Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
Didomi website screenshot

Didomi

Didomi is a Paris-based consent and preference management platform (CMP/PMP) that helps publishers, advertisers, retailers, and large enterprises collect, manage, and act on user privacy choices across web, mobile, CTV, and AMP surfaces. The platform covers GDPR, CCPA and the wider US state-law landscape, IAB TCF v2.x, Google Consent Mode v2, the IAB GPP, GPC, the EU DMA, Chilean Law 25, Australian privacy law, and other regulations through a single multi-regulation configuration model. Didomi exposes a JSON REST API (https://api.didomi.io/v1/) plus first-party SDKs for Web, iOS/tvOS, Android/Android TV, Unity, React Native, Flutter, Vega OS, and AMP, alongside IAB-compliant consent string tooling and reverse-proxy boilerplates for Fastly, CloudFront, and Cloudflare.

agent ready

Solid contracts, transparent operations, and an easy start — typically complete on four or five facets with one clear soft spot.

Kin Score

API Evangelist profiles Didomi the way a machine reads it — 113 machine-readable artifacts across 37 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.

Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Didomi scores 66.7/100 (strong), with a separate agent-readiness read of 55/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.

Kin Score

This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 66.7/100 · strong
Contract Quality 16.7 / 25
Developer Ergonomics 14.3 / 20
Commercial Clarity 15.8 / 20
Operational Transparency 2.7 / 13
Governance 10.4 / 12
Discoverability 6.8 / 10
Agent readiness — 55/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 15 / 15
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3

How we profile Didomi

Each block below is one kind of artifact we hold for Didomi. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.

APIs 37

Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.

Individual APIs this provider publishes, each with its own machine-readable definition.

Didomi Web SDK

The Didomi Web SDK is the browser-side library that renders consent notices, preference centers, and privacy widgets, gates third-party tags on user consent, and writes IAB TCF ...

Didomi Android SDK

Didomi's Android and Android TV SDK delivers native consent notices, preference popups, and TCF / GPP / Didomi consent string generation in Java / Kotlin / Jetpack Compose apps....

Didomi iOS SDK

The iOS / tvOS / Mac Catalyst SDK renders Didomi consent notices and preference centers natively in Swift and Objective-C apps, coordinates Apple's App Tracking Transparency (AT...

Didomi Cross-Platform SDKs (React Native, Flutter, Unity, Vega OS, AMP)

Didomi maintains first-party CMP plugins for React Native, Flutter, Unity (games and game consoles), Vega OS (LG webOS smart TVs), and Google AMP. Each wraps the platform's noti...

Didomi Consent String Toolkit

Open-source libraries published under github.com/didomi for encoding, decoding, and validating the Didomi consent string and the IAB TCF v2 consent string. Includes TypeScript (...

Didomi consents/events API

The consents/events API from Didomi — 2 operation(s) for consents/events.

Didomi consents/proofs API

The consents/proofs API from Didomi — 2 operation(s) for consents/proofs.

Didomi consents/tokens API

The consents/tokens API from Didomi — 1 operation(s) for consents/tokens.

Didomi consents/users API

The consents/users API from Didomi — 2 operation(s) for consents/users.

Didomi cookies API

Manage cookies set by a property

Didomi dashboards-urls API

The dashboards-urls API from Didomi — 1 operation(s) for dashboards-urls.

Didomi domains API

Provisioned domains for consent notices and privacy centers

Didomi Integrations API

The Integrations API from Didomi — 1 operation(s) for integrations.

Didomi keys API

Manage API keys

Didomi languages API

List of available languages for the SDKs

Didomi members API

Manage members of an organization

Didomi metadata API

A metadata service

Didomi metadata-purpose-regulation-override API

The metadata-purpose-regulation-override API from Didomi — 2 operation(s) for metadata-purpose-regulation-override.

Didomi notices API

The notices API from Didomi — 18 operation(s) for notices.

Didomi organizations API

Manage organizations

Didomi organizations-source-systems API

Manage organization source systems

Didomi partners API

The partners API from Didomi — 2 operation(s) for partners.

