> ## Documentation Index
> Fetch the complete documentation index at: https://docs.timeback.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a consent record

> Records a parental consent status for a student in the append-only audit trail. When guardianId is supplied it must belong to a guardian with an active relationship to the student (otherwise 400); guardianId may be null only for a pending record whose metadata.consentMethod is awaiting_guardian.



## OpenAPI

````yaml /openapi/learn-with-ai/platform-api.yaml post /consent/1.0/students/{studentId}/records
openapi: 3.1.1
info:
  title: TimeBack Platform API
  description: >-
    RESTful API for the TimeBack Platform. Covers authentication, rostering,
    curriculum, insights, assessments, content grading, and more.
  version: 2026.09.10.1
servers:
  - url: https://platform.dev.timeback.com
    description: integration
security: []
tags:
  - name: Auth
    description: Authentication and authorization endpoints
  - name: Organizations
    description: Organizations module contains all endpoints around organization management
  - name: Applications
    description: Applications module contains all endpoints for managing LTI applications
  - name: Users
    description: >-
      Users module contains all endpoints around user creation, update and
      consultation
  - name: Students
    description: Students module contains all endpoints around student management
  - name: Demographics
    description: >-
      Demographics module contains all endpoints around demographics
      consultation
  - name: Consent
    description: >-
      Initiate and query TimeBack parental consent for a student, backed by an
      immutable audit trail.
  - name: Classes
    description: Classes module contains all endpoints around class management
  - name: Courses
    description: Courses module contains all endpoints around course management
  - name: Enrollments
    description: Enrollments module contains all endpoints around enrollment consultation
  - name: CASE
    description: Competency and Academic Standards Exchange (CASE) 1.1 API
  - name: Curriculum
    description: Curriculum module contains endpoints for managing curriculum data
  - name: Competency Track
    description: Competency track endpoints
  - name: Content Grading
    description: >-
      Registration and management of graders for free-response content items —
      bring-your-own external graders (Tier 2) and, once shipped,
      platform-managed grading prompts (Tier 1).
  - name: Caliper
    description: The Caliper module contains all endpoints around Caliper Analytics
  - name: Insights
    description: Coaching insights and session analytics endpoints
paths:
  /consent/1.0/students/{studentId}/records:
    post:
      tags:
        - Consent
      summary: Create a consent record
      description: >-
        Records a parental consent status for a student in the append-only audit
        trail. When guardianId is supplied it must belong to a guardian with an
        active relationship to the student (otherwise 400); guardianId may be
        null only for a pending record whose metadata.consentMethod is
        awaiting_guardian.
      operationId: createConsentRecord
      parameters:
        - name: studentId
          in: path
          description: Unique identifier of the student
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConsentRecordInput'
      responses:
        '201':
          description: Consent record created successfully
        '400':
          $ref: '#/components/responses/BadRequest11'
        '403':
          description: Caller does not own the student's organization
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError3'
        '404':
          description: Student or guardian not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError3'
        '500':
          $ref: '#/components/responses/InternalError4'
      security:
        - CognitoUserPoolAuthorizer:
            - https://timeback-platform.trilogy.com/consent/scope/consent.write
components:
  schemas:
    ConsentRecordInput:
      type: object
      properties:
        guardianId:
          type:
            - string
            - 'null'
          format: uuid
          description: >-
            UUID of the parent/guardian providing consent. Nullable only for
            pending records where metadata.consentMethod is awaiting_guardian.
        consentStatus:
          $ref: '#/components/schemas/ConsentStatus'
        occurredAtTime:
          type: string
          format: date-time
          description: Timestamp when the consent status change occurred
        metadata:
          type:
            - object
            - 'null'
          additionalProperties: true
          description: >-
            Free-form audit context. Common keys the platform reads/writes:
            consentMethod, docusignEnvelopeId, docusignStatus,
            emailConsentInitiatedAt, returnUrl, and (on voided records)
            supersededBy and originalEnvelopeId. Additional keys are allowed.
      required:
        - consentStatus
        - occurredAtTime
    ApiError3:
      type: object
      properties:
        error:
          type: string
          description: Error name/type
        message:
          type: string
          description: Human-readable error message
        fields:
          type: array
          description: Validation errors for specific fields
          items:
            type: object
            properties:
              field:
                type: string
              message:
                type: string
      required:
        - error
        - message
    ConsentStatus:
      type: string
      enum:
        - pending
        - granted
        - denied
        - expired
        - voided
        - withdrawn
      description: >-
        Status of the consent. Note: the platform does not produce `expired`
        automatically; a request that lapses unsigned stays `pending`. `expired`
        is accepted only as a createConsentRecord input. `voided` is written
        when a request is superseded (re-request, name correction, sibling
        grant) or the DocuSign envelope is voided.
    imsxStatusInfoDType1:
      type: object
      properties:
        imsx_codeMajor:
          type: string
        imsx_severity:
          type: string
        imsx_description:
          type: string
        imsx_CodeMinor:
          type: object
  responses:
    BadRequest11:
      description: Bad request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/imsxStatusInfoDType1'
    InternalError4:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/imsxStatusInfoDType1'
  securitySchemes:
    CognitoUserPoolAuthorizer:
      type: oauth2
      description: >-
        OAuth 2.0 client credentials flow. Contact timeback@trilogy.com to
        request credentials for your application.
      flows:
        clientCredentials:
          tokenUrl: https://platform.dev.timeback.com/auth/1.0/token
          scopes:
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster.readonly: roster readonly
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster-core.readonly: roster-core readonly
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster.createput: roster createput
            https://purl.imsglobal.org/spec/lti/v1p3/scope/lti.readonly: lti readonly
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster-demographics.readonly: roster-demographics readonly
            https://timeback-platform.trilogy.com/consent/scope/consent.write: consent write
            https://timeback-platform.trilogy.com/consent/scope/consent.read: consent read
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster-core.createput: roster-core createput
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster.delete: roster delete
            https://purl.imsglobal.org/spec/or/v1p2/scope/roster-core.delete: roster-core delete
            https://purl.imsglobal.org/spec/case/v1p0/scope/case.readonly: case readonly
            https://purl.imsglobal.org/spec/case/v1p0/scope/case.createput: case createput
            https://purl.imsglobal.org/spec/case/v1p0/scope/case.delete: case delete
            https://timeback-platform.trilogy.com/competency-track/scope/competency-track.readonly: competency-track readonly
            https://timeback-platform.trilogy.com/competency-track/scope/competency-track.write: competency-track write
            https://timeback-platform.trilogy.com/competency-track/scope/competency-track.delete: competency-track delete
            https://timeback-platform.trilogy.com/content/scope/content.write: content write
            https://timeback-platform.trilogy.com/content/scope/content.read: content read
            https://purl.imsglobal.org/spec/caliper/v1p2/scope/events.write: events write
            https://purl.imsglobal.org/spec/caliper/v1p2/scope/events.readonly: events readonly
            https://timeback-platform.trilogy.com/webhooks/scope/webhooks.write: webhooks write
            https://timeback-platform.trilogy.com/webhooks/scope/webhooks.read: webhooks read
            https://timeback-platform.trilogy.com/webhooks/scope/webhooks.delete: webhooks delete

````