> ## Documentation Index
> Fetch the complete documentation index at: https://docs.privue.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# DigiLocker consent link

> Create a link that takes a person to DigiLocker to consent to sharing their documents.

Send the person to `details.url`. Once they have given their consent, `details.request_id` reads their account through the other DigiLocker endpoints, and where `callback_url` was given the result is POSTed there as well. A consent the person has not completed has nothing to read, so read once they reach `success_redirect_url` or the result reaches `callback_url`.

Only you can read through a consent you created, and for 30 days after you created it: a `request_id` from a link you did not create, or from one created longer ago, answers `404`.



## OpenAPI

````yaml /suite/api-reference/openapi.json post /digilocker/v1/create-url.1
openapi: 3.1.0
info:
  title: Privue API Suite
  version: 1.0.0
  description: >-
    Business, tax, registry, employment and identity verification against
    official Indian sources, a person's own documents read through DigiLocker
    with their consent, and an EPF member's passbook read with the OTP they
    receive.


    **Authentication.** Every request takes your API key as a bearer token:
    `Authorization: Bearer <your-key>`.


    **One envelope.** Every check returns the reasons behind a refusal and the
    record the source held, and an empty `reasons` means the check passed.
    Branch on `reasons` rather than on the status code, because a call the
    source answered returns `200` whatever it concluded.


    **DigiLocker and EPFO passbook.** A DigiLocker endpoint returns `details`
    alone: what it read, as the source holds it. So do submitting an EPFO
    passbook OTP and reading the passbook; sending the OTP answers like a check.


    **Versioning.** Each endpoint is versioned on its own, directly in its path.
    A new version of one endpoint never moves another, so no release requires
    migrating every integration at once.
servers:
  - url: https://api.privue.ai
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Checks
    description: One check on one subject, answered in the envelope every check shares.
  - name: DigiLocker
    description: >-
      A person's own documents, read through the consent they give at
      DigiLocker.
  - name: EPFO passbook
    description: >-
      A member's EPF passbook, read with the OTP sent to the mobile number on
      their account.
  - name: Orchestrated flows
    description: Every check on one business, asked and answered together in a single call.
  - name: Usage
    description: What you have called, and when.
paths:
  /digilocker/v1/create-url.1:
    post:
      tags:
        - DigiLocker
      summary: DigiLocker consent link
      description: >-
        Create a link that takes a person to DigiLocker to consent to sharing
        their documents.


        Send the person to `details.url`. Once they have given their consent,
        `details.request_id` reads their account through the other DigiLocker
        endpoints, and where `callback_url` was given the result is POSTed there
        as well. A consent the person has not completed has nothing to read, so
        read once they reach `success_redirect_url` or the result reaches
        `callback_url`.


        Only you can read through a consent you created, and for 30 days after
        you created it: a `request_id` from a link you did not create, or from
        one created longer ago, answers `404`.
      operationId: digilocker.create-url.1
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/DigilockerUrlRequest'
              default: {}
            examples:
              consent:
                summary: Aadhaar and PAN consent, with a callback
                value:
                  signup: false
                  success_redirect_url: https://app.example.com/kyc/done
                  success_redirect_time: 5
                  failure_redirect_url: https://app.example.com/kyc/declined
                  failure_redirect_time: 5
                  doc_type:
                    - ADHAR
                    - PANCR
                  purpose: kyc
                  get_scope: true
                  internal_id: applicant-1042
                  callback_url: https://app.example.com/digilocker/callback
                  get_e_aadhaar_pdf: true
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DigilockerUrlResponse'
              examples:
                created:
                  summary: A consent link
                  value:
                    details:
                      url: >-
                        https://api.digitallocker.gov.in/public/oauth2/1/authorize?client_id=AB12CD34&code_challenge=2R4H2pVG-SmhvTDn0xQlLcPWqAvp15XUufUBbQ0Sd2I&code_challenge_method=S256&response_type=code&state=652523835a9f9000112b1ee6
                      request_id: 652523835a9f9000112b1ee6
        '401':
          description: The API key is missing, malformed or not valid.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
        '403':
          description: The key is valid but is not entitled to this feature.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
        '422':
          description: >-
            The request failed validation, or the source would not accept the
            details in it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
        '429':
          description: >-
            The key is not cleared for this feature, or is sending too many
            requests. Nothing was called.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
        '503':
          description: >-
            The source could not be reached, or authentication is temporarily
            unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
        default:
          description: The request failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuiteError'
components:
  schemas:
    DigilockerUrlRequest:
      properties:
        signup:
          anyOf:
            - type: boolean
            - type: 'null'
          title: Signup
          description: >-
