IdukkiIdukki
Rights API

Rights-as-a-service · in private beta

The rights layer every UGC stack is missing.

Most teams pirate-rip UGC. We're building rights-clearance + an audit trail as a standalone API for ad networks, DSPs, agencies and every brand using UGC anywhere on the internet. In private beta, onboarding design partners now — pricing isn't set.

Rights API

Rights-as-a-service

Public-comment + consent-form request flow

  • Public-comment + consent-form

    Public-platform-comment request

  • Audit trail

    Full request/approve/reject

  • Compliance-aligned, not compliance-automated

    GDPR +

Audit traillive
  • Private beta
    Onboarding design partners now
  • 2
    Request channels live: platform comment + consent form
  • 3
    Compliance regimes we align to: GDPR, CCPA, DSA
  • In build
    External, authenticated API access
  • 01

    Public-comment + consent-form request flow

    We ask for rights the way the platforms actually allow it today: a public comment on the original post, plus a public consent form the creator can fill in. No DM automation exists — we’re not claiming it does.

    • Public-platform-comment request
    • Public consent-form capture
    • Manual admin review for edge cases
  • 02

    Audit trail

    Every request, approval and rejection is logged today. Cryptographic tamper-evidence (hash-chaining) is the beta’s build target, not shipped — the trail isn’t signed yet.

    • Full request/approve/reject history, live today
    • Tamper-evident hash-chain: build target, not shipped
    • Export formats: still being designed
  • 03

    Compliance-aligned, not compliance-automated

    Our audit trail is built around GDPR, CCPA and DSA recordkeeping expectations. We don’t yet offer pre-filled regional legal templates or an automated right-to-be-forgotten SLA — that’s roadmap, not shipped.

    • GDPR + CCPA + DSA-aligned event logging
    • Region-specific legal templates: not built
    • Automated takedown SLA: not built
  • 04

    External, authenticated API access

    The beta’s actual build: a real external API key with real enforcement, so partners outside Idukki can call the clearance and audit-trail endpoints directly. The key schema exists internally today; enforcing it externally is what design partners are helping us finish.

    • Per-partner API keys
    • Real request authentication — in active build
    • Read access to clearance status + audit history
  • 05

    Notifications: roadmap, not shipped

    Outbound webhooks (rights.granted, rights.revoked, rights.expired) don’t exist — there’s no webhook delivery infrastructure in the platform today, for any domain. Poll the audit endpoint for now.

    • No webhook infrastructure today
    • Poll-based status checks work today
    • Webhook events: roadmap
  • 06

    Human review, not just automation

    The comment + consent-form flow doesn’t catch every case — disputed ownership, non-responsive creators. Those go to the same manual review queue Idukki’s own dashboard uses internally.

    • Manual review queue for edge cases
    • Same reviewers as Idukki’s internal UGC ops
    • No fully automated fallback yet — by design
  1. Research
  2. Building
  3. Beta
  4. Live
Get a sandbox key as a design partner

Get a sandbox key as a design partner

Private beta is onboarding ad networks, DSPs, agencies and platform teams that move UGC at scale, to build the external API surface with real partners instead of in a vacuum. Tell us what you need — it shapes the build order.

  • Direct input into the API contract
  • Early access once external auth ships
  • No pricing commitment yet — pricing isn’t set

Cloudflare bot-protection

No spam. Unsubscribe anytime. We never sell your data.

We read every message and reply by email. If it fits, we suggest a call.

We use cookies

We use essential cookies to run this site and optional analytics cookies to understand how it’s used. You can change your choice anytime in our privacy policy.