Didomi partners-default-purposes API

The partners-default-purposes API from Didomi — 1 operation(s) for partners-default-purposes.

Didomi partners-legitimate-interest-purposes API

The partners-legitimate-interest-purposes API from Didomi — 1 operation(s) for partners-legitimate-interest-purposes.

Didomi partners-spi-purposes API

The partners-spi-purposes API from Didomi — 1 operation(s) for partners-spi-purposes.

Didomi partners-storages API

The partners-storages API from Didomi — 2 operation(s) for partners-storages.

Didomi premium-features API

Manage premium features

Didomi privacy-centers API

Manage privacy centers

Didomi purposes API

The purposes API from Didomi — 3 operation(s) for purposes.

Didomi purposes-groups API

The purposes-groups API from Didomi — 2 operation(s) for purposes-groups.

Didomi quotas API

Manage quotas

Didomi secrets API

Manage secrets

Didomi sessions API

Manage sessions

Didomi sso-connections API

Manage SSO connections

Didomi taxonomies API

Manage the taxonomy for vendors

Didomi vendors API

Manage vendors used by a property

Didomi widgets/notices/remote-configs API

The widgets/notices/remote-configs API from Didomi — 1 operation(s) for widgets/notices/remote-configs.

Scroll within the panel for all 37 ·

Postman Collections 1

A runnable collection turns the contract into something a developer can execute in seconds. We profile them because the fastest way to trust an API is to make a real call against it.

Ready-to-run Postman collections for exercising this provider's APIs.

Didomi API

POSTMAN

Open Collections 1

Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Didomi API

OPEN COLLECTION

Arazzo Workflows 12

Real integrations are rarely a single call. Arazzo describes the multi-step sequences — auth, then create, then confirm — so both a human and an agent can follow the choreography, not just the endpoints.

Multi-step API workflows described with the Arazzo specification.

Didomi Classify a Vendor and Register a Cookie

Create a vendor taxonomy item, register a cookie classified with it, and read the cookie back.

ARAZZO

Didomi Create a Consent User and Assign an Internal ID

Create an end user, patch it to assign your organization's internal user ID, and read it back.

ARAZZO

Didomi Create and Verify a Privacy Center

Create a privacy center for an organization and read it back to confirm it was created.

ARAZZO

Didomi Data Subject Erasure Request

Look up an end user by your internal ID and fulfil a right-to-erasure request by deleting their consent record.

ARAZZO

Didomi Deploy a Consent Notice

Create a consent notice, deploy a notice configuration to production, and confirm the deployment.

ARAZZO

Didomi Group Notices Under a Template

Create a consent notice, group it under a new notice template, and read the template back.

ARAZZO

Didomi Issue a Consent Token for an End User

Create an end user, assign an internal ID, and issue a scoped JWT consent token for that user.

ARAZZO

Didomi Provision an Organization and Invite a Member

Create an organization, invite a first member into it, and read the organization back.

ARAZZO

Didomi Record a Consent Event and Confirm Status

Create a consent event for an end user, then branch on whether it is confirmed or pending approval.

ARAZZO

Didomi Register and Verify a Cookie

Register a cookie set by a property and read it back to confirm registration.

ARAZZO

Didomi Submit Notice Text Content for Approval

Create a notice text, submit a content version for the Didomi approval process, and read the content status.

ARAZZO

Didomi Upload and Verify a Consent Proof

Upload a file as proof of consent for an organization and read it back to verify storage.

ARAZZO

Scroll within the panel for all 12 ·

Pricing Plans 1

Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.

Published pricing tiers and plan structures.

Didomi Plans Pricing

5 plans

PLANS

Rate Limits 1

Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.

Documented rate limits and quota policies.

Didomi Rate Limits

0 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.

Cost, billing, and metering signals for API financial operations.

Features 15

The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.

Notable capabilities this provider offers.

Multi-regulation CMP

One Didomi notice can target GDPR, CCPA and the wider US-state landscape, TCF v2.x, GPP, GPC, EU DMA, Chilean Law 25, Australian privacy law, and Nordic regimes from a single mu...

