Buró de Crédito

Buró de Ingresos APIConsents

Create Consent

posthttps://api.burodeingresos.com/consents

Registers a consent for an identifier. Accepts an 18-char CURP (individual) or a 12-char RFC (business). The payload is the same in both cases.

A consent expires 365 days after creation. After that, POST /verifications for the identifier returns consent_expired until you create a new consent. Data from verifications already completed can still be read.


Body Params

Consent payload. Same shape for individual (18-char CURP) and business (12-char RFC) identifiers.

identifierstringrequiredlength between 12 and 18

Identifier of the data owner: 18-char CURP for individuals or 12-char RFC for businesses.

ip_addressstringrequired

IP address of the user giving consent. Must be a valid IPv4 (e.g., 192.168.2.74) or IPv6 (e.g., 2001:db8::1) address.

privacy_notice_urlurirequired

URL to the privacy notice accepted by the user.

Responses

201Consent created successfully.

iduuid

Unique identifier for the created consent.

identifierstring

The CURP (individual, 18 chars) or RFC (business, 12 chars) associated with the consent.

ip_addressstring

The IP address of the user who gave consent. Returned as either an IPv4 or IPv6 address.

privacy_notice_urluri

URL of the privacy notice accepted by the user.

created_atdate-time

Timestamp of when the consent was created.

expires_atdate-time

Timestamp of when the consent expires (365 days after creation). After it, new verifications for the identifier need a new consent; data already obtained can still be read.

400Bad Request - Invalid input parameters, such as missing required fields or invalid field values.

errorobject

401Unauthorized - Invalid or missing API key.

errorobject