Buró de Ingresos APIConsents
Create Consent
posthttps://api.burodeingresos.com/consents
Registers a consent for an identifier. Accepts an 18-char CURP (individual) or a 12-char RFC (business). The payload is the same in both cases.
A consent expires 365 days after creation. After that, POST /verifications for the identifier returns consent_expired until you create a new consent. Data from verifications already completed can still be read.
Body Params
Consent payload. Same shape for individual (18-char CURP) and business (12-char RFC) identifiers.
identifierstringrequiredlength between 12 and 18
Identifier of the data owner: 18-char CURP for individuals or 12-char RFC for businesses.
ip_addressstringrequired
IP address of the user giving consent. Must be a valid IPv4 (e.g., 192.168.2.74) or IPv6 (e.g., 2001:db8::1) address.
privacy_notice_urlurirequired
URL to the privacy notice accepted by the user.
Responses
201Consent created successfully.
iduuid
Unique identifier for the created consent.
identifierstring
The CURP (individual, 18 chars) or RFC (business, 12 chars) associated with the consent.
ip_addressstring
The IP address of the user who gave consent. Returned as either an IPv4 or IPv6 address.
privacy_notice_urluri
URL of the privacy notice accepted by the user.
created_atdate-time
Timestamp of when the consent was created.
expires_atdate-time
Timestamp of when the consent expires (365 days after creation). After it, new verifications for the identifier need a new consent; data already obtained can still be read.
400Bad Request - Invalid input parameters, such as missing required fields or invalid field values.
errorobject
401Unauthorized - Invalid or missing API key.
errorobject
