REST API
Two public endpoints, no authentication required (the siteId serves as the key). Served under your Palladium instance.
GET /api/consent/{siteId}
Returns the banner configuration (texts, colors, categories, cookies, logo). Called automatically by palladium.js on load.
Settings
| Setting | Position | Description |
|---|
Response codes
| Code | Meaning |
|---|
POST /api/consent
Records the visitor's decision. Called by palladium.js after Accept / Reject / Save.
Body
{
"siteId": "plm_a9f4e2c7b3",
"consentId": "abcd1234",
"acceptedAll": true,
"preferences": true,
"statistics": true,
"marketing": true,
"userAgent": "Mozilla/5.0 …"
}Storage
The server derives and stores:
- The timestamp and consent ID.
- A SHA-256 hash of the IP (never the raw IP).
- Anonymous geolocation (country, region, city) resolved from IP via ip-api.com — the IP is then discarded.
- The User-Agent (truncated at 500 characters).
CORS: both endpoints are open to all origins (
Access-Control-Allow-Origin: *) because the snippet must be loadable from any registered site. Origin validation is done on the received Origin, not via a CORS whitelist.