Python Guide

Python integration

Python 3.8+, standard-library only (urllib). Works on any Ethiopian VPS without pip install.

1. Set up the client

import json
from urllib.request import Request, urlopen

BASE = "https://api.ethiolink-consent.et"

def call(method, path, body=None, api_key=None):
    headers = {"Content-Type": "application/json"}
    if api_key:
        headers["Authorization"] = f"Bearer {api_key}"
    data = json.dumps(body).encode() if body is not None else None
    req = Request(BASE + path, data=data, headers=headers, method=method)
    try:
        with urlopen(req) as res:
            return json.loads(res.read())
    except Exception as e:
        print("HTTP error", e.code if hasattr(e, "code") else e)
        raise

2. Request consent

request = call("POST", "/api/consent/request", {
    "user_fayda_id": "FAYDA-847291",
    "purpose": "Loan eligibility assessment",
    "data_categories_requested": ["transaction_history", "mobile_money"],
    "duration_days": 30,
    # "involves_automation": True,
    # "automation_description": "A scoring model estimates eligibility.",
}, api_key=ETHIOLINK_API_KEY)

consent_id = request["request"]["public_id"]

3. Verify a token before touching data

from urllib.parse import urlencode

verdict = call("GET",
    "/api/consent/active?" + urlencode({"token": consent_token, "reason": "loan_application"}),
    api_key=ETHIOLINK_API_KEY)

assert verdict["active"], verdict["status"]  # revoked | expired | ...
if verdict.get("automation", {}).get("objection"):
    print("User objected - route to human review")

4. Retrieve encrypted data

data = call("GET",
    "/api/data/retrieve?" + urlencode({"token": consent_token, "reason": "loan_application"}),
    api_key=ETHIOLINK_API_KEY)
for t in data["transfers"]:
    print(t["source_institution"], len(t["encrypted_data"]), "bytes")

5. Webhook signature verification

import hashlib, hmac

def verify_webhook(body: dict, signature: str, timestamp: str, secret: str) -> bool:
    expected = hmac.new(
        secret.encode(), f"{timestamp}.{json.dumps(body)}".encode(),
        hashlib.sha256).hexdigest()
    return hmac.compare_digest(signature, expected)

← All guides