どのようにお手伝いできますか?

OpenDSR API

  • 更新

概要:概要:この記事は、アプリの使用状況と計測を記録するためにプラットフォームを使用しているAppsFlyerのクライアント(広告主、またはアプリ所有者)を対象としています。アプリ所有者は、GDPR(ヨーロッパ)、CCPA(カリフォルニア)、LGPD(ブラジル)、PDPA(タイ)、およびPIPA(韓国)などの適用されるデータ保護法に準拠するために、OpenDSR(データ主体リクエスト)APIを実装します。

弁護士からの一言: ここに記載されていることは、一切法的な助言ではありません。これらは情報提供と便宜上の目的でのみ提供されています。あなたは、GDPR、CCPA、またはその他の法律がどのように適用されるか、または適用されないかを正確に判断するために、法務およびその他の専門アドバイザーと密接に連携するべきです。お客様とAppsFlyer 間のプライバシー事項については、AppsFlyer Services Privacy Policyに準拠しています。本サービスのプライバシーポリシーに関するご質問、または当社のデータ保護責任者へのお問い合わせは、 privacy@appsflyer.comまでご連絡ください。一般データ保護規則第27条の目的上、AppsFlyerのEU域内の代表者は AppsFlyer Germany GmbH, Schönhauser Allee 180, 10119 Berlin, Germany(ご連絡先privacy@appsflyer.comまたは+49-30-166373500)です。

プライバシー規制

この記事内のプライバシー規制には、次の表示に記載されている規制が含まれています。

規制 ロゴ 説明
GDPR GDPR.png 「一般データ保護規則(General Data Protection Regulation)」は、欧州連合(EU)における個人データ保護 およびプライバシーに関するEU規制です。
CCPA CCPA.png カリフォルニア州消費者プライバシー法(California Consumer Privacy Act)
LGPD LGPD.png Lei Geral de Proteção de Dados
PDPA 6137_Privacy_Shield_Thailand-01.png Personal Data Protection Act

プライバシー規制、GDPR、CCPA、LGPD、PDPAという用語は、この記事では同じ意味で使用されています。

OpenDSR イニシアチブ

プライバシー規制の遵守に向けて、データ主体からのリクエストに対処し管理するために、AppsFlyerは mParticle、Amplitude、Braze の3社と連携して OpenDSR プロトコル (旧:OpenGDPR) を構築しました。

OpenDSR はオープンソース・フレームワークで、個人データの公平かつ透明性のある使用のために、テクノロジー企業間の連携をサポートします。データプライバシーに関するアクションを複数のシステムにて処理し、保管することで、データプライバシー対策を取ることができます。

OpenDSRイニシアチブの詳細については、こちらを参照してください。

定義

DSR用語 AppsFlyer 用語 説明
データ主体(Data Subject) アプリユーザーまたはエンドユーザー データが収集されるアプリユーザー
データ管理者(Data Controller) アプリ所有者または広告主 個人データ処理の目的と手段を決定するアプリ所有者
データ処理者(Data Processor) AppsFlyerとそのパートナー データ管理者に代わって個人データの処理を行う、AppsFlyerと連携済みパートナー。

DSRの要件

DSRでは、データ主体(Data Subject)の義務と権利について詳細に定められており、アプリ所有者(Data Controller)はこれらを遵守しなければなりません。 APIでは、これらの権利はリクエストタイプに変換されています。以下では、AppsFlyerがさまざまなリクエストタイプを処理する方法について詳しく説明します。

リクエストタイプ

(権利)

