Skip to main content
The person must accept ProofAge’s consent text before any image is uploaded, because the images are biometric data. The hosted widget does this for you; when you capture in your own UI, you show the text and record the acceptance yourself.
Until consent is recorded, POST /v1/verifications/{id}/media and POST /v1/verifications/{id}/submit answer 403 CONSENT_REQUIRED.
200 OK

2. Show the text

Show the page at url before the person accepts. Don’t summarise or paraphrase it.

3. Record the acceptance

200 OK
The hash is what proves which text the person saw: the API accepts it only if it matches the active version’s text.

Retrying

Sending the same consent_version_id and text_sha256 again answers 200 and changes nothing, so a retry after a network error is safe. The version and hash are checked first, though: if the text was replaced in the meantime, the old version answers 409 even on a verification that already has consent. Fetch GET /v1/consent again in that case.

Errors

Next steps