Corgi BankDocumentation
OpenAPI

Export only policy-approved customer fields to a named recipient for a permitted purpose; enforce current notices and opt-out atomically

POST/customers/{id}/sharing-exports

A verified service with customers:privacy:share must match the current approved service/recipient/purpose/field grant and supply an actual-use evidence reference/hash. Current policy/election and notice/opportunity/opt-out gates are checked atomically before snapshot capture or idempotent replay. A denied result contains no data. Only approved contact fields may be returned; no tax IDs or account data. Share-only services cannot bypass this gate using operational customer reads.

Path parameters

idstringRequired

Headers

Idempotency-KeystringRequired

Send on every write that creates or changes money or state; a replay with the same key returns the original result with 200.

Body parameters

election_versionintegerRequired
evidence_refstringRequired
evidence_sha256stringRequired
fieldsarray of stringsRequired
policy_idstringRequired
purposestringRequired
recipient_idstringRequired
rule_idstringRequired

Returns

200 OK

allowedbooleanRequired
basisstringRequired
customer_idstringRequired

Example cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm

dataobjectOptional
data_sha256stringOptional
election_versionintegerRequired
idstringRequired
notice_idstringOptional
policy_idstringRequired
policy_versionintegerRequired
purposestringRequired
reasonsarray of stringsRequired
recipient_idstringRequired
recorded_atstring · date-timeRequired
rule_idstringRequired

Errors

Every error is a problem document with a stable code. See Errors.

400401403404409412413422424429500503

to move to open esc to close