Get your users' consent
Consent applies to the cloud API only.
You need end-user consent to verify a document with the cloud API.
Every request to /api/v3/verify must carry a consent part.
If it's missing, the request is rejected and no verification is performed.
Consent is scoped to an end user and to a duration, not to a single request.
You declare who gave consent (userId) and how long it's valid (durationDays), and each request registers a consent record against that user.
Structure
Consent is defined as the following structure:
{
"userId": "<your-id-for-the-end-user>",
"durationDays": 365,
"givenOn": "2026-07-31T09:00:00Z",
"note": "User agreed to identity verification terms.",
"customerContext": {
"customerId": "<your-customer-id>",
"transactionId": "<your-transaction-id>"
}
}
Two fields are required:
userId: Your own unique identifier for the end user granting the consent. This is the field that ties consent records to a person in your system, so keep it stable across requests for the same end user.durationDays: How long the consent stays valid. The expiry date is calculated from it, so pick a duration that matches the retention period stated in your own privacy notice.
The rest are optional:
givenOn: When the end user granted the consent.note: The consent statement, agreement text, or notes associated with the consent. Use it to record what the end user actually agreed to.customerContext.customerId: Your own identifier for the customer entity the consent belongs to.customerContext.transactionId: Your own identifier for the transaction the consent was collected for.
Submit the consent
Send the consent as a text form value named consent, containing the JSON object.
Unlike configuration, it can't be sent as a file part.
- cURL
- JavaScript
- Python
- Go
curl https://us-east.verify.microblink.com/api/v3/verify \
--request POST \
--header 'Authorization: Basic <credentials>' \
--form 'imageFirstSide=@front_id.jpg' \
--form 'imageSecondSide=@back_id.png' \
--form 'consent={
"userId": "<your-id-for-the-end-user>",
"durationDays": 365
}'
const formData = new FormData()
formData.append('imageFirstSide', new Blob([]), 'front_id.jpg')
formData.append('imageSecondSide', new Blob([]), 'back_id.png')
formData.append('consent', '{
"userId": "<your-id-for-the-end-user>",
"durationDays": 365
}')
fetch('https://us-east.verify.microblink.com/api/v3/verify', {
method: 'POST',
headers: {
Authorization: 'Basic <credentials>'
},
body: formData
})
requests.post(
"https://us-east.verify.microblink.com/api/v3/verify",
headers={
"Authorization": "Basic <credentials>"
},
files=[
("imageFirstSide", open("front_id.jpg", "rb")),
("imageSecondSide", open("back_id.png", "rb"))
],
data={
"consent": "{\n \"userId\": \"<your-id-for-the-end-user>\",\n \"durationDays\": 365\n}"
}
)
package main
import (
"bytes"
"fmt"
"io"
"mime/multipart"
"net/http"
"os"
)
func main() {
requestUrl := "https://us-east.verify.microblink.com/api/v3/verify"
payload := &bytes.Buffer{}
writer := multipart.NewWriter(payload)
part, _ := writer.CreateFormFile("imageFirstSide", "front_id.jpg")
f, _ := os.Open("front_id.jpg")
defer f.Close()
_, _ = io.Copy(part, f)
part, _ = writer.CreateFormFile("imageSecondSide", "back_id.png")
f, _ = os.Open("back_id.png")
defer f.Close()
_, _ = io.Copy(part, f)
_ = writer.WriteField("consent", "{\n \"userId\": \"<your-id-for-the-end-user>\",\n \"durationDays\": 365\n}")
writer.Close()
req, _ := http.NewRequest("POST", requestUrl, payload)
req.Header.Set("Content-Type", writer.FormDataContentType())
req.Header.Add("Authorization", "Basic <credentials>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(res)
fmt.Println(string(body))
}
Code examples here use the us-east region.
Use the appropriate region for your deployment.