Review recommended
STA
STA TLS trust configuration
STA uses system roots for BACEN TLS and does not use tenant trust-store configuration or a client certificate.Midaz
Midaz holder-account listing scope
Holder-account listings span the Organization unless you filter withledger_id.Flowker
Flowker HTTP content-digest pin
The generic HTTP executor can pin content with a SHA-256 digest and fails closed on a mismatch.Platform
Platform Helm version and configuration guidance
Helm guidance now reflects supported chart values, dependencies, components, and deployment prerequisites.ConsignadoLenderMidaz
Streaming catalog contract corrections
Consignado, Lender, and Midaz event references now reflect their current streaming catalogs.LenderReporterTEDPixStreaming Hub
Streaming integration contract corrections
Event, queue, and delivery contracts across streaming integrations are now explicit.PlatformLerian Console
Helm package version and Console prerequisites
Lerian Helm chart packages use plain semantic versions, and Console compatibility guidance is updated.Midaz
Midaz transaction lifecycle streaming
Midaz transaction lifecycle facts use the Kafka-compatible streaming surface, not the retired RabbitMQ event exchange.Tracer
Tracer CORS default
An unset or emptyCORS_ALLOWED_ORIGINS allows every origin; configure an explicit allow-list in production.Matcher
Matcher callback-provided SLA dates
Matcher stores SLA dates supplied by inbound callbacks; severity does not create a deadline.Lender
Lender assignment-set discard
Operators can discard an unsold assignment set while preserving its evidence and audit trail.Access ManagerPix
Access Manager Pix Lerian M2M applications
Access Manager now documents the Pix Lerian SPI, DICT, and COB application names for M2M setup.Matcher
Matcher event streaming contract
Matcher’s public CloudEvents, delivery policies, and manifest boundary are now documented in full.Midaz
Midaz event streaming contract
Midaz’s public Ledger-event payloads, manifest boundary, and delivery semantics are now explicit.Reporter
Reporter event streaming contract
Reporter’s 12 emitted CloudEvents now have complete delivery and payload contracts.TracerMidaz
Tracer event producer boundary
The standalone Tracer service and the Tracer component embedded in Midaz have different event contracts.Fetcher
Fetcher event routing and envelope contract
Fetcher event routing, DLQ keys, and legacy/current job identifiers are now documented.MidazLenderMatcherPixConsignado
Kafka topic auto-provisioning
Kafka-based streaming producers try to create fact and dead-letter topics by default at startup.Midaz
Midaz account-deletion balance contract
Account deletion requires zero available and on-hold balance; an in-progress transaction is not an independent blocker.Platform
Platform Helm deployment prerequisites
Component-specific Kubernetes API baselines now guide Helm deployment planning.Tracer
Tracer authentication and validation-history contract
Authentication precedence and the scope of stored validation history are now explicit.LenderTED
Lender streaming and portability contract
The streaming catalog and M011 portability-discovery prerequisites are documented.Matcher
Matcher consent, audit, and fee contracts
Aggregator connections can await consent, audit checks can resume withfromSeq, and rate-shaped fee expressions are limited to 0..1. Documentation correction; no runtime release is announced.Tracer
Tracer rule identity and permission declaration
Rule names are case-sensitive and preserve internal whitespace. Optional identity permission declaration is fail-open. Documentation correction; no runtime release is announced.PlatformAccess ManagerLerian Console
Platform Helm availability and prerequisites
Helm prerequisites, available charts, Console values, and compatibility guidance now reflect the supported inventory. Documentation correction; no runtime release is announced.LenderTED
Lender collection and Consignado event contract
Lender now documentscollection.instruction.issued and four configuration-gated portability and refinance outcome consumers. The current Consignado gateway contract includes the two portability outcomes, which are emitted only when the outcome consumer is enabled and the deployed gateway manifest declares the event; it does not declare the two refinance outcomes. Review event routing and feature flags before enabling affected integrations. Documentation correction; no runtime release is announced.MidazFetcherLenderTED
Consignado API and streaming contracts
