# The consumer portal

> Every order carries an access code the consumer can use to see exactly what was furnished about them and dispute any item. How it works and what they see.

- **HTML:** https://offendersearch.app/docs/fcra/consumer-portal
- **Base URL:** https://api.offendersearch.app
- **Authentication:** `X-API-Key` request header, on an account with FCRA Partner Access
- **FCRA API reference as markdown:** https://offendersearch.app/docs/fcra.md

## An access code on every order

Every order has `consumerPortal.url` and `consumerPortal.accessCode`. Put both in the consumer’s copy of the report or your pre-adverse notice. With the code, their last name and their date of birth, the consumer can see exactly what we furnished about them in that order and dispute any item — without contacting you first.

## What the consumer sees

- The date of the order, the screening company that placed it, the business it was for, and the stated purpose.
- Every record furnished in that order, in plain language — for a registry record: the registry, the registration status and the offenses listed; for a criminal record: where it is held, the case number and filing date, and each charge with its disposition and date — with the name and date of birth as the record states them, and when it was re-verified.
- For each search, in plain language, what was searched: the states searched live and when, and the date the rest of the data is current to.
- A **Dispute this item** button on each record, and a tracker showing each dispute’s status, due date and outcome.

They never see withheld records, other orders, or anything not furnished in that order. The portal never asks for a Social Security number.

## Identity and protection

A view opens only when the access code, last name and date of birth all match the order; the code is accepted with or without its dashes, in any case. A mismatch returns the same generic message whatever was wrong, and five failures in an hour — for one code, or from one connection — lock further attempts for an hour. A session lasts 30 minutes, and a cancelled order cannot be opened.

## How portal disputes reach you

A dispute filed in the portal is the same dispute object you would open through the API, with `origin: "consumer_portal"`. You receive `dispute.created`, and every later status change as `dispute.updated`.

## Without an access code

A consumer without a code can still request their file or open a dispute at `/consumer`. We verify their identity before disclosing anything.

---

## Related

- Previous: [Disputes & reinvestigation](https://offendersearch.app/docs/fcra/disputes.md)
- Next: [Webhooks & events](https://offendersearch.app/docs/fcra/webhooks.md)
- Index: [FCRA API reference](https://offendersearch.app/docs/fcra.md)