GDPRの定義 AppsFlyerによるリクエストの処理
アクセス
  • リクエストがあった場合、アプリユーザーはアプリ所有者が個人データを処理するかどうか、その理由と期間を知る権利があります。
  • データがAppsFlyerなどの第三者と共有された場合、アプリユーザーはこの第三者が誰なのかを知る権利があります。
  • データ主体はどんな種類のデータが処理されているのか知る権利を有します。
  • If there is automated processing, that has a significant effect on them.
アプリ所有者は、アプリユーザーの処理された個人データのコピーを受信できます。
ポータビリティ アプリユーザーは自分の個人データのすべてを、構造化され、一般的に使用され、機械によって読み取り可能な形式(CSVファイルなど)で受け取る権利を有します。 アプリ所有者はアプリユーザーの処理された個人データのコピーを受信できます。
訂正 アプリユーザーは、自分の個人データが不正確であったり虚偽がある場合に訂正をリクエストできます。アプリ所有者は、不正確または不完全なデータを消去または修正する必要があります。
  • AppsFlyerは、訂正リクエストがあった日付以前のアプリユーザーのデータ削除します。
  • その後受信したデータはAppsFlyerによって記録されます。
削除 消去の権利により、アプリ所有者はリクエストを受けてから 14 日以内に個人データを削除する必要があります。 データは削除されます。

AppsFlyer の GDPR リクエスト API

このセクションで示すように GDPR Request API を使用して、DSR コンプライアンスを実装します。

  • GDPRリクエスト GDPRリクエスト:次のリクエストタイプのいずれかを実行します:アクセス、ポータビリティ、削除、訂正。
  • 2.GDPRリクエストにstatusポストバックのエンドポイントが指定されている場合、リクエストの直後に最初のポストバック(Pending)が送信され、続いて30秒間隔で2つのstatusポストバック(in_progress、completed)が送信されます。
  • Discovery Request: Inquire as to the supported API version and Data Format.
  • キャンセル 保留中の段階でGDPRリクエストをキャンセルする。

アプリ所有者は、アプリユーザーがリクエストを送信できるように、アプリにUIの変更を実装する必要があります。注:GDPRリクエストは1回につき1人のユーザーを対象とします。

1. GDPR request

GDPRリクエストフロー

The GDPR request types, Access, Portability, Erasure, and Rectification, have the following flow:

  1. App User submits a request.
  2. The App Owner constructs the GDPR request (see below) and sends it to AppsFlyer.
  3. AppsFlyer receives the request and responds with a "201 OK" for valid requests.
  4. For Access and Portability: Requests are fulfilled within 8 days.
    Note: This 8-day period begins when the App Owner submits their request. The request status changes to In Progress from pending and will be completed within an additional 6 days, totaling 8 days.
    For Erasure and Rectification:
    • During the following 48 hours, the request is queued and has a pending status. The App User may cancel the request.
    • After 48 hours, the request status changes to in_progress. AppsFlyer sends a status change postback. At this point, the request can't be canceled.
    • Within 10 days (see note below), AppsFlyer fulfills the request, and the request status changes to completed. AppsFlyer sends a status change postback.

      • In the case of erasure or rectification, the App User's data is deleted.
      • In the case of portability or access, the App User's data can be accessed in the AppsFlyer dashboard under GDPR or via the Request API (see below).

      Note: This 10-day period begins when the App Owner submits their request. After 48 hours, the request status changes to In Progress and will be completed within an additional 8 days, totaling 10 days.

GDPRリクエストのフォーマット

A GDPR Request API can be submitted via HTTP POST to the following endpoint:

https://hq1.appsflyer.com/api/gdpr/v1/opendsr_requests

For the API authorization, use the same V2 API token as for Pull API. An admin user can retrieve the token from the API token page in the dashboard. Add the token into the request header as follows: 'Authorization': 'Bearer %AuthTokenV2%'

パラメーター

Property Name Mandatory Description
subject_request_id Yes UUID v4 string. Generated by the controller at the time of request submission to a Processor. It can then be used in order to check the status of the request, update or cancel it.
subject_request_type Yes

String value representing the type of GDPR Request. Supported values:

  • erasure
  • portability
  • access
  • rectification
subject_identities Yes
  • An array of identity objects defining the requester's identity (see below).
  • Each request can contain only one subject identity.
submitted_time Yes
  • RFC 3339 date string of the time of the original request by the data subject
  • Timestamps in UTC
property_id Yes