The Consignado reference and guide now cover the client-facing API surface. v3 streaming contracts clarify application-topic routing, the public Midaz manifest boundary, operational portability proposals, and Fetcher terminal-event recovery. Review integrations before the next deployment. Documentation correction; no runtime release is announced.Matcher
Matcher ServiceNow connector and error catalog
Matcher documentation now covers the ServiceNow Table API incident connector, safe retry behavior, the public error catalog, and corrected source, rule, and priority guidance. Review connector configuration and client error handling. Documentation update; no new runtime release is announced.Fetcher
Fetcher direct-mode integrity contract
Direct-mode SHA-256 detects accidental corruption but does not authenticate payloads against tampering. Review security controls that rely on the digest.Lender
Lender assignment of receivables guide
The new guide separates a receivables assignment’s fund, eligibility, approval, file-exchange, and external-evidence lifecycle stages. Review operating controls before using the flow.Pix
SPI DICT discovery and inventory configuration
DICT workers have independent controls, defaults, and readiness thresholds; several are enabled by default. Review your SPI environment configuration and monitoring.Reporter
Reporter data-source support and deletion contract
What changedReporter supports PostgreSQL and MongoDB Data Sources only. PostgreSQL connections can specify schemas; MongoDB connections cannot. Reporter also refuses to delete a Data Source while a live Template references it.Who is affectedTeams that configure Reporter Data Sources or retire a database connection used by Templates.What you need to doConfirm that configured external Data Sources use PostgreSQL or MongoDB. Before retiring a connection, update or delete every live Template that references it.Lender
Lender authentication configuration contract
What changedLender configures authentication withPLUGIN_AUTH_ENABLED and PLUGIN_AUTH_HOST. AUTH_REQUIRED is not a Lender configuration variable and is no longer listed in the prerequisites or deployment checklist.Who is affectedTeams that configure Lender route authorization.What you need to doRemove reliance on AUTH_REQUIRED from Lender deployment templates and runbooks. Configure the two documented authentication variables and verify identity-provider reachability.Access Manager
Access Manager SSO preflight and fixed-organization setup
What changedAccess Manager documentation now covers non-mutating SSO provider preflight validation andPLUGIN_AUTH_SSO_STATIC_ORGANIZATION for a fixed-organization single-tenant BYOC deployment. Do not set the variable with MULTI_TENANT_ENABLED=true.Who is affectedTeams that configure Access Manager SSO, especially single-tenant BYOC deployments.What you need to doUse preflight before saving an SSO provider. Evaluate the static-organization option only for a fixed-organization single-tenant deployment.Flowker
Flowker workflow execution and observability model
What changedFlowker documentation now distinguishes workflow-graph execution, recorded processing nodes, and opt-in telemetry. Trigger nodes do not create step records, and the documentation no longer claims a Console execution dashboard.Who is affectedTeams that operate workflows or consume Flowker execution history and telemetry.What you need to doReview runbooks and execution-history consumers. Enable and connect a telemetry backend if you need OpenTelemetry data.Tracer
Tracer rule-engine performance claim removed
What changedTracer documentation no longer presents an unverified guarantee that compiled CEL expressions evaluate in under one millisecond.Who is affectedTeams that used the prior statement for Tracer performance planning or commitments.What you need to doReview sizing and latency commitments. Measure rule evaluation under your own rule sets and load.Lerian Console
Lerian Console deletion contract
What changedThe documentation now correctly states that deleting a Console user or application permanently removes it and cannot be undone. Application details show the name, description, ClientId, and ClientSecret; they do not show scopes or redirect URIs.Who is affectedTeams that administer users or applications in Lerian Console.What you need to doReview access-management runbooks before your next deletion. Do not rely on application details as a source of scope or redirect URI data.Platform
Helm chart coverage for BYOC deployments
