PHP integration
PHP 8.0+, cURL-based. A single helper class covers every endpoint.
1. Set up the client
<?php
final class EthioLink
{
private const BASE = 'https://api.ethiolink-consent.et';
public function __construct(private string $apiKey) {}
public function call(string $method, string $path, ?array $body = null): array
{
$ch = curl_init(self::BASE . $path);
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => $method,
CURLOPT_HTTPHEADER => [
'Content-Type: application/json',
'Authorization: Bearer ' . $this->apiKey,
],
CURLOPT_POSTFIELDS => $body !== null ? json_encode($body) : null,
]);
$res = curl_exec($ch);
$code = curl_getinfo($ch, CURLINFO_HTTP_CODE);
curl_close($ch);
$json = json_decode($res, true) ?? [];
if ($code >= 400) {
throw new RuntimeException($json['error']['message'] ?? 'HTTP ' . $code);
}
return $json;
}
}
2. Request consent
$el = new EthioLink($_ENV['ETHIOLINK_API_KEY']);
$request = $el->call('POST', '/api/consent/request', [
'user_fayda_id' => 'FAYDA-847291',
'purpose' => 'Loan eligibility assessment',
'data_categories_requested' => ['transaction_history', 'mobile_money'],
'duration_days' => 30,
// 'involves_automation' => true,
// 'automation_description' => 'A scoring model estimates eligibility.',
]);
$consentId = $request['request']['public_id'];
3. Verify a token before touching data
$verdict = $el->call('GET',
'/api/consent/active?token=' . urlencode($consentToken) .
'&reason=loan_application');
if (! $verdict['active']) {
throw new RuntimeException("Consent not usable: {$verdict['status']}");
}
if (($verdict['automation']['objection'] ?? false) === true) {
// Route to human review (PDPP Art. 31)
}
4. Retrieve encrypted data
$data = $el->call('GET',
'/api/data/retrieve?token=' . urlencode($consentToken) .
'&reason=loan_application');
foreach ($data['transfers'] as $t) {
echo $t['source_institution'], ' ', strlen($t['encrypted_data']), " bytes\n";
}
5. Webhook signature verification
function verify_webhook(string $payload, string $sig, string $ts, string $secret): bool
{
$expected = hash_hmac('sha256', $ts . '.' . $payload, $secret);
return hash_equals($expected, $sig);
}