String representing the mobile app to which this request is scoped:

Examples:

  • iOS: id123456789
  • Android: com.example, com.publishers.name
  • Android out-of-store: com.publisher.name-channel
    Note In some cases, App Owners record out-of-store attribution using the Android Google Play name. In these cases use the regular app name as it displays in the Dashboard.
api_version No Version string representing the desired version of the GDPR Requests API
status_callback_urls No, but recommended
  • An array of up to 3 endpoints for status callbacks to be sent to the following request status changes.
  • Only HTTPS endpoints are supported.
  • Invalid URLs are rejected.
platform

 
No Value is one of the supported DSR platforms:
android, ios, web, windowsphone
Yes

For a CTV, PC, or Console platform request, include any of the following platforms:

nativepc, playstation, roku, steam, webos, 
vidaa,tizen, smartcast, chatgpt, battlenet, 
quest, switch, xbox, epic

Subject_identities オブジェクト

Object type Mandatory Description
identity_type Yes
  • The identity type in string format for android, ios, web, windowsphone platforms are any of the following:
    • ios_advertising_id
    • android_advertising_id
    • fire_advertising_id
    • microsoft_advertising_id
    • appsflyer_id
    • customer_user_id (CUID)
  • For CTV, PC, and Consoleplatforms only the following:
    • appsflyer_id
    • customer_user_id (CUID)
  • Example: android_advertising_id

Important!

To use CUID through the OpenDSR API, you must send the CUID with idfa / appsflyer_id inside in-app events using event_name: Login - Complete or Registration - Account created

identity_value Yes
  • Format: String
  • Example: "a7551968-d5d6-44b2-9831-815ac9017798"
identity_format Yes
  • The method used to encode the identity_value: raw is the only supported:
  • Example: "raw"

例:GDPR消去要求

Example of an erasure request for android, ios, web, windowsphone platforms:

curl --location --request POST 'https://hq1.appsflyer.com/api/gdpr/v1/opendsr_requests' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer %AuthTokenv2% \
--data-raw '{
 "subject_request_id":"f4e5a271-f25e-4107-b681-************",
 "subject_request_type":"erasure",
 "submitted_time":"2020-07-05T10:00:00Z",
 "platform": "android",
 "subject_identities":[
  {
   "identity_type":"android_advertising_id",
   "identity_value":"55*****-****-****-************",
   "identity_format":"raw"
  }
 ],
 "api_version":"0.1",
 "property_id":"com.*********.*******.********",
 "status_callback_urls":[
  "https://examplecontroller.com/opengdpr_callbacks"
 ]
}'
 

Example of an erasure request forCTV, PC, and Console platforms:

curl --location --request POST 'https://hq1.appsflyer.com/api/gdpr/v1/opendsr_requests' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer %AuthTokenv2% \
--data-raw '
{"requester": "test@email.com",
"subject_request_id":"valid-uuid4-string",
"subject_request_type":"erasure",
"submitted_time":"2020-07-05T10:00:00Z",
"subject_identities":[
 {
  "identity_type":"appsflyer_id",
  "identity_value":"valid-appsflyer-id-string",
  "identity_format":"raw"
 }
],
"api_version":"0.1",
"property_id":"app-id",
"platform": "roku",
"status_callback_urls":[
 "https://examplecontroller.com/opengdpr_callbacks"
 ]
}'

 

