Consent Receipt
v0.1.0The payload of a consent receipt (spec §9.3): a signed, self-contained assertion about one consent record, issued by the capturing party to one named relying party. The receipt itself is a JWS in compact serialization (RFC 7515), signed with an asymmetric algorithm (ES256 MUST be supported, 'none' MUST NOT be accepted); this schema describes the claims inside it. Claims follow §9.3.1, which remains the normative definition. Timestamps are JWT NumericDate values (seconds since the Unix epoch), not RFC 3339 strings, because the payload is a JWS claim set. A receipt is a statement about consent, not a grant of access or an authentication credential. Resources: consent.get_receipt, consent.verify_receipt, consent.report_revocation.
consent.get_receiptconsent.verify_receiptconsent.report_revocation{
"iss": "https://crm.example-vendor.com",
"sub": "+15125550143",
"aud": "https://scheduler.other-vendor.com",
"iat": 1786032000,
"exp": 1786035600,
"jti": "rcpt_01J9F2K8QW",
"cnsnt_id": "cns_7Yb3",
"channel": "sms",
"purpose": "marketing",
"status": "granted",
"granted_at": 1785945600,
"method": "web_form",
"disclosure_hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
"disclosure_uri": "https://crm.example-vendor.com/disclosures/sms-marketing/v4",
"status_uri": "https://crm.example-vendor.com/consent/status/cns_7Yb3",
"evidence_uri": "https://crm.example-vendor.com/consent/evidence/cns_7Yb3",
"expires_at": 1817481600
}This schema is served at its $id: https://automotivemcp.ai/schemas/consent/consent-receipt.json. All 26 are listed in /schemas/index.json.