PHP Guide

PHP integration

PHP 8.0+, cURL-based. A single helper class covers every endpoint.

1. Set up the client

<?php
final class EthioLink
{
    private const BASE = 'https://api.ethiolink-consent.et';

    public function __construct(private string $apiKey) {}

    public function call(string $method, string $path, ?array $body = null): array
    {
        $ch = curl_init(self::BASE . $path);
        curl_setopt_array($ch, [
            CURLOPT_RETURNTRANSFER => true,
            CURLOPT_CUSTOMREQUEST  => $method,
            CURLOPT_HTTPHEADER     => [
                'Content-Type: application/json',
                'Authorization: Bearer ' . $this->apiKey,
            ],
            CURLOPT_POSTFIELDS => $body !== null ? json_encode($body) : null,
        ]);
        $res = curl_exec($ch);
        $code = curl_getinfo($ch, CURLINFO_HTTP_CODE);
        curl_close($ch);
        $json = json_decode($res, true) ?? [];
        if ($code >= 400) {
            throw new RuntimeException($json['error']['message'] ?? 'HTTP ' . $code);
        }
        return $json;
    }
}

2. Request consent

$el = new EthioLink($_ENV['ETHIOLINK_API_KEY']);
$request = $el->call('POST', '/api/consent/request', [
    'user_fayda_id'               => 'FAYDA-847291',
    'purpose'                     => 'Loan eligibility assessment',
    'data_categories_requested'   => ['transaction_history', 'mobile_money'],
    'duration_days'               => 30,
    // 'involves_automation'      => true,
    // 'automation_description'   => 'A scoring model estimates eligibility.',
]);
$consentId = $request['request']['public_id'];

3. Verify a token before touching data

$verdict = $el->call('GET',
    '/api/consent/active?token=' . urlencode($consentToken) .
    '&reason=loan_application');

if (! $verdict['active']) {
    throw new RuntimeException("Consent not usable: {$verdict['status']}");
}
if (($verdict['automation']['objection'] ?? false) === true) {
    // Route to human review (PDPP Art. 31)
}

4. Retrieve encrypted data

$data = $el->call('GET',
    '/api/data/retrieve?token=' . urlencode($consentToken) .
    '&reason=loan_application');
foreach ($data['transfers'] as $t) {
    echo $t['source_institution'], ' ', strlen($t['encrypted_data']), " bytes\n";
}

5. Webhook signature verification

function verify_webhook(string $payload, string $sig, string $ts, string $secret): bool
{
    $expected = hash_hmac('sha256', $ts . '.' . $payload, $secret);
    return hash_equals($expected, $sig);
}

← All guides