GDPR 削除リクエストコードの例

Java
/*
using the okhttp package install from maven
https://mvnrepository.com/artifact/com.squareup.okhttp3/okhttp
 */

import okhttp3.*;
import java.io.IOException;

public class GdprSendRequest {
 public static void main(String[] args){

  OkHttpClient client = new OkHttpClient();
  RequestBody body = RequestBody.create(null, "" +
  "{\r\n\"subject_request_id\": \"\"," +
  "\r\n\"subject_request_type\": \"erasure\"," +
  "\r\n\"platform\": \"android\"," +
  "\r\n\"submitted_time\": \"2018-11-02T15:00:00Z\"," +
  "\r\n\"subject_identities\": [\r\n" +
  "{\r\n\"identity_type\": \"android_advertising_id\"," +
  "\r\n\"identity_value\": \"\"," +
  "\r\n\"identity_format\": \"raw\"\r\n}" +
   "\r\n]," +
   "\r\n\"property_id\": \"com.example.application\"}");

  Request request = new Request.Builder()
  .url("https://hq1.appsflyer.com/api/gdpr/v1/opendsr_requests/opendsr_requests")
  .post(body)
  .addHeader("Content-Type", "application/json")
  .addHeader("Accept", "application/json")
  .addHeader("Authorization: Bearer", "")
  .build();

  try {
   Response response = client.newCall(request).execute();
   System.out.println(response.code());
   System.out.println(response.body().string());
   System.exit(0);
  } catch (IOException e) {
   e.printStackTrace();
   System.exit(1);
  }
 }
}

PythonNode.jsC#
""" using the requests python package,
install using pip install requests """

import requests
import json
headers = {
 "Content-Type": "application/json",
 "Accept": "application/json",
 "Authorization: Bearer": ""
}

body = {
 "subject_request_id": "",
 "subject_request_type": "erasure",
 "submitted_time": "2018-10-02T15:00:00Z",
 "platform": "android",
 "subject_identities": [
  { "identity_type": "android_advertising_id",
   "identity_value": "",
   "identity_format": "raw" }
  ],
 "property_id": "com.example.application"
}
body = json.dumps(body)
res = requests.request("POST",
"https://hq1.appsflyer.com/api/gdpr/v1/opendsr_requests",
headers=headers, data=body, params=params)
print(res.text)
 
/* using the request npm package,
install using npm install request */

var request = require("request");
var options = { method: 'POST',
 url: 'https://hq1.appsflyer.com/api/gdpr/v1/opendsr_requests',
 headers:
 { Accept: 'application/json',
  'Content-Type': 'application/json',
  'Authorization: Bearer': '' },
 body:
 { subject_request_id: '',
  subject_request_type: 'erasure',
  submitted_time: '2018-10-02T15:00:00Z',
  platform: 'android',
  subject_identities:
  [ { identity_type: 'android_advertising_id',
   identity_value: '',
   identity_format: 'raw' } ],
 property_id: 'com.example.application'
 },
 json: true };
request(options, function (error, response, body) {
 if (error) throw new Error(error);

 console.log(body);
});
using System;
 using RestSharp;
 namespace CS
 {
  class Gdpr
  {
   static void Main(string[] args)
   {
 		var url = "https://hq1.appsflyer.com/api/gdpr/v1/opendsr_requests";
   var client = new RestClient(url);
   var request = new RestRequest(Method.POST);
   request.AddHeader("Content-Type", "application/json");
   request.AddHeader("Accept", "application/json");
   request.AddHeader("Authorization: Bearer", "")
   var body = "{\r\n\"subject_request_id\": \"\"," +
    "\r\n \"subject_request_type\": \"erasure\"," +
    "\r\n \"submitted_time\": \"2018-11-02T15:00:00Z\"," +
    "\r\n \"platform\": \"android\"," +
    "\r\n \"subject_identities\": [\r\n" +
    "{ \r\n \"identity_type\": \"android_advertising_id\"," +
    "\r\n \"identity_value\": \"\"," +
    "\r\n \"identity_format\": \"raw\"\r\n }" +
    "\r\n ]," +
    "\r\n \"property_id\": \"com.example.application\"}";

    request.AddParameter("undefined", body,ParameterType.RequestBody);
    IRestResponse response = client.Execute(request);
    // handle response by reading response.StatusCode
    Console.WriteLine(response.Content);
   }
  }
2. Status request