What changedDeployment documentation now correctly states that official Helm charts are available for the products and platform components supported through Lerian’s Helm repository; it no longer states that every product has an official chart.Who is affectedTeams planning or operating BYOC deployments with Helm.What you need to doConfirm chart availability for your target product or platform component before planning a BYOC deployment.Midaz
Double-entry consistency guidance
What changedThe double-entry guide now states that matching the source total, destination total, and sent value in Midaz is an amount-consistency control. It does not itself prove authorization, classification, or completeness. The debit/source and credit/destination explanation applies to the illustrated transfer, not every account type.Who is affectedTeams using the guide for Midaz control design, audit evidence, or training.What you need to doReview material that treated double-entry balancing as proof that other financial controls passed, and keep those controls separate.Action required
PixTED
Pix and TED streaming delivery configuration
Pix Switch uses its fixed CloudEvents source, and TED RabbitMQ lifecycle delivery requires streaming.Matcher
Matcher authentication and actor-mapping contract
Matcher acceptsplugin-auth or disabled, and actor-mapping permissions use hyphenated names.Reporter
Reporter Data Source configuration and worker bootstrap
Reporter Data Source configuration, encryption, schema overrides, and worker RabbitMQ requirements are clarified.Lender
Lender M2M custody and ledger provisioning
Lender supports Vault KV v2 for M2M credentials and provisions Midaz ledger accounts by default.Pix
SILOC MQ activation contract
SILOC inbound SFN processing is controlled by its MQ connection descriptor, notSFN_INGEST_ENABLED.Midaz
Midaz Billing v2 ledger scope
Billing packages and calculations use ledger-scoped v2 routes; the URL is the only ledger input.Reporter
Reporter Data Source probe contract
Reporter probes Data Sources bydataSourceId; retrieve schema through a separate operation.Pix
SPI settlement streaming configuration
SPI requires streaming brokers at startup and its BR Code settlement consumer runs unconditionally.Reporter
Reporter Data Source deletion path
Reporter Data Source deletion usesdataSourceId, not the former connectionId path parameter.Consignado
Consignado sandbox server endpoint
Use the served Consignado sandbox host; the former hostname fails before HTTP.ConsignadoLender
Consignado streaming and replay contracts
Consignado event, command-gating, and redirection-replay behavior are now explicit.Reporter
Reporter template and data-source contracts
Reporter no longer claims unsupported regulatory mappings, and template uploads are limited to 1 MiB.Platform
Platform IP allowlist enforcement contract
Configure the trusted-proxy boundary before relying on an IP allowlist.Reporter
Reporter CCS encoding and data-source contract
CCS templates require UTF-16BE output, and multi-tenant data sources use the API.Midaz
Midaz route validation contract
Enable route validation before using Accounting Routes as transaction controls.LenderStreaming HubTED
Event streaming configuration and STA outcome contracts
Lender TLS certificates must be base64-encoded PEM, Consignado manifests use/v1/streaming/manifest, and Streaming Hub catalog matching uses resourceType and eventType. Review event and STA integrations before deployment. Documentation correction; no runtime release is announced.Midaz
Midaz fee asset contract
Fee requests require a non-emptysend.asset; DEFAULT_CURRENCY is not a fallback. Update fee clients and deployment templates. Documentation correction; no runtime release is announced.Reporter
Reporter data-source and preview contracts
Reporter data sources use an API-managed encrypted registry, reports use cursors, and exhausted template-preview capacity returns429 / RPT-0108. Update clients and configuration. Documentation correction; no runtime release is announced.Pix
SILOC CloudEvents source identity
SILOC now validatesSTREAMING_CLOUDEVENTS_SOURCE against the identity in the current Lerian deployment package; another value or surrounding whitespace prevents startup. Documentation correction; no runtime release is announced.PixTEDSTAConsignado
TED OUT completion and rail event contracts
TED OUT exposesCOMPLETED through its transfer and reconciliation APIs but does not emit transfer.completed yet. Do not use that event as a TED OUT completion signal; update completion handling before your next deployment. SPI now documents the mandate-resolution consumer, STA documents its effective defaults and inbound ZIP bounds, and Consignado exposes its streaming manifest endpoint. Documentation correction; no runtime release is announced.Tracer
