Signed webhooks for every consent event.
Stream consent grants, withdrawals, and citizen rights requests directly into your AWS S3 bucket, Snowflake warehouse, or CRM in real time. Every payload is HMAC-SHA256 signed with replay-proof timestamps.
Cryptographically verify origin authenticity on every incoming request with standard timing-safe comparisons.
Automatic exponential backoff retries across 72 hours with full HTTP payload preservation in your DLQ.
We store pseudonymous consent records only. Full downstream event logs stream straight into your private cloud.
Engineered for mission-critical ingestion.
Zero data loss, strict replay prevention, and seamless integration with existing data warehouses.
Cryptographic Signature Verification
Every webhook request carries an X-ConsentPlix-Signature header containing an HMAC-SHA256 signature computed using your secret signing key. Replay attacks are rejected via timestamp validation.
At-Least-Once Guaranteed Delivery
Failed endpoints trigger exponential backoff retries across 72 hours. Dead-letter queues (DLQ) preserve failed attempts for manual redelivery with full HTTP trace history.
Direct S3, BigQuery & Snowflake Sync
Stream consent signals straight into your own cloud data warehouse. We store zero customer profiles; your team retains 100% of the operational intelligence.
Local CLI Testing & Webhook Sandbox
Simulate consent grants, rights revocations, and SLA alerts locally using the ConsentPlix CLI or trigger signed test payloads directly from the developer dashboard.
Structured statutory event catalog.
Select an event to inspect its canonical JSON payload schema, statutory parameters, and signature header commitment.
{
"event": "consent.granted",
"receipt_id": "rcpt_7f3a91e4b82c",
"subject_token": "sub_8f9c2a014e7b",
"jurisdiction": "IN_DPDP",
"purposes": {
"analytics_storage": true,
"ad_storage": true,
"functional": true
},
"notice_version": "v2.1",
"notice_hash": "sha256:d8a1c4...",
"timestamp": "2026-10-08T10:42:00Z",
"signature": "hmac_sha256:9f8e7d..."
}Cryptographic verification in 5 lines.
import express from 'express';
import crypto from 'crypto';
const app = express();
const WEBHOOK_SECRET = process.env.CONSENTPLIX_WEBHOOK_SECRET!;
// 1. Ingest raw body for cryptographic signature verification
app.post('/api/webhooks/consent', express.raw({ type: 'application/json' }), (req, res) => {
const signature = req.headers['x-consentplix-signature'] as string;
const timestamp = req.headers['x-consentplix-timestamp'] as string;
// 2. Reject payloads older than 5 minutes to prevent replay attacks
if (Math.abs(Date.now() / 1000 - parseInt(timestamp, 10)) > 300) {
return res.status(400).send('Timestamp out of bounds');
}
// 3. Compute expected HMAC-SHA256 signature
const hmac = crypto.createHmac('sha256', WEBHOOK_SECRET);
const digest = hmac.update(`${timestamp}.${req.body.toString('utf8')}`).digest('hex');
if (crypto.timingSafeEqual(Buffer.from(signature), Buffer.from(digest))) {
const event = JSON.parse(req.body.toString('utf8'));
// 4. Update internal downstream pipelines (e.g. CRM, Tag Managers)
if (event.event === 'consent.withdrawn') {
console.log(`Quarantine tracking for: ${event.subject_token}`);
}
return res.status(200).json({ received: true });
}
return res.status(401).send('Invalid cryptographic signature');
});Webhook architecture FAQ.
How does ConsentPlix prevent webhook spoofing and replay attacks?
Every webhook payload includes two headers: X-ConsentPlix-Signature and X-ConsentPlix-Timestamp. The signature is computed using HMAC-SHA256 across the concatenated timestamp and raw body. Consumers reject payloads where the timestamp drift exceeds 300 seconds, completely nullifying replay attacks.
What happens if our receiver endpoint goes down?
Our webhook delivery engine provides at-least-once guaranteed delivery. If your server returns a non-2xx status code or times out after 10 seconds, the delivery enters an exponential backoff retry loop (attempting delivery after 1m, 5m, 15m, 1h, 6h, up to 72 hours). Failed deliveries are preserved in your dashboard Dead-Letter Queue (DLQ).
Can we stream consent records directly to Amazon S3 or Google Cloud Storage?
Yes. In addition to HTTP endpoints, ConsentPlix supports direct serverless data streams into AWS S3, Google Cloud Storage, or Snowflake stages, buffering records in parquet or newline-delimited JSON formats with hourly rotation.
Does the webhook payload include customer personal identifiable information (PII)?
No. ConsentPlix is architected with a strict zero-customer-PII policy. Webhook payloads contain pseudonymous subject tokens, itemized statutory purpose grants, notice version hashes, and cryptographic signatures. Your customer identity data stays exclusively in your own database.
Stream consent events to your warehouse this week.
Schedule a 30-minute integration walkthrough or explore our developer documentation to set up your Ed25519 webhook receiver.