REST API

Two public endpoints, no authentication required (the siteId serves as the key). Served under your Palladium instance.

GET /api/consent/{siteId}

Returns the banner configuration (texts, colors, categories, cookies, logo). Called automatically by palladium.js on load.

Settings

siteIdPathDomain identifier.langQuery (optional)Visitor's preferred BCP-47 code.Accept-LanguageHeaderUsed as fallback if lang is absent.
SettingPositionDescription

Response codes

200Configuration served.404 site_not_foundUnknown siteId.403 domain_pausedDomain paused in the console.403 origin_mismatchRequest hostname ≠ registered one.429Rate limit reached (60 req/min/IP).
CodeMeaning

POST /api/consent

Records the visitor's decision. Called by palladium.js after Accept / Reject / Save.

Body

{
  "siteId":      "plm_a9f4e2c7b3",
  "consentId":   "abcd1234",
  "acceptedAll": true,
  "preferences": true,
  "statistics":  true,
  "marketing":   true,
  "userAgent":   "Mozilla/5.0 …"
}

Storage

The server derives and stores:

  • The timestamp and consent ID.
  • A SHA-256 hash of the IP (never the raw IP).
  • Anonymous geolocation (country, region, city) resolved from IP via ip-api.com — the IP is then discarded.
  • The User-Agent (truncated at 500 characters).
CORS: both endpoints are open to all origins (Access-Control-Allow-Origin: *) because the snippet must be loadable from any registered site. Origin validation is done on the received Origin, not via a CORS whitelist.