Skip to main content

consent

Check the status of a consent request

Also known as: Consent Request Status. Checks the current status of a previously initiated consent request. Can be polled periodically while awaiting patient action.

MandatoryAny one of them is mandatory

Certification cases HIU_FLOW_101, HIU_FLOW_102, HIU_FLOW_103, HIU_FLOW_104, HIU_FLOW_105, HIU_FLOW_106, HIU_FLOW_107, HIU_FLOW_108, HIU_FLOW_109, HIU_FLOW_110, HIU_FLOW_111, HIU_FLOW_112, HIU_FLOW_113

POST/hiecm/consent/v3/request/status

Status values: - REQUESTED, Awaiting patient action - GRANTED, Patient approved; consentArtefacts array will contain artefact IDs - DENIED, Patient denied the request - EXPIRED, Request timed out without patient action - REVOKED, Previously granted consent was revoked by the patient

Authorizations

Authorizationbearer tokenRequired

Bearer token obtained from POST /hiecm/gateway/v3/sessions

Headers

REQUEST-IDstringRequired

A fresh UUID that you generate for this request. The callback that answers it carries the same value. In M3 a single consent can produce several callbacks, so keep the mapping from request id to consent request id rather than relying on ordering.

TIMESTAMPstringRequired

The current time in ISO 8601 UTC, with milliseconds and the Z suffix. The gateway rejects a request whose timestamp has drifted too far from its own clock, so take this from a synchronised clock rather than from a local one.

X-CM-IDstringRequired

Which consent manager you are talking to. sbx on the sandbox and abdm in production.

X-HIU-IDstringRequired

Identifier of the health information user the request or callback is intended for. This is per facility, and it is what a callback arriving at your one bridge URL is routed on. The bridge URL and your credentials belong to the integration, not to the facility.

Body

consentRequestIdstringRequired

ID returned from the consent init call

Responses

200

Consent request status

400

Bad request, invalid parameters or missing fields

Error codes for this module

401

Unauthorized, missing or invalid Bearer token

Everything returns 401

Callbacks

  • After this call, ABDM posts The consent manager reports the state of a consent request you asked about. to /api/v3/hiu/consent/request/on-status. Open the callback.