            Whether a person without a DigiLocker account may create one during
            the consent. An account created this way has to be linked to its
            Aadhaar number in DigiLocker before any document can be read from
            it.
        success_redirect_url:
          anyOf:
            - type: string
              maxLength: 2083
              minLength: 1
              format: uri
            - type: 'null'
          title: Success Redirect Url
          description: Where the person is sent after giving consent
        success_redirect_time:
          anyOf:
            - type: integer
              minimum: 0
            - type: 'null'
          title: Success Redirect Time
          description: >-
            Seconds before the person is sent to `success_redirect_url`.
            Defaults to 10
        failure_redirect_url:
          anyOf:
            - type: string
              maxLength: 2083
              minLength: 1
              format: uri
            - type: 'null'
          title: Failure Redirect Url
          description: Where the person is sent when the consent is not given
        failure_redirect_time:
          anyOf:
            - type: integer
              minimum: 0
            - type: 'null'
          title: Failure Redirect Time
          description: >-
            Seconds before the person is sent to `failure_redirect_url`.
            Defaults to 10
        doc_type:
          anyOf:
            - items:
                type: string
                minLength: 1
              type: array
              minItems: 1
            - type: 'null'
          title: Doc Type
          description: >-
            The DigiLocker document types the person is asked to share, and the
            only ones the consent screen shows. Defaults to `["PANCR", "ADHAR",
            "DRVLC"]`: PAN, Aadhaar and driving licence.
          examples:
            - - ADHAR
        purpose:
          anyOf:
            - $ref: '#/components/schemas/DigilockerPurpose'
            - type: 'null'
          description: Why the person is asked for their consent
        get_scope:
          anyOf:
            - type: boolean
            - type: 'null'
          title: Get Scope
          description: Whether the callback reports what the person gave access to
        internal_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Internal Id
          description: Your own reference for this consent, carried back on the callback
        pinless_authentication:
          anyOf:
            - type: boolean
            - type: 'null'
          title: Pinless Authentication
          description: >-
            Whether the person may sign in to DigiLocker on their phone without
            a PIN
        callback_url:
          anyOf:
            - type: string
              maxLength: 2083
              minLength: 1
              format: uri
            - type: 'null'
          title: Callback Url
          description: >-
            Where the consent's result is sent, as a JSON POST, once the person
            has given it. Must be an https URL.
        persist_password:
          anyOf:
            - type: string
            - type: 'null'
          title: Persist Password
          description: A password the files read through this consent are protected with
        get_base64_files:
          anyOf:
            - type: boolean
            - type: 'null'
          title: Get Base64 Files
          description: Whether files come back as base64 in place of a download link
        get_e_aadhaar_pdf:
          anyOf:
            - type: boolean
            - type: 'null'
          title: Get E Aadhaar Pdf
          description: Whether the e-Aadhaar PDF comes back
        get_e_aadhaar_jpeg:
          anyOf:
            - type: boolean
            - type: 'null'
          title: Get E Aadhaar Jpeg
          description: Whether the e-Aadhaar JPEG comes back
      additionalProperties: false
      type: object
      title: DigilockerUrlRequest
      description: >-
        How the DigiLocker consent is presented, where the person and the result
        go, and what it returns.


        Every field is optional.
    DigilockerUrlResponse:
      properties:
        details:
          $ref: '#/components/schemas/DigilockerUrl'
          description: The consent link and its request id
      type: object
      required:
        - details
      title: DigilockerUrlResponse
      description: >-
        The DigiLocker link to send the person to, and the id their consent is
        read by.
    SuiteError:
      properties:
        code:
          type: integer
          title: Code
          description: HTTP status code of the response
        timestamp:
          type: integer
          title: Timestamp
          description: Unix millisecond timestamp of when the response was produced
        message:
          type: string
          title: Message
          description: What went wrong, in one sentence
      type: object
      required:
        - code
        - timestamp
        - message
      title: SuiteError
      description: Why a request failed.
    DigilockerPurpose:
      type: string
      enum:
        - kyc
        - verification
        - compliance
        - availing_services
        - educational
      title: DigilockerPurpose
      description: >-
        Why the person is asked for their consent, as DigiLocker shows it to
        them.
    DigilockerUrl:
      properties:
        url:
          type: string
          title: Url
          description: The DigiLocker authorization link to send the person to
        request_id:
          type: string
          title: Request Id
          description: >-
            Identifies this consent. Once the person has given it, it reads
            their documents
      type: object
      required:
        - url
        - request_id
      title: DigilockerUrl
      description: >-
        The link that takes a person to DigiLocker to consent, and the id their
        consent is read by.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Your API key, sent as `Authorization: Bearer <your-key>`.'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.