Tracer asset field contract
Tracer usesasset, not currency, in limit and validation requests, rule inputs, returned validation context, and Console terminology. Replace the former field in payload builders, rules, and client models. Documentation correction; no runtime release is announced.Flowker
Flowker webhook and external API header contract
Webhookaccepted_headers and _webhook.headers ingestion rules are documented. External OpenAPI integrations support static headers and fail closed on missing required inputs. Review affected workflows before deployment. Documentation correction; no runtime release is announced.Lender
Lender migration and Consignado command contract
Migration directories are fixed in the service image; remove retiredMIGRATIONS_PATH from deployment configuration. consignado.margin.requested was retired later; only the exclusion and redirection commands remain. Documentation correction; no runtime release is announced.FetcherLenderMatcherMidazReporterTracer
Event streaming v3 application contract
v3 uses application topics, fixed producer sources, and source-qualified CloudEvents types. Matcher-to-Lender handoff is live when both runtimes are enabled; Reporter manifests use event keys without per-event topic fields. Review routing and configuration before deployment. Documentation correction; no runtime release is announced.LenderMidazReporterPix
Event streaming integration contracts
What changedThe event-streaming documentation now corrects Lender topic and retry semantics, Reporter delivery boundaries and identifier scope, and Midaz event payload and CRM topic conventions. It also documents streaming configuration requirements for Lender, Pix Switch, Boleto, and SLC.Who is affectedTeams that consume Lender, Midaz, or Reporter events, or operate the documented streaming integrations.What you need to doReview subscriptions, event parsers, retry controls, and deployment configuration before the next deployment. This is a documentation correction; it does not announce a runtime release.Streaming HubMidazLenderFetcherPix
Event streaming identity and delivery contracts
Deduplicate CloudEvents by(ce-source, ce-id) rather than ce-id alone. Use the documented event-type tokens and review Streaming Hub tenant and EventBridge routing before the next deployment.Matcher
Matcher duplicate-ingestion contract
Sources can define a mapped composite duplicate key, and the default duplicate policy isFLAG_AS_EXCEPTION. Review import configuration and exception handling before the next reconciliation run.Pix
SILOC ingress routing contract
SILOC uses a closed SFN product-message routing policy and deduplicates relayed funding byBCMSG.NUOp. Update settlement-ingress operating controls.Access Manager
Access Manager SSO tenant validation
Auth rejects an SSO callback when its email is missing or resolves to another tenant. Verify identity-provider claims and tenant mappings.Midaz
Midaz CRM and Fees Engine integration contract
Create holder-owned accounts withPOST /v2/organizations/{organization_id}/ledgers/{ledger_id}/holders/{id}/accounts. CRM and Fees Engine are integrated Midaz components; configure fees in Midaz, not as a plugin.Access Manager
Access Manager SSO and Helm configuration
Pre-login SSO matching usesdomain:. Set disablePasswordLogin explicitly when required, and review chart 8.6.0 with Auth and Identity 3.1.0 before upgrading.Reporter
Reporter trial-balance classification contract
Use rubric codes inaccountingEntries and each operation’s routeCode for new report classifications. Do not use deprecated OperationRoute.code as the source.Flowker
Flowker environment-label contract
prod and production both require production authentication guards. With the Tenant Manager secrets backend, set a non-empty ENV_NAME.Lender
Lender full-settlement prepayment event
Processlender.prepayment_quote.created only as a full-settlement prepayment-quote event; it does not cover every prepayment quote.Midaz
Midaz customer-closure v2 routes
What changedThe customer-account closure guide now uses the current/v2 Holder and Instrument routes for listing, updating, and archiving the Holder and its instruments. Only the CRM Holder and Instrument routes changed to /v2. The documented Ledger Balance and Ledger Account routes remain on /v1.Who is affectedTeams automating the Midaz customer-account closure flow.What you need to doReplace the former CRM Holder and Instrument /v1 paths in closure automation with the documented /v2 equivalents, then test the complete flow before your next production closure.Lender
