Developers

Karibu ID with OneTrust — an integration recipe

Developer guide

A guide, not code, built only from Karibu ID's published contract (contracts/openapi.json, v0.57.0): the reader API, the reader webhooks and the exports (FA v5.7 §36.7). It describes one way a reader organisation can feed a OneTrust third-party risk programme from what Karibu ID holds. Karibu ID has no partnership with OneTrust; OneTrust is a trademark of its owner. Karibu ID reports findings, never verdicts: the assessment and the decision stay the reader's own.

What you need

  • A reader organisation in Karibu ID with exports on, and a reader admin.
  • In OneTrust, an integration workflow that can receive an HTTPS POST and call a REST API, and a place to keep the webhook signing secret and a Karibu ID access token.

1. Vendors from shares

  1. Add a webhook endpoint (POST /v1/reader/webhooks) pointing at the OneTrust workflow; keep the signing secret shown once.
  2. Verify every delivery's KaribuID-Signature (HMAC-SHA256 over <t>. and the raw body, a 300-second replay window), then act on event_type.
  3. On share_granted, create or link the vendor by its KE (ids.organisation); on share_revoked, mark the Karibu ID evidence as no longer shared.

2. Evidence for an assessment

  • The record shared in full, as a signed file: GET /v1/reader/exports/records/{ke}. Attach it to the vendor's assessment; anyone can check its signature at /v1/public/reports/{ks}/verify.
  • The findings across the companies that share with you in full: GET /v1/reader/exports/findings?format=xlsx.
  • Questionnaire answers the company shared with you: listen for questionnaire_answered, then read them through the questionnaire routes. Answers are the company's declarations, shown as "declared by the company on [date]", never Karibu ID's view.

3. Monitoring

  • finding_new, report_superseded and the ledger_* events reopen or update the vendor's assessment; ledger_high (struck off, dissolved, liquidation, statutory management, licence revoked) always reaches you.
  • reader_tier_changed tells you a relationship's tier changed under your own tiering rules; map it to OneTrust's own tiering if you keep both.

4. Keep it within the rules

  • The webhook bodies carry ids only; fetch details signed in, and only what you need.
  • When a share ends, Karibu ID's routes answer 404; stop using and remove what you copied.
  • Every export is in your access log, and a company's record export in the company's.

Mirrored from Karibu ID’s published integration recipes (commit 00ba731), built from contract version 0.59.0.