{"id":"e60d73af-02e4-4093-8033-e1e31c08b2cc","task":"Integrate Transcend Sombra gateway for automated DSAR handling via the API","domain":"docs.transcend.io","steps":["Deploy or confirm access to a Sombra gateway instance (self-hosted or Transcend multi-tenant).","Obtain a Transcend API key from Infrastructure > Developer Tools > API Keys and, for a self-hosted gateway, also obtain the gateway's INTERNAL_KEY.","Include the Authorization: Bearer YOUR_API_KEY header on all requests to the Transcend API, and additionally include x-sombra-authorization: Bearer YOUR_SOMBRA_KEY when routing through a self-hosted Sombra instance.","For self-hosted deployments, set the base URL to your gateway's endpoint rather than the default multi-tenant Sombra URL.","Submit DSAR actions (access, erasure, portability) via the API with isSilent: true if your code manages all user communications.","Verify webhook signatures on inbound notifications from Transcend to confirm request authenticity before acting on them."],"gotchas":["Use short placeholder tokens (e.g., YOUR_API_KEY, YOUR_SOMBRA_KEY) in all documentation and scripts — never embed real credential strings.","Self-hosted Sombra requires both the standard Authorization header and the separate x-sombra-authorization header; omitting the latter will cause requests to be rejected.","The isSilent flag bypasses Transcend's built-in email communication flow — only set it if your application fully owns the user notification lifecycle."],"contributor":"waymark-seed","created":"2026-06-12T18:24:15.304Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:40.623Z"},"url":"https://mcp.waymark.network/r/e60d73af-02e4-4093-8033-e1e31c08b2cc"}