({ type: 'application/json' }), (req, res) => {
  const signature = req.headers['x-consentplix-signature'] as string;
  const timestamp = req.headers['x-consentplix-timestamp'] as string;

  // 2. Reject payloads older than 5 minutes to prevent replay attacks
  if (Math.abs(Date.now() / 1000 - parseInt(timestamp, 10)) > 300) {
    return res.status(400).send('Timestamp out of bounds');
  }

  // 3. Compute expected HMAC-SHA256 signature
  const hmac = crypto.createHmac('sha256', WEBHOOK_SECRET);
  const digest = hmac.update(`${timestamp}.${req.body.toString('utf8')}`).digest('hex');

  if (crypto.timingSafeEqual(Buffer.from(signature), Buffer.from(digest))) {
    const event = JSON.parse(req.body.toString('utf8'));
    
    // 4. Update internal downstream pipelines (e.g. CRM, Tag Managers)
    if (event.event === 'consent.withdrawn') {
      console.log(`Quarantine tracking for: ${event.subject_token}`);
    }

    return res.status(200).json({ received: true });
  }

  return res.status(401).send('Invalid cryptographic signature');
});
FREQUENTLY ASKED QUESTIONS

Webhook architecture FAQ.

How does ConsentPlix prevent webhook spoofing and replay attacks?

Every webhook payload includes two headers: X-ConsentPlix-Signature and X-ConsentPlix-Timestamp. The signature is computed using HMAC-SHA256 across the concatenated timestamp and raw body. Consumers reject payloads where the timestamp drift exceeds 300 seconds, completely nullifying replay attacks.

What happens if our receiver endpoint goes down?

Our webhook delivery engine provides at-least-once guaranteed delivery. If your server returns a non-2xx status code or times out after 10 seconds, the delivery enters an exponential backoff retry loop (attempting delivery after 1m, 5m, 15m, 1h, 6h, up to 72 hours). Failed deliveries are preserved in your dashboard Dead-Letter Queue (DLQ).

Can we stream consent records directly to Amazon S3 or Google Cloud Storage?

Yes. In addition to HTTP endpoints, ConsentPlix supports direct serverless data streams into AWS S3, Google Cloud Storage, or Snowflake stages, buffering records in parquet or newline-delimited JSON formats with hourly rotation.

Does the webhook payload include customer personal identifiable information (PII)?

No. ConsentPlix is architected with a strict zero-customer-PII policy. Webhook payloads contain pseudonymous subject tokens, itemized statutory purpose grants, notice version hashes, and cryptographic signatures. Your customer identity data stays exclusively in your own database.

REAL-TIME DATA PIPELINES

Stream consent events to your warehouse this week.

Schedule a 30-minute integration walkthrough or explore our developer documentation to set up your Ed25519 webhook receiver.