IAB TCF v2.x / GPP / GPC compliance

Didomi is an IAB-registered CMP that emits, validates, and decodes TCF v2.x and IAB GPP consent strings and honors Global Privacy Control signals.

Google Consent Mode v2

Native, certified Google Consent Mode v2 integration on Web and Mobile, plus Amazon Consent Signal and Microsoft UET Consent Mode bridges.

Preference Management Platform (PMP)

A separately licensed Preference Management module exposing custom preference centers, headless preference widgets, marketing channel preferences, and email/SMS opt-in flows.

Privacy Requests Management

DSAR / privacy-request intake forms, internal workflow, evidence storage, and reporting for GDPR Articles 15-22 and CCPA opt-out / delete rights.

Compliance Monitoring & Reports

Automated scanning of websites and apps for vendor coverage, unauthorized tags, and CMP behavior; CSV / Excel compliance reports surfaced via the Platform API and Console.

Privacy Widgets

Configurable, themed widgets (preference centers, DSAR forms, headless React widgets, embeddable widgets) deployable on Didomi-managed or customer-owned domains.

Consent Notice on Custom Domain

Serve consent notices from the customer's own domain via DNS delegation or via reverse-proxy boilerplates for Fastly, AWS CloudFront, and Cloudflare.

Cross-device / cross-domain consent sharing

Authenticated users can carry their consent state across domains and across devices via the platform's tokens and links APIs.

Server-side Google Tag Manager (Addingwell)

Server-side tagging product (Addingwell, acquired by Didomi) integrated with the consent model for first-party tagging without browser-side third-party calls.

Cross-Platform SDKs

First-party SDKs for Web, iOS / tvOS / Mac Catalyst, Android / Android TV, React Native, Flutter, Unity, Vega OS (LG smart TVs), and Google AMP.

Open Consent String tooling

Open-source consent-string encoders / decoders in TypeScript, Rust (with C and Java FFI), and Go, plus the iabtcf-es TCF v2 toolkit fork.

JWT bearer authentication

Platform API uses short-lived (one-hour) JWT access tokens obtained by exchanging API key + secret against POST /v1/sessions.

Token-bucket rate limiting

100 requests per 15 seconds per organization across most routes, with the high-volume /consents/* family exempt; RateLimit / RateLimit-Policy headers and 429 + Retry-After when ...

SSO and member management

Programmatic management of organization members, roles, SSO connections, partner-portal sessions, and per-key API quotas via the Platform API.

Scroll within the panel for all 15 ·

Semantic Vocabularies 1

JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.

JSON-LD contexts and semantic vocabularies used across these APIs.

Didomi Context

22 classes · 10 properties

JSON-LD

Spectral Rules 2

Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.

Didomi API Rules

5 rules · 4 warnings

SPECTRAL

Didomi API Rules

10 rules · 4 errors · 5 warnings

SPECTRAL

JSON Schema 3

Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.

Standalone JSON Schema definitions for this provider's data models.

Didomi Consent Event

10 properties

JSON SCHEMA

Didomi Consent Notice

15 properties

JSON SCHEMA

Didomi Privacy Request (DSAR)

11 properties

JSON SCHEMA

JSON Structure 1

JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.

JSON Structure definitions describing this provider's data shapes.

Didomi Consent Event Structure

10 properties

JSON STRUCTURE

Examples 3

Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.

Example request and response payloads for these APIs.

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Didomi Authentication

http · 1 scheme

SECURITY

Didomi Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Didomi Trust Center

ISO 27001, GDPR

SECURITY

Agentic Access 1

An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.

Recommended x-agentic-access execution contracts for AI agents.

Didomi Agentic Access

190 operations · 118 acting · 12 human-in-the-loop

190 operations · 118 acting

AGENTIC

Use Cases 6

What developers actually build with this provider — captured so the catalogue answers 'what is this for', not just 'what does this expose'.

What developers build with this provider.

