PageSourceSearch

https://plaid.com/_next/static/chunks/pages/core-exchange/docs/consent-management-fce432ef0a7a222d.js

js plaid.com collected 2026-09-24 07:18:38 UTC 9,063 bytes, 2 lines download raw bytes

1try{let e="undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof globalThis?globalThis:"undefined"!=typeof self?self:{},t=(new e.Error).stack;t&&(e._sentryDebugIds=e._sentryDebugIds||{},e._sentryDebugIds[t]="dbbdcc1a-b7a1-4fb4-ae82-0f3a0c28df5b",e._sentryDebugIdIdentifier="sentry-dbid-dbbdcc1a-b7a1-4fb4-ae82-0f3a0c28df5b")}catch(e){}(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[64702],{60144:function(e,t,a){"use strict";a.r(t),a.d(t,{default:function(){return k},metadata:function(){return d},tableOfContents:function(){return f}});var n=a(36864),o=a(4730);a(67294);var r=a(3905),s=a(47608),i=a(43402),c=a.n(i),l=["components"],d={toc:!0,subnav:!0,title:"Consent management",layout:"guide",description:"Manage user consent and access authorization records",parentTocLevel:2,childTocLevel:3,secondLevelToc:!0,alwaysExpand:!0},p=function(e){return function(t){return console.warn("Component "+e+" was not imported, exported, or provided by MDXProvider as global scope"),(0,r.kt)("div",t)}},u=p("Header"),m=p("Callout"),h=p("Image"),g={metadata:d};function k(e){var t=e.components,a=(0,o.Z)(e,l);return(0,r.kt)("wrapper",(0,n.Z)({},g,a,{components:t,mdxType:"MDXLayout"}),(0,r.kt)("div",{className:c().page},(0,r.kt)(u,{title:"Consent management",subtitle:d.description,mdxType:"Header"}),(0,r.kt)("h2",{id:"overview"},"Overview"),(0,r.kt)("p",null,"Plaid provides the ability to view authorization records and manage consent through the ",(0,r.kt)("a",{parentName:"p",href:"/core-exchange/docs/consent-management/api"},"Consent API")," and the Data Partner Dashboard. Using these tools, you can build a customer-facing consent management dashboard as well as audit and review consent records. "),(0,r.kt)("h2",{id:"authorization-records"},"Authorization records"),(0,r.kt)("p",null,"An authorization record captures the full context of a user's consent:"),(0,r.kt)("ul",null,(0,r.kt)("li",{parentName:"ul"},(0,r.kt)("strong",{parentName:"li"},"Application details:")," Which app has access (name, ID, logo)"),(0,r.kt)("li",{parentName:"ul"},(0,r.kt)("strong",{parentName:"li"},"Accounts shared:")," Specific accounts the user authorized"),(0,r.kt)("li",{parentName:"ul"},(0,r.kt)("strong",{parentName:"li"},"Data types:")," What data the app can access (transactions, balances, identity, etc.)"),(0,r.kt)("li",{parentName:"ul"},(0,r.kt)("strong",{parentName:"li"},"Consent timestamp:")," When the user granted authorization"),(0,r.kt)("li",{parentName:"ul"},(0,r.kt)("strong",{parentName:"li"},"Connection status:")," Active, revoked, or expired")),(0,r.kt)("h3",{id:"accessing-authorization-records"},"Accessing authorization records"),(0,r.kt)("table",null,(0,r.kt)("thead",{parentName:"table"},(0,r.kt)("tr",{parentName:"thead"},(0,r.kt)("th",{parentName:"tr",align:null},"Method"),(0,r.kt)("th",{parentName:"tr",align:null},"Best for"),(0,r.kt)("th",{parentName:"tr",align:null},"Availability"))),(0,r.kt)("tbody",{parentName:"table"},(0,r.kt)("tr",{parentName:"tbody"},(0,r.kt)("td",{parentName:"tr",align:null},(0,r.kt)("strong",{parentName:"td"},(0,r.kt)("a",{parentName:"strong",href:"/core-exchange/docs/consent-management/api"},"Consent API"))),(0,r.kt)("td",{parentName:"tr",align:null},"Automated systems, high volume"),(0,r.kt)("td",{parentName:"tr",align:null},"All integration models")),(0,r.kt)("tr",{parentName:"tbody"},(0,r.kt)("td",{parentName:"tr",align:null},(0,r.kt)("strong",{parentName:"td"},"Data Partner Dashboard")),(0,r.kt)("td",{parentName:"tr",align:null},"Manual review, low volume"),(0,r.kt)("td",{parentName:"tr",align:null},"Single institution only")))),(0,r.kt)(m,{mdxType:"Callout"},(0,r.kt)("p",null,"The no-code Dashboard interface is only available for single-institution accounts. Platform accounts must use the ",(0,r.kt)("a",{parentName:"p",href:"/core-exchange/docs/consent-management/api"},"Consent API"),".")),(0,r.kt)("h3",{id:"consent-api-beta"},"Consent API (beta)"),(0,r.kt)("p",null,"Build a consumer-facing consent portal, answer support requests about a customer's connections, and revoke access programmatically. Because it follows the FDX consent grant model, the ",(0,r.kt)("a",{parentName:"p",href:"/core-exchange/docs/consent-management/api"},"Consent API")," allows you to build an integration supporting multiple data access platforms, rather than locking you into a Plaid-specific schema."),(0,r.kt)(m,{mdxType:"Callout"},(0,r.kt)("p",null,"The Consent API is