Ga naar inhoud

Share evidence with the authority

POST
/api/v1/evidence/disclosures
curl --request POST \
--url https://example.com/api/v1/evidence/disclosures \
--header 'Content-Type: application/json' \
--cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E \
--data '{ "process_id": "example", "recipient": "example", "reason": "example", "consent": true }'

Sends the evidence bundle of a process, with the consent and the reason, to the authority, for example in a dispute. Anchors first, so the bundle carries an independent timestamp. Recorded as evidence.

Media typeapplication/json
object
process_id
required
string
recipient

Only authority, the default.

string
reason
required

Why the evidence is shared; at least 5 characters.

string
consent
required

Must be true: explicit consent to share.

boolean

Example generated

{
"process_id": "example",
"recipient": "example",
"reason": "example",
"consent": true
}

OK.

Media typeapplication/json
object
id
required
string
remote_id

The id at the authority.

string | null
process_id
required
string
recipient
required

The DID of the recipient.

string
reason
required
string
given_by
required
string
shared_at
required
string format: date-time

Example generated

{
"id": "example",
"remote_id": "example",
"process_id": "example",
"recipient": "example",
"reason": "example",
"given_by": "example",
"shared_at": "2026-04-15T12:00:00Z"
}

No consent, another recipient, or no reason.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

No valid session, DPoP-bound token or API key.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The authority could not be reached or refused.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}