Redact receipt
curl --request POST \
--url https://api.truthlocks.com/v1/receipts/{id}/redact \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"fields": [
"<string>"
],
"reason": "<string>"
}
'import requests
url = "https://api.truthlocks.com/v1/receipts/{id}/redact"
payload = {
"fields": ["<string>"],
"reason": "<string>"
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({fields: ['<string>'], reason: '<string>'})
};
fetch('https://api.truthlocks.com/v1/receipts/{id}/redact', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/receipts/{id}/redact",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'fields' => [
'<string>'
],
'reason' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/receipts/{id}/redact"
payload := strings.NewReader("{\n \"fields\": [\n \"<string>\"\n ],\n \"reason\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.truthlocks.com/v1/receipts/{id}/redact")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"fields\": [\n \"<string>\"\n ],\n \"reason\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/receipts/{id}/redact")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"fields\": [\n \"<string>\"\n ],\n \"reason\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"receipt_id": "<string>",
"status": "<string>",
"redacted_fields": [
"<string>"
]
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}Receipts
Redact Receipt
Remove PII from a receipt payload while preserving cryptographic proof.
POST
/
v1
/
receipts
/
{id}
/
redact
Redact receipt
curl --request POST \
--url https://api.truthlocks.com/v1/receipts/{id}/redact \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"fields": [
"<string>"
],
"reason": "<string>"
}
'import requests
url = "https://api.truthlocks.com/v1/receipts/{id}/redact"
payload = {
"fields": ["<string>"],
"reason": "<string>"
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({fields: ['<string>'], reason: '<string>'})
};
fetch('https://api.truthlocks.com/v1/receipts/{id}/redact', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/receipts/{id}/redact",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'fields' => [
'<string>'
],
'reason' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/receipts/{id}/redact"
payload := strings.NewReader("{\n \"fields\": [\n \"<string>\"\n ],\n \"reason\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.truthlocks.com/v1/receipts/{id}/redact")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"fields\": [\n \"<string>\"\n ],\n \"reason\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/receipts/{id}/redact")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"fields\": [\n \"<string>\"\n ],\n \"reason\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"receipt_id": "<string>",
"status": "<string>",
"redacted_fields": [
"<string>"
]
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}Removes PII from a receipt’s payload while preserving the cryptographic proof. The receipt’s signature, transparency log entry, and Merkle inclusion proof remain intact — only the
payload_json is replaced with a redaction marker.
Use this for GDPR right-to-erasure requests on receipts containing personal data.
Redaction is permanent. The original payload cannot be restored. The cryptographic proof remains valid for audit purposes.
Path parameters
string
required
UUID of the receipt to redact.
Headers
string
required
UUID for idempotent redaction.
Response
string
UUID of the redacted receipt.
string
redactedstring
ISO 8601 timestamp of redaction.
What changes after redaction
status→redactedpayload_json→{"redacted": true, "redacted_by": "tenant_request"}- A
RECEIPT_REDACTevent is anchored in the transparency log - All other fields (signature, log proof, receipt_type) are preserved
Authorizations
API key for machine-to-machine authentication
Path Parameters
Receipt UUID
Body
application/json

