curl --request GET \
--url https://public-api.sessionboard.com/v1/gdpr/requests \
--header 'x-access-token: <api-key>'import requests
url = "https://public-api.sessionboard.com/v1/gdpr/requests"
headers = {"x-access-token": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'x-access-token': '<api-key>'}};
fetch('https://public-api.sessionboard.com/v1/gdpr/requests', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://public-api.sessionboard.com/v1/gdpr/requests",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-access-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://public-api.sessionboard.com/v1/gdpr/requests"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("x-access-token", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://public-api.sessionboard.com/v1/gdpr/requests")
.header("x-access-token", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://public-api.sessionboard.com/v1/gdpr/requests")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["x-access-token"] = '<api-key>'
response = http.request(request)
puts response.read_body[
{
"id": "<string>",
"org_id": "<string>",
"request_type": "erasure",
"identity_type": "email",
"identity_value": "<string>",
"status": "complete",
"matching_user_exists": true,
"response": {
"users": [
123
],
"org_users": [
"<string>"
],
"event_users": [
123
],
"contact_records": [
"<string>"
],
"people": [
"<string>"
],
"users_scrubbed": [
123
],
"users_retained": [
{}
],
"counts": {
"org_users": 123,
"event_users": 123,
"contact_records": 123,
"people": 123,
"users_identified": 123,
"users_scrubbed": 123,
"users_retained": 123
}
},
"created_at": "<string>",
"updated_at": "<string>"
}
]List GDPR requests
Returns the organization’s GDPR data access and erasure requests, newest first.
The response is a bare JSON array, not a results envelope. This page
previously showed an envelope; the endpoint has always returned the
array.
Paginated with page and pageSize (default 25, maximum 100). Keep
requesting pages until one comes back with fewer than pageSize
entries.
Both parameters are validated. A page or pageSize outside its
documented range, and any query parameter this operation does not
declare, are rejected with a 400. Out-of-range values used to be
accepted and silently clamped.
curl --request GET \
--url https://public-api.sessionboard.com/v1/gdpr/requests \
--header 'x-access-token: <api-key>'import requests
url = "https://public-api.sessionboard.com/v1/gdpr/requests"
headers = {"x-access-token": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'x-access-token': '<api-key>'}};
fetch('https://public-api.sessionboard.com/v1/gdpr/requests', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://public-api.sessionboard.com/v1/gdpr/requests",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-access-token: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://public-api.sessionboard.com/v1/gdpr/requests"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("x-access-token", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://public-api.sessionboard.com/v1/gdpr/requests")
.header("x-access-token", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://public-api.sessionboard.com/v1/gdpr/requests")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["x-access-token"] = '<api-key>'
response = http.request(request)
puts response.read_body[
{
"id": "<string>",
"org_id": "<string>",
"request_type": "erasure",
"identity_type": "email",
"identity_value": "<string>",
"status": "complete",
"matching_user_exists": true,
"response": {
"users": [
123
],
"org_users": [
"<string>"
],
"event_users": [
123
],
"contact_records": [
"<string>"
],
"people": [
"<string>"
],
"users_scrubbed": [
123
],
"users_retained": [
{}
],
"counts": {
"org_users": 123,
"event_users": 123,
"contact_records": 123,
"people": 123,
"users_identified": 123,
"users_scrubbed": 123,
"users_retained": 123
}
},
"created_at": "<string>",
"updated_at": "<string>"
}
]Authorizations
Organization API token. Generate from Organization Settings → API Tokens.
Query Parameters
1-based page number, 1 to 999. Outside that range is a 400.
1 <= x <= 999Requests per page, 1 to 100. Outside that range is a 400; values above 100 are no longer clamped.
1 <= x <= 100Response
OK
Identifier of the stored request. Quote this when evidencing a DSAR.
erasure, access email Outcome of the request.
complete— at least one record matched and was processed.no_records_found— nothing in this organization matched the email, so nothing was erased.pending— the request is stored but has not finished processing.
complete, no_records_found, pending True when the email matched at least one record of any kind.
What the request matched and what happened to it. people, users_scrubbed, users_retained and counts are present on requests processed recently and absent on older records; an absent field means "not recorded", not "zero".
Show child attributes
Show child attributes