currently in beta. To request access, contact Plaid solutions engineering. Note that the no-code Dashboard does not currently support the Consent API; if using both surfaces, you may see inconsistent data across the two.")),(0,r.kt)("p",null,"See the ",(0,r.kt)("a",{parentName:"p",href:"/core-exchange/docs/consent-management/api"},"Consent API reference")," for endpoints, request and response fields, data clusters, webhooks, and Sandbox testing."),(0,r.kt)("p",null,"The ",(0,r.kt)("a",{parentName:"p",href:"/core-exchange/docs/consent-management/permissions-manager"},"Permissions Manager API")," is the legacy, Plaid-proprietary predecessor to the ",(0,r.kt)("a",{parentName:"p",href:"/core-exchange/docs/consent-management/api"},"Consent API"),". It remains supported for integrations already built on it, and its reference page covers the same guidance as this page in its own schemas."),(0,r.kt)("h3",{id:"data-partner-dashboard-single-institution-only"},"Data Partner Dashboard (single institution only)"),(0,r.kt)("p",null,"For single-institution accounts, use the Permissions Manager tabs of Plaid's Data Partner Dashboard to search authorization records by user identifier. Browse connections, view details, and manage access via the web, no API integration needed."),(0,r.kt)("p",null,(0,r.kt)("strong",{parentName:"p"},"How to access:")," Reach out to your Plaid contact to enable dashboard access."),(0,r.kt)(h,{src:"/assets/img/core-exchange/permissions-manager/lookup.png",alt:"Dashboard search interface for looking up customer connections",caption:"Search by customer to view authorization details",expandable:!0,mdxType:"Image"}),(0,r.kt)("p",null,"If you build your own consumer-facing consent portal (rather than relying solely on the Dashboard), you're responsible for keeping Plaid and connected apps in sync when a user revokes access on your domain; see ",(0,r.kt)("a",{parentName:"p",href:"/core-exchange/docs/consent-management/api#revocation-and-ecosystem-sync"},"Revocation and ecosystem sync")," on the ",(0,r.kt)("a",{parentName:"p",href:"/core-exchange/docs/consent-management/api"},"Consent API")," reference."),(0,r.kt)("h2",{id:"plaid-portal-myplaidcom"},"Plaid Portal (my.plaid.com)"),(0,r.kt)("p",null,"Users can view and manage all their Plaid connections at ",(0,r.kt)("a",{parentName:"p",href:"https://my.plaid.com"},"my.plaid.com"),". This consumer-facing portal shows:"),(0,r.kt)("ul",null,(0,r.kt)("li",{parentName:"ul"},"Which apps have access to their data"),(0,r.kt)("li",{parentName:"ul"},"Which accounts are shared with each app"),(0,r.kt)("li",{parentName:"ul"},"When users created connections"),(0,r.kt)("li",{parentName:"ul"},"Options to revoke access")),(0,r.kt)("h2",{id:"best-practices"},"Best practices"),(0,r.kt)("ul",null,(0,r.kt)("li",{parentName:"ul"},"Integrate with the ",(0,r.kt)("a",{parentName:"li",href:"/core-exchange/docs/consent-management/api"},"Consent API")," or the dashboard to access authorization records"),(0,r.kt)("li",{parentName:"ul"},"Set refresh token expiration to 13+ months (allows buffer for reauthorization)"),(0,r.kt)("li",{parentName:"ul"},"Direct users to ",(0,r.kt)("a",{parentName:"li",href:"https://my.plaid.com"},"my.plaid.com")," for self-service connection management")),(0,r.kt)("p",null,"If you're building against the ",(0,r.kt)("a",{parentName:"p",href:"/core-exchange/docs/consent-management/api"},"Consent API")," directly, see its ",(0,r.kt)("a",{parentName:"p",href:"/core-exchange/docs/consent-management/api#best-practices"},"best practices")," for revocation and webhook guidance.")))}k.isMDXComponent=!0;var f=[{id:"overview",level:2,title:"Overview"},{id:"authorization-records",level:2,title:"Authorization records"},{id:"accessing-authorization-records",level:3,title:"Accessing authorization records"},{id:"consent-api-beta",level:3,title:"Consent API (beta)"},{id:"data-partner-dashboard-single-institution-only",level:3,title:"Data Partner Dashboard (single institution only)"},{id:"plaid-portal-myplaidcom",level:2,title:"Plaid Portal (my.plaid.com)"},{id:"best-practices",level:2,title:"Best practices"}];g.tableOfContents=f,k.layoutProps=g,k.layout=function(e){return(0,r.kt)(s.Z,e)}},78956:function(e,t,a){(window.__NEXT_P=window.__NEXT_P||[]).push(["/core-exchange/docs/consent-management",function(){return a(60144)}])},43402:function(e){e.exports={page:"core-exchange_page__hVAuI"}}},function(e){e.O(0,[49774,86898,26736,29622,12291,22359,68239,79255,92888,40179],function(){return e(e.s=78956)}),_N_E=e.O()}]);
2//# sourceMappingURL=consent-management-fce432ef0a7a222d.js.map

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.