> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.liquifyfin.in/partner-consent/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.liquifyfin.in/_mcp/server. # Partner Consent Specification > **Warning** > > **Draft Specification — Pending Legal Sign-Off**:\ > `LIQ-PARTNER-CONSENT-v1` is currently a draft specification under review by Legal. Legal must formally approve this consent text before any partner renders it in production. Partners must render the text exactly as specified without modifications, filling in **only the bracketed placeholder fields**. ## Overview The Digital Personal Data Protection (DPDP) Act and regulatory guidelines require explicit, purpose-specific, unbundled consent before accessing customer KYC data or fetching registrar mutual fund records. Liquify provides the **`LIQ-PARTNER-CONSENT-v1`** contract to standardize the consent capture journey across all partner applications. --- ## UI & Display Compliance Rules To ensure legal validity and seamless API processing, partner applications must adhere to the following rules: 1. **Dedicated Standalone Screen**: Display the entire consent text on its own dedicated screen in your mobile or web flow. It must **not** be placed behind a link, hidden in an accordion, or embedded inside your application's general Terms & Conditions. 2. **No Pre-Ticked Checkboxes**: Checkboxes must **never** be checked by default. The customer must actively and individually select each purpose. 3. **Mandatory vs. Optional Checkboxes**: * **Box 1 (`KYC_PAN`)** is required to proceed with onboarding and account creation. * **Boxes 2 (`MF_HOLDINGS`)** and **Box 3 (`PARTNER_SHARE`)** are optional; however, computing borrowing eligibility requires all three consents to be granted. 4. **Granular Purpose Relay**: Relay **only** the purpose codes corresponding to the checkboxes the customer actually ticked. 5. **Accurate Timestamping**: The `captured_at` parameter must represent the exact ISO 8601 timestamp at which the customer tapped the submit button. 6. **Strict Version Validation**: The backend checks `consent_text_version` against `a7.vendor.consent.text-versions`. Any wording, translation, or language modification requires a newly registered version code; unregistered strings return `400 VALIDATION_FAILED`. --- ## Purpose Code Mapping | Checkbox | UI Purpose | API Purpose Code | Requirement | | :-------- | :---------------------------- | :--------------- | :--------------------------------------------------- | | **Box 1** | Create my Liquify account | `KYC_PAN` | **Mandatory** to continue onboarding. | | **Box 2** | Fetch my mutual fund holdings | `MF_HOLDINGS` | **Required** for CAMS/KFintech CAS portfolio sync. | | **Box 3** | Share my result with partner | `PARTNER_SHARE` | **Required** to display borrowing limits to partner. | --- ## Consent Screen Template (Exact Copy) Partners must render the exact wording below, replacing only the bracketed variables (`[Partner name]`, `[mobile number]`, `[name]`, `[email]`, `[phone]`, `[link]`): #### Partner Screen Mockup · LIQ-PARTNER-CONSENT-v1 **Your consent to Liquify** `[Partner name]` works with Sumanju Technologies Private Limited ("Liquify") to check how much you can borrow against your mutual funds. Liquify needs your consent for each step below. Tick only what you agree to. --- ☐ **1. Create my Liquify account (needed to continue)**\ I allow Liquify to verify my PAN, and to use my PAN, name, date of birth, gender and mobile number `[mobile number]` to create my Liquify account. I can sign in to it with an OTP sent to this number. ☐ **2. Fetch my mutual fund holdings**\ I allow Liquify to fetch my mutual fund holdings from MF Central, CAMS or KFintech, using an OTP they send to the mobile number or email registered with them, and to use those holdings to work out how much I can borrow against them. ☐ **3. Share my result with `[partner name]`**\ I allow Liquify to share with `[partner name]` the amount I can borrow, the value of my mutual fund portfolio and the date my holdings were last fetched. Nothing else about my holdings is shared. --- *Disclosures & Policies:* * The amount I can borrow is an **estimate, not a loan offer**. Any loan is decided by the lender, whose name, interest rate and charges I will see before I apply. * Liquify stores this data in **India**, uses it only for the purposes I ticked, and keeps it only as long as the law requires. * I can withdraw any of these consents at any time in the Liquify app or by writing to the Grievance Officer. Withdrawing stops future use; it does not undo what was done before. * **Grievance Officer**: `[name]`, `[email]`, `[phone]`. If my complaint is not resolved, I can complain to the Data Protection Board of India. * Privacy policy: `[link]` · Consent text `LIQ-PARTNER-CONSENT-v1` --- ## Relaying & Reading Consents via API Once the customer submits the consent screen, relay their choices to the customer consent endpoint: ```bash curl -X POST "https://a7.liquifyfin-uat.in/v1/customers/ObEDjNxG/consents" \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -d '{ "purposes": [ "KYC_PAN", "MF_HOLDINGS", "PARTNER_SHARE" ], "granted": true, "captured_at": "2026-10-02T10:20:00+05:30", "ip": "49.36.10.1", "device": "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X)", "consent_text_version": "LIQ-PARTNER-CONSENT-v1" }' ``` > **Note** > > **Reading Consent State**: The customer may withdraw any purpose in the Liquify app at any time. Before performing operations that require consent, check their active status via: > > ```bash > curl -X GET "https://a7.liquifyfin-uat.in/v1/customers/ObEDjNxG/consents" \ > -H "Authorization: Bearer " > ``` ### Success Response ```json { "data": [ { "purpose": "KYC_PAN", "granted": true, "recorded_at": "2026-10-02T04:28:40Z", "consent_text_version": "LIQ-PARTNER-CONSENT-v1" }, { "purpose": "MF_HOLDINGS", "granted": true, "recorded_at": "2026-10-02T04:28:40Z", "consent_text_version": "LIQ-PARTNER-CONSENT-v1" }, { "purpose": "PARTNER_SHARE", "granted": true, "recorded_at": "2026-10-02T04:50:03Z", "consent_text_version": "LIQ-PARTNER-CONSENT-v1" } ], "meta": { "request_id": "c4129a01-1b92-4fc3-a7c8-479e0a29ef19", "ts": "2026-10-02T10:20:01Z" } } ``` --- ## Architectural & Compliance Rationale #### DPDP Granular Consent Per DPDP requirements, bundling multiple purposes into a single agreement is prohibited. Distinct checkboxes ensure customers independently consent to account creation, portfolio ingestion, and partner sharing. #### Mobile Handle Notice Box 1 explicitly identifies the mobile number and notifies the user of OTP login access, providing notice since accounts are created via partner handoff before initial OTP challenge. #### Unnamed Lender by Design Co-branding banking partners (e.g. Bajaj Finance Limited) requires separate marketing approvals. The text designates the lender generically until formal loan application presentation. #### Data Localization & Redressal All customer data resides strictly within India. Customers can withdraw consent via the Liquify app or Grievance Officer, with escalation rights to the Data Protection Board of India. > High-performance, secure Partner API infrastructure for mutual fund portfolio synchronization and mutual fund & check eligibility.