Every submitted GDPR request can be later queried for its status, by specifying the subject_request_id. There are four supported status types:

  1. pending - A correct request has been received and is currently in the queue
  2. in_progress - A request is currently being acted on
  3. completed - A request has been fulfilled
  4. canceled - A request has been canceled

Statusリクエストのフォーマット

A status request can be submitted via HTTP GET to the following endpoint:

https://hq1.appsflyer.com/api/gdpr/v1/opendsr_requests/<req_id>

Statusレスポンスの例

HTTP/1.1 200 OK
Content-Type: application/json
X-OpenGDPR-Processor Domain: example processor.com
X-OpenGDPR-Signature:
kiGlog3PdQx+FQmB8wYwFC1fekbJG7Dm9WdqgmXc9uKkFRSM4uPzylLi7j083461xLZ+mUloo3tpsmyIZpt5eMfgo7ejXPh6lqB4ZgCnN6+1b6Q3NoNcn/+11UOrvmDj772wvg6uIAFzsSVSjMQxRs8LAmHqFO4cF2pbuoPuK2diHOixxLj6+t97q0nZM7u3wmgkwF9EHIo3C6G1SI04/odvyY/VdMZgj3H1fLnz+X5rc42/wU4974u3iBrKgUnv0fcB4YB+L6Q3GsMbmYzuAbe0HpVA17ud/bVoyQZAkrW2yoSy1x4Ts6XKba6pLifIHf446Bubsf5r7x1kg6Eo7B8zur666NyWOYrglkOzU4IYO8ifJFRZZXazOgk7ggn9obEd78GBc3kjKKZdwaCrLx7WV5y9TMDCf+2FILOJM/MwTUy1dLZiaFHhGdzld2AjbjK1CfVzyPssch0iQYYtbR49GhumvkYl11S4oDfu0c3t/xUCZWg0hoR3XL3B7NjcrlrQinB1KbyTNZccKR0F4Lk9fDgwTVkrAg152UqPyzXxpdzXjfkDkSEgAevXQwVJWBNf18bMIEgdH2usF/XauQoyrne7rcMIWBISPgtBPj3mhcrwscjGVsxqJva8KCVCKD/4Axmo9DISib5/7A6uczJxQG2Bcrdj++vQqK2succ=
{
 "controller_id":"example_controller_id",
 "expected_completion_time":"2018-11-01T15:00:01Z",
 "subject_request_id":"a7551968-d5d6-44b2-9831-815ac9017798",
 "request_status":"pending",
}

Statusポストバック

As described in the GDPR Request Flow above, when the status of a GDPR request changes, from pending to in_progress to completed, AppsFlyer sends a GDPR postback to the requesting endpoints, specified with the status_callback_urls property.

Status postback example:

POST /opengdpr_callbacks HTTP/1.1
Host: examplecontroller.com
Content-Type: application/json
X-OpenGDPR-Processor Domain: gdpr.appsflyer.com
X-OpenGDPR-Signature: kiGlog3PdQx+FQmB8wYwFC1fekbJG7Dm9WdqgmXc9uKkFRSM4uPzylLi7j083461xLZ+mUloo3tpsmyIZpt5eMfgo7ejXPh6lqB4ZgCnN6+1b6Q3NoNcn/+11UOrvmDj772wvg6uIAFzsSVSjMQxRs8LAmHqFO4cF2pbuoPuK2diHOixxLj6+t97q0nZM7u3wmgkwF9EHIo3C6G1SI04/odvyY/VdMZgj3H1fLnz+X5rc42/wU4974u3iBrKgUnv0fcB4YB+L6Q3GsMbmYzuAbe0HpVA17ud/bVoyQZAkrW2yoSy1x4Ts6XKba6pLifIHf446Bubsf5r7x1kg6Eo7B8zur666NyWOYrglkOzU4IYO8ifJFRZZXazOgk7ggn9obEd78GBc3kjKKZdwaCrLx7WV5y9TMDCf+2FILOJM/MwTUy1dLZiaFHhGdzld2AjbjK1CfVzyPssch0iQYYtbR49GhumvkYl11S4oDfu0c3t/xUCZWg0hoR3XL3B7NjcrlrQinB1KbyTNZccKR0F4Lk9fDgwTVkrAg152UqPyzXxpdzXjfkDkSEgAevXQwVJWBNf18bMIEgdH2usF/XauQoyrne7rcMIWBISPgtBPj3mhcrwscjGVsxqJva8KCVCKD/4Axmo9DISib5/7A6uczJxQG2Bcrdj++vQqK2succ=