Lender Consignado API and event contract
What changedThe Consignado API replacesPUT /v1/credentials/dataprev/taxa-mensal with PUT /v1/credentials/dataprev/portal-base-url. The Lender reference adds nine Consignado contract-divergence and compensating-adjustment operations, documents lender.loan_account.debt_balance_changed, and corrects guarantee recovery to lender.guarantee_recovery_cash.allocated. CONSIGNADO_ENABLED now documents its remaining legacy rejected-averbação handling only.Who is affectedTeams integrating with the Lender Consignado API, consuming its events, or operating the Consignado configuration.What you need to doReplace calls to the retired monthly-rate endpoint, validate portal URLs before sending them, update guarantee-recovery subscriptions, and review CONSIGNADO_ENABLED runbooks before the next deployment.Matcher
Matcher activation and fee-conflict contract
What changedSetup progress now exposescontext.activation.requirement.* values in readiness.missing and next.requirementId. An unready activation returns 409 with MTCH-0103 and those identifiers. Fee-schedule deletion conflicts use MTCH-0108 and include blocking contexts at errors.fee-schedule.delete.blocking-contexts.Who is affectedTeams that build Matcher setup flows or handle fee-schedule deletion conflicts.What you need to doUpdate client handling to use the public requirement identifiers, MTCH-0103 problem details, and the documented MTCH-0108 blocking-context field.Reporter
CADOC 4111 Reporter template contract
What changedThe CADOC 4111 guide now matches the testedregistros/registro XML layout, YYYY/MM/dd date format, and balance selection from the latest operation for each account-and-route pair.Who is affectedTeams using the Reporter CADOC 4111 template or a custom template derived from the previous guide.What you need to doUpdate and validate the template before your next CADOC 4111 submission. Do not sum every historical operation.Matcher
Matcher error and idempotency contract
What changedThe documentation now correctly describes Matcher’s RFC 9457 error envelope and idempotency-key constraints and retry behavior. Runtime behavior did not change.Who is affectedTeams integrating with the Matcher API.What you need to doAlign error parsing and generated idempotency keys with the documented contract before your next client release.Pix
SPI operations PII startup configuration
What changedThe documentation now correctly states that the SPI service requiresSPI_OPERATIONS_PII_ENCRYPTION_KEY to be a valid AES-256 key and SPI_OPERATIONS_BLIND_INDEX_PEPPER to contain at least 32 characters in every environment. Missing, malformed, or too-short values prevent the service from starting.Who is affectedTeams deploying or operating the SPI service for Pix operations.What you need to doBefore the next SPI start or redeployment, verify that both values are supplied through your secret manager and meet the documented requirements. Do not commit or log either value.Flowker
Flowker scheduler Redis isolation configuration
What changedThe documentation now correctly states that the Flowker scheduler has its own Redis configuration, but startup does not enforce isolation from the Redis used for tenant lifecycle events. Operators must provide a dedicated Redis instance or, when sharing an instance, a different logical database index.Who is affectedTeams running Flowker workers with scheduled workflows enabled.What you need to doVerify the scheduler Redis settings before enabling or continuing to run scheduled workflows. Point the scheduler to a dedicated Redis instance, or configure a logical database index that tenant lifecycle events do not use.Product index
August 26 additions: Platform IP allowlists enforce the configured trusted-proxy boundary; Reporter CCS templates require UTF-16BE output; Midaz validates direct transactions against route rules only when route validation is enabled; Helm guidance now identifies component-specific Kubernetes API baselines; Tracer documents authentication precedence and stored validation-history scope; and Lender documents its streaming catalog and M011 portability prerequisites. These are documentation corrections, not runtime-release announcements.
No action
OpenAPI specification downloads
API Reference now provides direct YAML downloads for every rendered specification.Deprecation
LenderConsignado
Lender streaming command deprecation
Lender no longer exposes the dormantconsignado.margin.requested command.
