Python integration
Python 3.8+, standard-library only (urllib). Works
on any Ethiopian VPS without pip install.
1. Set up the client
import json
from urllib.request import Request, urlopen
BASE = "https://api.ethiolink-consent.et"
def call(method, path, body=None, api_key=None):
headers = {"Content-Type": "application/json"}
if api_key:
headers["Authorization"] = f"Bearer {api_key}"
data = json.dumps(body).encode() if body is not None else None
req = Request(BASE + path, data=data, headers=headers, method=method)
try:
with urlopen(req) as res:
return json.loads(res.read())
except Exception as e:
print("HTTP error", e.code if hasattr(e, "code") else e)
raise
2. Request consent
request = call("POST", "/api/consent/request", {
"user_fayda_id": "FAYDA-847291",
"purpose": "Loan eligibility assessment",
"data_categories_requested": ["transaction_history", "mobile_money"],
"duration_days": 30,
# "involves_automation": True,
# "automation_description": "A scoring model estimates eligibility.",
}, api_key=ETHIOLINK_API_KEY)
consent_id = request["request"]["public_id"]
3. Verify a token before touching data
from urllib.parse import urlencode
verdict = call("GET",
"/api/consent/active?" + urlencode({"token": consent_token, "reason": "loan_application"}),
api_key=ETHIOLINK_API_KEY)
assert verdict["active"], verdict["status"] # revoked | expired | ...
if verdict.get("automation", {}).get("objection"):
print("User objected - route to human review")
4. Retrieve encrypted data
data = call("GET",
"/api/data/retrieve?" + urlencode({"token": consent_token, "reason": "loan_application"}),
api_key=ETHIOLINK_API_KEY)
for t in data["transfers"]:
print(t["source_institution"], len(t["encrypted_data"]), "bytes")
5. Webhook signature verification
import hashlib, hmac
def verify_webhook(body: dict, signature: str, timestamp: str, secret: str) -> bool:
expected = hmac.new(
secret.encode(), f"{timestamp}.{json.dumps(body)}".encode(),
hashlib.sha256).hexdigest()
return hmac.compare_digest(signature, expected)