> ## Documentation Index
> Fetch the complete documentation index at: https://docs.consentfly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Consent history

> Audit trail for a consent. Counts against quota.



## OpenAPI

````yaml /openapi.yaml get /consents/{id}/history
openapi: 3.0.0
info:
  title: ConsentFly
  version: 1.1.0
  description: >
    API REST do ConsentFly para gerenciar consentimentos e evidências de
    privacidade em escala. Autentique cada chamada com `Authorization: Bearer
    sk-...` (API Key). Cada requisição bem-sucedida consome **1 unidade** da
    cota mensal do plano. Gere sua API Key em `/dashboard/api-keys`.
  contact: {}
servers:
  - url: https://www.consentfly.com.br/api/v1
    description: Produção
security:
  - ApiKeyAuth: []
tags:
  - name: Consents
    description: Capturar, listar, atualizar e auditar registros de consentimento.
  - name: DSAR
    description: >-
      Direito ao esquecimento por titular e recibo canônico para evidência
      regulatória.
  - name: Exports
    description: >-
      Exportação CSV em streaming síncrono ou via job assíncrono para volumes
      grandes.
paths:
  /consents/{id}/history:
    get:
      tags:
        - Consents
      summary: Consent history
      description: Audit trail for a consent. Counts against quota.
      parameters:
        - name: id
          in: path
          required: true
          description: Consent UUID
          schema:
            type: string
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/consents.ConsentHistoryListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '402':
          $ref: '#/components/responses/PaymentRequired'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/QuotaExceeded'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - ApiKeyAuth: []
components:
  schemas:
    consents.ConsentHistoryListResponse:
      type: object
      description: Lista de snapshots históricos do consentimento.
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/consents.ConsentHistoryDTO'
    consents.ConsentHistoryDTO:
      type: object
      description: >-
        Snapshot histórico de uma alteração no consentimento (trilha de
        auditoria).
      properties:
        id:
          type: string
          description: Identificador do snapshot histórico.
          example: 01HK8WD2QXKB4R7N9F1H3P5T0G
        consent_id:
          type: string
          description: Identificador semântico do consentimento alterado.
          example: analytics-2026-05
        accepted:
          type: boolean
          description: Estado de aceite registrado neste snapshot.
          example: false
        preferences:
          type: object
          additionalProperties:
            type: boolean
          description: Preferências por categoria neste snapshot.
          example:
            analytics: false
            marketing: false
            functional: true
        policy_version:
          type: integer
          description: Versão da política vigente no momento do snapshot.
          example: 3
        changed_by:
          type: string
          description: Origem da alteração (`banner`, `api`, `dashboard`, `system`).
          example: api
        actor_id:
          type: string
          description: >-
            Identificador do agente que executou a alteração (subject_id, API
            Key fingerprint, etc.).
          example: ak_live_a1b2c3d4
        created_at:
          type: string
          format: date-time
          description: Quando o snapshot foi gerado.
          example: '2026-05-24T11:05:42Z'
    utils.APIErrorResponse:
      type: object
      description: Envelope JSON padrão de erro da API.
      properties:
        error:
          type: string
          description: >-
            Código legível por máquina (ex. `unauthorized`, `quota_exceeded`,
            `plan_required`).
          example: unauthorized
        message:
          type: string
          description: Mensagem legível por humano. Para 5xx é genérica.
          example: Invalid or missing API key
  responses:
    Unauthorized:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/utils.APIErrorResponse'
    PaymentRequired:
      description: Plan inactive (payment required)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/utils.APIErrorResponse'
    Forbidden:
      description: Forbidden (feature gate or plan limit)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/utils.APIErrorResponse'
    NotFound:
      description: Not Found (cross-tenant access collapses to 404)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/utils.APIErrorResponse'
    QuotaExceeded:
      description: Monthly API quota exhausted
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/utils.APIErrorResponse'
    InternalError:
      description: Internal Server Error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/utils.APIErrorResponse'
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: |
        Autenticação por API Key no formato `Authorization: Bearer sk-...`
        (sempre inclua o prefixo `Bearer`).

        Gere sua chave em `/dashboard/api-keys` após criar a conta e
        verificar o e-mail. A chave é exibida **uma única vez** no momento
        da criação — armazene em variável de ambiente no seu backend.
        Nunca exponha em código client-side.

````