{
"controller_id":"example controller id at the processor",
"expected_completion_time":"2018-11-01T15:00:01Z",
"status_callback_url":"https://examplecontroller.com/opengdpr_callbacks",
"Subject_request_id":"a7551968-d5d6-44b2-9831-815ac9017798",
"Request_status":"pending"
}

ポストバックの検証

To validate the authenticity of incoming postbacks:

  1. Create an allowlist of all the processor domains that you allow to make callbacks.
  2. If the header value for X-OpenGDPR-Processor-Domain is in your allowlist, fetch the certificate.
    • The certificate URL is the value of processor_certificate in the /discovery response body.
    • You can also fetch the certificate directly from the AppsFlyer endpoint using the V2 API token as a bearer token in the authorization header: GET https://hq1.appsflyer.com/api/gdpr/v1/certificate
  3. Validate the certificate using a library to confirm that the certificate:
    1. Is issued by a trusted authority.
    2. Is issued to the same string provided in the X-OpenGDPR-Processor-Domain header value.
    3. Isn’t expired.
  4. Once you confirm the certificate is valid, use it to validate the X-OpenGDPR-Signature header against the raw request body. AppsFlyer uses SHA256 RSA as a signing algorithm.
  5. Get a response in the status header:
    1. 202 Accepted if validation is successful.
    2. 401 Unauthorized if the signature fails to validate or the processor domain isn’t in your allowlist.
3. Report request

Once an Access Request or Portability Request has been completed, you can download the report via HTTP GET to the following endpoint:

https://hq1.appsflyer.com/api/gdpr/v1/download/[REQUEST_ID]

The generated report is available for fourteen days from the time of completion.

4. Discovery request-in process

To learn about the formats supported by AppsFlyer, a discovery request can be submitted via HTTP GET to the following endpoint:

https://hq1.appsflyer.com/api/gdpr/v1/discovery

Discoveryレスポンスの例

HTTP/1.1 200 OK
Content-Type: application/json
{
 "api_version": "0.1",
 "supported_identities": [
 {
  "identity_type": "android_advertising_id",
  "identity_format": "raw"
 },
 ],
 "supported_subject_request_types": [
 "erasure", "access", "portability", "rectification"
 ],
 "processor_certificate": "https://exampleprocessor.com/cert.pem"
}
5. Cancellation request

It is possible to cancel a GDPR request, based on its subject_request_id, but only during the pending phase.

To submit an HTTP DELETE with subject_request_id :

https://hq1.appsflyer.com/api/gdpr/v1/opendsr_requests/<req_id>

Cancellationレスポンス

When a GDPR cancellation request is received, AppsFlyer returns an HTTP response with status code 202 and several other parameters.

Once the cancellation of the request takes place AppsFlyer sends a postback with the canceled status.

6. GDPR requests test API

This AppsFlyer API is a test API for the AppsFlyer's GDPR Requests API.

How does it work?

The test API works as follows:

1. Once a GDPR request has been made, the request is immediately placed in ‘Pending’ status. For testing purposes, the status changes every 30 seconds.

2. If an endpoint for a status postback has been inserted in the GDPR request, a first postback is sent right after the request and two more status postbacks are sent in 30-second intervals.