Publisher CMP for ad monetization

News publishers and media groups (Yahoo, large French / European publishers) use Didomi as their IAB TCF CMP so SSPs and DSPs receive valid consent signals and ad inventory is m...

Retailer / e-commerce consent and preference

Retail and e-commerce brands (Lacoste, Rakuten, Michelin) capture consent for analytics, personalization, marketing, and CRM channels via the CMP and Preference Management Platf...

Connected TV CMP

CTV apps on LG webOS / Vega OS, Android TV, and tvOS use Didomi's native SDKs to render consent on TV screens and emit the same TCF / Didomi consent strings used on web.

DSAR / privacy-request intake at scale

Enterprises route GDPR Article 15-22 and CCPA opt-out / delete requests through Didomi's Privacy Requests product, with audit-grade proofs and structured exports.

Cross-domain / cross-device consent for media groups

Media groups operating dozens of domains share a single consent across all properties and across user devices via consent tokens and links.

Server-side first-party tagging

Marketing teams replace browser-side third-party tags with server-side Google Tag Manager via Addingwell, gated on Didomi consent.

Integrations 16

Pre-built integrations with other platforms tell you where this provider already fits in a stack.

Pre-built integrations with other platforms and tools.

Google Tag Manager

First-class Didomi GTM template and native integration; certified Google Consent Mode v2 signal delivery.

Google Ad Manager / AdSense / AdX

Pass TCF consent signal and non-personalized-ads (NPA) fallback to Google ad stack.

Adobe Launch / Adobe DTM

Documented integration patterns for managing tag firing under Didomi consent.

Tealium iQ

Native Tealium integration for tag governance under Didomi consent.

Eulerian

Tag firing control through Eulerian tag management.

Prebid

Pass TCF v2 / US state-law consent to Prebid header bidding wrappers.

Salesforce DMP (Krux)

Forward consent state to Salesforce DMP / Krux.

Piano Analytics (AT Internet)

Integration with Piano Analytics (formerly AT Internet) for consent-aware analytics.

Kameleoon

Consent integration with Kameleoon experimentation / personalization platform.

Simple Analytics

Privacy-friendly analytics integration.

Amazon Consent Signal

Native bridge to Amazon's consent signal for Amazon Publisher Services.

Microsoft UET Consent Mode

Native bridge to Microsoft UET / Bing Ads consent mode.

mParticle

First-party JavaScript kit integration for mParticle customer data platform.

Magento 2

Didomi Magento 2 extension for consent management on Magento storefronts.

Firebase

Cloud Functions integration to ship Didomi consent into the Firebase / Google ecosystem.

Postman

Public Postman workspace and collections for the Platform API.

Scroll within the panel for all 16 ·

Solutions 8

Packaged solutions the provider offers on top of the raw API surface.

Packaged solutions this provider offers.

CMP for Publishers

IAB TCF v2.x CMP specialized for ad-funded publishers and media groups.

CMP for Advertisers and Brands

Consent capture and forwarding for advertiser stacks, MarTech tools, and CDPs.

CMP for Connected TV

Native CTV consent for Vega OS, Android TV, tvOS, and other TV runtimes.

CMP for Mobile Apps

iOS / Android / cross-platform consent management coordinated with ATT and Google Consent Mode v2.

Preference Management Platform

Marketing-preference and channel-opt-in management beyond regulatory consent.

Privacy Requests

GDPR / CCPA DSAR intake, internal workflow, and audit-grade evidence.

Compliance Monitoring

Continuous scanning of digital properties for vendor coverage, unauthorized tags, and CMP misconfigurations.

Addingwell - Server-side Tagging

Server-side Google Tag Manager product acquired by Didomi, integrated with the Didomi consent model.

Scroll within the panel for all 8 ·

Resources

Every other property we hold for Didomi — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.

Get Started 4

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Access & Security 3

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 3

Status, limits, changes, and where to get help

Company 2

The organization behind the API

Other 1

Properties that don't map to a standard resource type

← All providers · Data indexed from github.com/api-evangelist/didomi · machine-readable index on apis.io