Resolve which engine owns a key
Authoritative, never advisory. 200 resolved:true names the owning engine; 200 resolved:false is a decided negative — nobody’s key, or another tenant’s, indistinguishably; 503 means the Courier cannot answer and the caller fails the payment closed. This operation never answers 404. A POST that reads: the key is personal data and travels in the body, never in a URL. An engine treats ANY status other than 200 and 422 as fail-closed — 404, 405, 429 and every 5xx included — and keys on the code (JDC-9001), never on the detail sentence. The 503 sentence names what could not answer — the ownership map, or the engine credential (registry or tenant database) — and both tell the engine to fail closed.
Authorizations
Engines authenticate with an Access Manager application token.
- Token URL
- https://access-manager.example.com/oauth2/token
Body
The kind of key.
ACCOUNT, DOCUMENT, PIX_KEY_EMAIL, PIX_KEY_PHONE, PIX_KEY_RANDOM, PAYMENT_ID, PIX_RECURRENCE_ID ACCOUNT only: the account number, digits with an optional trailing check-digit letter.
256ACCOUNT only: a current account's branch, 1 to 4 digits. Omit it, or send it empty, for a payment account, which has none; empty is never branch 0.
256The key as the caller holds it, for every kind except ACCOUNT. Do not pre-normalize.
1 - 256Response
OK
ACCOUNT, DOCUMENT, PIX_KEY_EMAIL, PIX_KEY_PHONE, PIX_KEY_RANDOM, PAYMENT_ID, PIX_RECURRENCE_ID The normalized form the Courier resolved against.
256ASSIGNMENT_MAP Present only when resolved is true.
Present only when resolved is true: whether the owner is the engine whose credential made this call. Compare on this; an engine never needs its own registry id.