GDPR Request Test Endpoint: POST

https://hq1.appsflyer.com/api/gdpr/v1/stub

Status Request Test Endpoint: GET

https://hq1.appsflyer.com/api/gdpr/v1/stub/:requestId

Discovery Request Test Endpoint: GET

https://hq1.appsflyer.com/api/gdpr/v1/stub/discovery

Cancellation Request Test Endpoint: DELETE

https://hq1.appsflyer.com/api/gdpr/v1/stub/:requestId

Certificate Test Endpoint: GET

https://hq1.appsflyer.com/api/gdpr/v1/stubcertificate

Access/Portability Reports Test Endpoint: GET

https://hq1.appsflyer.com/api/gdpr/v1/stub/download/:requestId

Notes

  • A valid V2 API token must be inserted into the request header as follows: 'Authorization': 'Bearer %AuthTokenV2%'
  • In the ‘property_id’ property, the App ID must belong to the account owner (according to the API token).
7. Request logs

An admin user can access the GDPR requests submitted in the Logs Dashboard.

For completed access and portability requests, it is also possible to download the report from within this dashboard.

To access the Logs Dashboard:

  1. From the top bar, open the account menu (email address dropdown) > E-GDPR log.
  2. The following window opens:
GDPR_Table.png
8. GDPR API return codes and error messages

The GDPR API HTTP return codes and error messages are detailed in this section.

GDPR API リターンコード

Return code Description
201 Created
202 Cancelation request received
400 Bad request. The body contains the error code and message as listed in the table that follows.

HTTPリターンコード 400 - bad request

Messages having return code 400 contain a JSON with the error code and message.

{ "error": { "code":400, "af_gdpr_code": "%AF error code%", "message":"%error message text%" } }

リターンコード400 bad request のメッセージ

Error code Error description (message)
e211 Unable to cancel request with invalid status
e212 Request not permitted. Erasure is in progress for the identifier.
e213 Request already exists
e214 Request not found
e215 One or more subject-identities already exist in an open request. if another request for the same identity_value is currently open in ‘pending’ or ‘in_progress’ state.
e311 Invalid request content-type(リクエストのcontent-typeが無効です)
e312 Invalid API version(APIバージョンが無効です)
e313 Invalid subject_request_id( subject_request_id が無効です)
e314 Invalid submitted_time format( submitted_time format が無効です)
e315 Invalid status_callback_url length( status_callback_url の長さが無効です)
e316 Invalid status_callback_url format( status_callback_url の形式が無効です)
e317 Invalid app_id format( app_id の形式が無効です)
e318 Invalid identity_type( identity_type が無効です)
e319 Application platform does not match identity types(アプリのプラットフォームがIDタイプと一致しません)
e321 LAT users are not supported via api(LATユーザーはAPIでサポートされていません)
e322 Invalid subject_request_type( subject_request_type が無効です)
e323 Invalid subject_identities format( subject_identities の形式が無効です)
e324 Invalid subject_identities length( subject_identities の長さが無効です)
e325 Invalid subject_identities value( subject_identities の値が無効です)
e320 Invalid JSON format in request body
e411 AppID is incorrect or does not belong to your account(AppIDが正しくないかアカウントに属していません)
e412 No permissions to cancel erasure request(削除リクエストをキャンセルする権限がありません)
e413 No permissions to view request(リクエストを表示する権利がありません)
e511 内部で問題が発生しました。 60分経ってから再度お試しください。 If the problem persists contact AppsFlyer support. support@AppsFlyer.com

特性と制限

  • OpenDSR API レート制限:1分につき350リクエストこの制限を超えるとエラーが発生し、リクエストを再送信する必要があります。 Exceeding this limit will result in an error, requiring the request to be resent. このレート制限内に留まることで、1日あたり最大504,000件のリクエストが可能になります。
  • 60日以上前のリクエストステータスの確認:「リクエストが見つかりません」が返されます。