Export only policy-approved customer fields to a named recipient for a permitted purpose; enforce current notices and opt-out atomically
/customers/{id}/sharing-exportsA verified service with customers:privacy:share must match the current approved service/recipient/purpose/field grant and supply an actual-use evidence reference/hash. Current policy/election and notice/opportunity/opt-out gates are checked atomically before snapshot capture or idempotent replay. A denied result contains no data. Only approved contact fields may be returned; no tax IDs or account data. Share-only services cannot bypass this gate using operational customer reads.
Path parameters
idstringRequiredHeaders
Idempotency-KeystringRequiredSend on every write that creates or changes money or state; a replay with the same key returns the original result with 200.
Body parameters
election_versionintegerRequiredevidence_refstringRequiredevidence_sha256stringRequiredfieldsarray of stringsRequiredpolicy_idstringRequiredpurposestringRequiredrecipient_idstringRequiredrule_idstringRequiredReturns
200 OK
allowedbooleanRequiredbasisstringRequiredcustomer_idstringRequiredExample cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm
dataobjectOptionaldata_sha256stringOptionalelection_versionintegerRequiredidstringRequirednotice_idstringOptionalpolicy_idstringRequiredpolicy_versionintegerRequiredpurposestringRequiredreasonsarray of stringsRequiredrecipient_idstringRequiredrecorded_atstring · date-timeRequiredrule_idstringRequiredErrors
Every error is a problem document with a stable code. See Errors.
400401403404409412413422424429500503