The Identity Envelope Decryption Endpoint

Learn how you can use the Retrieval API for identity envelope decryption.


Want API reference information for the Identity Envelope Decryption endpoint?

See Decrypt Identity Envelopes for more information.

You can use the Identity Envelope Decryption endpoint to decrypt identity envelopes into RampIDs.

What is an Identity Envelope?

An Identity envelope is an opaque and encrypted structure containing RampIDs and metadata. Each envelope is created with a client-specific encryption key that makes it unique. An envelope is valid for 30 days from the date of creation.

An envelope is represented as a Base64-encoded string.

Identity envelope string example


The string is different each time an envelope is created for the same underlying data as a result of randomization.

Identity Envelope Decryption

Due to the opaque nature of identity envelopes, they need to be decrypted into usable identifier data for the parties who receive them. The RampID API provides the decryption capability using the envelope decryption endpoint. This endpoint is used to decode and decrypt an envelope to extract the identifier in the envelope. The RampID API then encrypts the value with a partner-specific encryption key and partner ID. The result is a RampID in the partner ID space that is usable for transactions.

There is a limitation to the type of data the API can decrypt from. The data represented in the envelopes must correspond to a valid RampID. Data types such as cookie and mobile ID are not currently supported.

Envelope Decryption Endpoint

The API supports envelope lookups on Person-based identifiers. As the name implies, the input envelope must represent an individual in the underlying data, namely, with granularity of "X" (meaning INDIVIDUAL).

This endpoint supports POST operations with an envelope string passed in as a query parameter. The standard API parameters for the lookup endpoint are also applicable.

The URI path is:

  • /people/envelope?key=<envelope_string_representing_individual>

The API returns status code 200 to indicate a successful execution. The resulting decrypted RampID is made available in the anonymousConsumerLink attribute in the "anonymousAbilitec" bundle.

Unsuccessful responses from the endpoint may return status codes of 400 (bad request), 404 (not found) or 500 (server error). See Errors and Troubleshooting section for details.


Before Using the Identity Envelope Decryption Endpoint

In order to use this endpoint, a user must be set up with proper credentials and access permissions. A client representative can help with this setup. For making API calls, a user needs to have a client ID and a client secret. For more details, see "Request an Access Token".

Sample Requests and Responses

The following sample requests assume a valid access token is obtained and passed in the Authorization header.

Batch Calls

Due to privacy restrictions, you will need to transcode multiple envelopes at a time using batch calls. The API supports passing up to 1000 envelopes in the same batch call. This can be done by making a POST call to and passing in JSON that looks like:

 . . .

The response should look like:

  "person": {
    "anonymousAbilitec": {
      "anonymousConsumerLink": "XiT001sgRRky74xZ6NrpSsF6z2ucg6TeV8rISolIhOMe-R94lh47QP2xuVITxFm6otlyrB"
  "person": {
    "anonymousAbilitec": {
      "anonymousConsumerLink": "XiT001xuVITx94lh47QP2xuVITxFmyrBF6z2ucg6TeV8rIe-R94lh47Qh47QP2xrIhz2u"

Decrypting a Singular Envelope to a RampID

Sample request (example only, not valid for real-world use cases):

curl --header "Authorization: Bearer <ACCESS_TOKEN>" ''

Sample response with derived RampID output:

  "person": {
    "anonymousAbilitec": {
      "anonymousConsumerLink": "XiT001sgRRky74xZ6NrpSsF6z2ucg6TeV8rISolIhOMe-R94lh47QP2xuVITxFm6otlyrB"

Errors and Troubleshooting

In addition to error codes listed in Error documents, the envelope decryption endpoint may return the following errors:



Status Code


Invalid lookup request

Invalid keyType and documentClass combination


Only people documents are supported.

Invalid RampID granularity for document class


Only INDIVIDUAL granularity ("X") is supported

Unsupported RampID source in the envelope


The source type of the identity link data in the envelope is not supported by the API.

Invalid envelope



Envelope handle cannot be read.



Envelope handle is invalid/unsupported.

Envelope error: ENVELOPE_EXPIRED


Envelope was created at least 30 days ago and has expired.



Envelope does not contain at least 1 permitted publisher subnetwork.



Envelope payload cannot be decrypted using the key indicated by the handle.



Envelope string is not in valid Base64 format.

No matching entity

Entity in the envelope no longer exists


The entity represented in the envelope does not exist in the data repository any more.

Opted-out entity


The entity represented in the envelope has opted out.

Server error

Internal server error


An error was encountered on server side while processing the request.