> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Execute the FGTS guarantee for a contract

> Proxies execucao-garantias-fgts (Manual 017 §3.1). THIS MOVES CASH AND CANNOT BE UNDONE — it is marked x-money-path: true in this document. The guarantee executes AT MOST ONCE per (tenant, contract). X-Idempotency is required and is never defaulted; the gateway records the request durably BEFORE calling the rail.

The four conflict cases, all 409:
1. Same key, same body — the recorded outcome is REPLAYED (replayed: true) without touching the rail. This is the only non-conflict repeat.
2. Same key, DIFFERENT body — refused, never served the earlier answer.
3. A BRAND-NEW key for a contract that ALREADY has an execution record — REFUSED, not replayed. The stored outcome belongs to the other key, and a fresh key must not buy a second cash movement. This is a refusal, not a fault: nothing was claimed and the rail was not called.
4. The first attempt's outcome could not be established — the key is terminally unresolved. Retrying could execute the guarantee twice, and Manual 017 publishes no operation that asks the rail whether it already did, so reconciliation is an OPERATOR action, deliberately not an automatic one.

The two collateral values are Obrigatório=Não at the rail: OMIT them for a contract with no FGTS collateral. Sending 0 is refused locally with 422 — the rail reads 0 as an invalid guarantee value, and refusing early keeps the mistake from burning your idempotency key.



