Developers
Karibu ID with OneTrust — an integration recipe
Developer guide
A guide, not code, built only from Karibu ID's published contract (contracts/openapi.json, v0.57.0): the reader API, the reader webhooks and the exports (FA v5.7 §36.7). It describes one way a reader organisation can feed a OneTrust third-party risk programme from what Karibu ID holds. Karibu ID has no partnership with OneTrust; OneTrust is a trademark of its owner. Karibu ID reports findings, never verdicts: the assessment and the decision stay the reader's own.
What you need
- A reader organisation in Karibu ID with exports on, and a reader admin.
- In OneTrust, an integration workflow that can receive an HTTPS POST and call a REST API, and a place to keep the webhook signing secret and a Karibu ID access token.
1. Vendors from shares
- Add a webhook endpoint (
POST /v1/reader/webhooks) pointing at the OneTrust workflow; keep the signing secret shown once. - Verify every delivery's
KaribuID-Signature(HMAC-SHA256 over<t>.and the raw body, a 300-second replay window), then act onevent_type. - On
share_granted, create or link the vendor by its KE (ids.organisation); onshare_revoked, mark the Karibu ID evidence as no longer shared.
2. Evidence for an assessment
- The record shared in full, as a signed file:
GET /v1/reader/exports/records/{ke}. Attach it to the vendor's assessment; anyone can check its signature at/v1/public/reports/{ks}/verify. - The findings across the companies that share with you in full:
GET /v1/reader/exports/findings?format=xlsx. - Questionnaire answers the company shared with you: listen for
questionnaire_answered, then read them through the questionnaire routes. Answers are the company's declarations, shown as "declared by the company on [date]", never Karibu ID's view.
3. Monitoring
finding_new,report_supersededand theledger_*events reopen or update the vendor's assessment;ledger_high(struck off, dissolved, liquidation, statutory management, licence revoked) always reaches you.reader_tier_changedtells you a relationship's tier changed under your own tiering rules; map it to OneTrust's own tiering if you keep both.
4. Keep it within the rules
- The webhook bodies carry ids only; fetch details signed in, and only what you need.
- When a share ends, Karibu ID's routes answer 404; stop using and remove what you copied.
- Every export is in your access log, and a company's record export in the company's.
Mirrored from Karibu ID’s published integration recipes (commit 00ba731), built from contract version 0.59.0.