## OpenAPI

````yaml en/openapi/v3-current/consignado.yaml post /v1/consignado/fgts/garantias/execucao
openapi: 3.1.0
info:
  contact:
    email: contact@lerian.studio
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for Lerian Consignado — Dataprev. The API covers tenant
    credentials and rail configuration, worker margin, loan auctions and bids,
    contract registration and lifecycle, disbursement confirmation, portability,
    refinancing, renegotiation, FGTS guarantees, reconciliation, funds,
    assignments, usage, throughput, and event subscriptions. Secret material is
    written to the tenant secret store and is never returned by any operation.
  license:
    name: Lerian Studio General License
  title: Lerian Consignado API
  version: v1.0.0
servers:
  - url: https://consignado.sandbox.lerian.net
security:
  - BearerAuth: []
tags:
  - description: >-
      Per-tenant Dataprev credential custody and public rail configuration
      (upload, status, rotation, revoke, requester code, and worker portal base
      URL)
    name: Credentials
  - description: >-
      Tenant-scoped consignado gateway usage: priced billable-unit aggregation
      per competência
    name: Consignado Usage
  - description: >-
      Per-tenant streaming-hub subscription control-plane (list, create, get,
      rotate, revoke, and test delivery)
    name: Subscriptions
  - description: >-
      Dataprev payroll-rail surface: FGTS balance and authorization reads, the
      FGTS guarantee execution, contract suspension, reactivation and term
      changes, the rail's own contract documents, and the on-demand reads of
      leilão solicitações, escriturações, repasses and employment terminations
    name: Consignado Rail
  - description: >-
      Synchronous rail command surface: the operations a bancarizador without
      the lender drives over HTTP. Each shares its command implementation with
      the equivalent lender event trigger.
    name: Consignado Rail Commands
  - description: >-
      Gateway-owned disbursement confirmation: a client bank recording money it
      has ALREADY paid to a worker. It crosses no government boundary and
      proxies no Dataprev operation.
    name: Consignado Disbursement
  - description: >-
      Per-tenant self-service outbound Dataprev rail throughput: read and set
      this tenant's own requests-per-second, including a deliberate pause at
      zero
    name: Consignado Throughput
paths:
  /v1/consignado/fgts/garantias/execucao:
    post:
      tags:
        - Consignado Rail
      summary: Execute the FGTS guarantee for a contract
      description: >-
        Proxies execucao-garantias-fgts (Manual 017 §3.1). THIS MOVES CASH AND
        CANNOT BE UNDONE — it is marked x-money-path: true in this document. The
        guarantee executes AT MOST ONCE per (tenant, contract). X-Idempotency is
        required and is never defaulted; the gateway records the request durably
        BEFORE calling the rail.


        The four conflict cases, all 409:

        1. Same key, same body — the recorded outcome is REPLAYED (replayed:
        true) without touching the rail. This is the only non-conflict repeat.

        2. Same key, DIFFERENT body — refused, never served the earlier answer.

        3. A BRAND-NEW key for a contract that ALREADY has an execution record —
        REFUSED, not replayed. The stored outcome belongs to the other key, and
        a fresh key must not buy a second cash movement. This is a refusal, not
        a fault: nothing was claimed and the rail was not called.

        4. The first attempt's outcome could not be established — the key is
        terminally unresolved. Retrying could execute the guarantee twice, and
        Manual 017 publishes no operation that asks the rail whether it already
        did, so reconciliation is an OPERATOR action, deliberately not an
        automatic one.


        The two collateral values are Obrigatório=Não at the rail: OMIT them for
        a contract with no FGTS collateral. Sending 0 is refused locally with
        422 — the rail reads 0 as an invalid guarantee value, and refusing early
        keeps the mistake from burning your idempotency key.
      operationId: executeConsignadoFgtsGuarantee
      parameters:
        - description: >-
            Client-chosen idempotency key. REQUIRED: an absent key is 422, never
            a generated default. The key decides what a REPEAT gets back; the
            CONTRACT decides what may happen at all. Same key + same body: the
            recorded outcome is replayed without touching the rail. Same key +
            different body: 409. A BRAND-NEW key for a contract that already has
            an execution record: 409 — a fresh key does not buy a second
            execution. First attempt's outcome unestablished: 409 until an
            operator reconciles it.
          in: header
          name: X-Idempotency
          required: true
          schema:
            description: >-
              Client-chosen idempotency key. REQUIRED: an absent key is 422,
              never a generated default. The key decides what a REPEAT gets
              back; the CONTRACT decides what may happen at all. Same key + same
              body: the recorded outcome is replayed without touching the rail.
              Same key + different body: 409. A BRAND-NEW key for a contract
              that already has an execution record: 409 — a fresh key does not
              buy a second execution. First attempt's outcome unestablished: 409
              until an operator reconciles it.
            examples:
              - idem-fgts-exec-2026-07-30-0001
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/FgtsGuaranteeExecutionRequestBody'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FgtsGuaranteeExecutionResponse'
          description: OK
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
      security:
        - BearerAuth: []
components:
  schemas:
    FgtsGuaranteeExecutionRequestBody:
      additionalProperties: false
      properties:
        codigoInscricaoEmpregador:
          enum:
            - '1'
            - '2'
          examples:
            - '1'
          type: string
        cpf:
          description: >-
            Worker CPF, exactly 11 digits. In the BODY, never a path or query
            parameter.
          examples:
            - '99999999999'
          pattern: ^[0-9]{11}$
          type: string
        matricula:
          examples:
            - 99999999999-A
          minLength: 1
          type: string
        numeroContrato:
          description: Rail contract number.
          examples:
            - 99999999999AN1
          maxLength: 15
          minLength: 1
          type: string
        numeroInscricaoEmpregador:
          examples:
            - '42422253000101'
          minLength: 1
          type: string
        valorMultaRescisoriaGarantiaFgts:
          description: >-
            Rescission-penalty portion pledged as collateral (decimal string,
            BRL). Obrigatório=Não — omit rather than send 0.
          examples:
            - '100.00'
          pattern: ^[0-9]+(\.[0-9]{1,2})?$
          type: string
        valorSaldoDisponivelGarantiaFgts:
          description: >-
            Consignable FGTS balance pledged as collateral (decimal string,
            BRL). Obrigatório=Não at the rail: OMIT it for a contract with no
            FGTS collateral. Sending 0 is not an absence — the rail reads it as
            an invalid guarantee value.
          examples:
            - '98587.56'
          pattern: ^[0-9]+(\.[0-9]{1,2})?$
          type: string
      required:
        - numeroContrato
        - cpf
        - matricula
        - codigoInscricaoEmpregador
        - numeroInscricaoEmpregador
      type: object
    FgtsGuaranteeExecutionResponse:
      additionalProperties: false
      properties:
        dtPrevRepasse:
          description: Forecast repasse date (yyyy-MM-dd).
          examples:
            - '2026-07-15'
          type: string
        protocolo:
          description: >-
            Rail protocol number, up to 32 digits. A string so 32 digits survive
            without precision loss.
          examples:
            - '12345678901234567890123456789012'
          type: string
        replayed:
          description: >-
            true when this response was served from the durable record of an
            earlier identical request under the same X-Idempotency key, without
            touching the rail — the guarantee was executed once, and this is the
            recorded outcome. false means THIS call performed the execution.
          examples:
            - false
          type: boolean
      required:
        - protocolo
        - replayed
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````