> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# List the disbursement confirmations recorded for this tenant

> Walks the confirmations client banks recorded against this tenant, most recently confirmed first: money the client says it ALREADY paid a worker.

'orphan' is the field to read first. It is true when this deployment holds NO averbado contract under the confirmation's contract number, which means a client reported paying against a contract that is not here. It is DERIVED on every read from the same predicate the antecipação gate uses, never stored: storing it would create a second owner of the truth about whether a contract exists, and the two would disagree the moment an averbação landed after its confirmation.

Filter with 'orphan=true' to see only those, or 'orphan=false' for the matched ones. OMITTING the parameter is the whole book, which is what an operator arriving with no filter is asking for.

'amount' is the canonical BRL decimal STRING the client asserted, byte for byte as it was recorded, and it is never re-rendered: 'payload_digest' is taken over exactly those bytes, so a reformatted number would stop re-deriving the digest a client checks its own receipt against.

'confirmed_at' is when THIS GATEWAY stamped the confirmation and it is what orders the book. 'paid_at' is when the CLIENT says the money left, which is declared rather than observed, so it never orders anything: a client may declare any instant it likes, and a late confirmation ordered by it would insert itself in the middle of a page an operator had already walked past.

There is deliberately NO time window. A confirmation is immutable and is never purged, and a window would hide exactly the old orphan nobody ever reconciled.

Paging is keyset over the gateway's stamp and the confirmation id. Send the previous page's page.next_after as after. has_more is true exactly when another page exists, and next_after is null exactly when it is false, so a client loop may terminate on either. The cursor never expires; a cursor this service did not mint is refused with 422 rather than silently restarting the walk from the top.

It answers from a LOCAL table and crosses no government boundary. It answers 501 on a deployment that composed no disbursement family, the same posture the confirmation intake answers there: a deployment that can never record a confirmation has none to report, and an empty page would say the opposite. The tenant is derived from the validated identity and is never read from the request.



## OpenAPI

````yaml /en/openapi/v3-current/consignado.yaml get /v1/consignado/disbursement-confirmations
openapi: 3.1.0
info:
  contact:
    email: contact@lerian.studio
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for Lerian Consignado — Dataprev. The API covers tenant
    credentials and rail configuration, worker margin, loan auctions and bids,
    contract registration and lifecycle, disbursement confirmation, portability,
    refinancing, renegotiation, FGTS guarantees, reconciliation, funds,
    assignments, usage, throughput, and event subscriptions. Secret material is
    written to the tenant secret store and is never returned by any operation.
  license:
    name: Lerian Studio General License
  title: Lerian Consignado API
  version: v1.0.0
servers:
  - url: https://br-consignado-gw.sandbox.lerian.net
security:
  - BearerAuth: []
tags:
  - description: >-
      Per-tenant Dataprev credential custody and public rail configuration
      (upload, status, rotation, revoke, requester code, and worker portal base
      URL)
    name: Credentials
  - description: >-
      Tenant-scoped consignado gateway usage: priced billable-unit aggregation
      per competência
    name: Consignado Usage
  - description: >-
      Per-tenant streaming-hub subscription control-plane (list, create, get,
      rotate, revoke, and test delivery)
    name: Subscriptions
  - description: >-
      Dataprev payroll-rail surface: FGTS balance and authorization reads, the
      FGTS guarantee execution, contract suspension, reactivation and term
      changes, the rail's own contract documents, and the on-demand reads of
      leilão solicitações, escriturações, repasses and employment terminations
    name: Consignado Rail
  - description: >-
      Synchronous rail command surface: the operations a bancarizador without
      the lender drives over HTTP. Each shares its command implementation with
      the equivalent lender event trigger.
    name: Consignado Rail Commands
  - description: >-
      Gateway-owned disbursement confirmation: a client bank recording money it
      has ALREADY paid to a worker. It crosses no government boundary and
      proxies no Dataprev operation.
    name: Consignado Disbursement
  - description: >-
      Per-tenant self-service outbound Dataprev rail throughput: read and set
      this tenant's own requests-per-second, including a deliberate pause at
      zero
    name: Consignado Throughput
paths:
  /v1/consignado/disbursement-confirmations:
    get:
      tags:
        - Consignado Disbursement
      summary: List the disbursement confirmations recorded for this tenant
      description: >-
        Walks the confirmations client banks recorded against this tenant, most
        recently confirmed first: money the client says it ALREADY paid a
        worker.


        'orphan' is the field to read first. It is true when this deployment
        holds NO averbado contract under the confirmation's contract number,
        which means a client reported paying against a contract that is not
        here. It is DERIVED on every read from the same predicate the
        antecipação gate uses, never stored: storing it would create a second
        owner of the truth about whether a contract exists, and the two would
        disagree the moment an averbação landed after its confirmation.


        Filter with 'orphan=true' to see only those, or 'orphan=false' for the
        matched ones. OMITTING the parameter is the whole book, which is what an
        operator arriving with no filter is asking for.


        'amount' is the canonical BRL decimal STRING the client asserted, byte
        for byte as it was recorded, and it is never re-rendered:
        'payload_digest' is taken over exactly those bytes, so a reformatted
        number would stop re-deriving the digest a client checks its own receipt
        against.


        'confirmed_at' is when THIS GATEWAY stamped the confirmation and it is
        what orders the book. 'paid_at' is when the CLIENT says the money left,
        which is declared rather than observed, so it never orders anything: a
        client may declare any instant it likes, and a late confirmation ordered
        by it would insert itself in the middle of a page an operator had
        already walked past.


        There is deliberately NO time window. A confirmation is immutable and is
        never purged, and a window would hide exactly the old orphan nobody ever
        reconciled.


        Paging is keyset over the gateway's stamp and the confirmation id. Send
        the previous page's page.next_after as after. has_more is true exactly
        when another page exists, and next_after is null exactly when it is
        false, so a client loop may terminate on either. The cursor never
        expires; a cursor this service did not mint is refused with 422 rather
        than silently restarting the walk from the top.


        It answers from a LOCAL table and crosses no government boundary. It
        answers 501 on a deployment that composed no disbursement family, the
        same posture the confirmation intake answers there: a deployment that
        can never record a confirmation has none to report, and an empty page
        would say the opposite. The tenant is derived from the validated
        identity and is never read from the request.
      operationId: listConsignadoDisbursementConfirmations
      parameters:
        - description: >-
            Narrows the page to confirmations with no averbado contract here
            (true) or to matched ones (false). Omitted means the whole book,
            which is never the same as either half.
          explode: false
          in: query
          name: orphan
          schema:
            description: >-
              Narrows the page to confirmations with no averbado contract here
              (true) or to matched ones (false). Omitted means the whole book,
              which is never the same as either half.
            enum:
              - 'true'
              - 'false'
            examples:
              - 'true'
            type: string
        - description: >-
            The previous page's page.next_after. Omitted starts at the most
            recent confirmation. A cursor this service did not mint is refused,
            never restarted from the top.
          explode: false
          in: query
          name: after
          schema:
            description: >-
              The previous page's page.next_after. Omitted starts at the most
              recent confirmation. A cursor this service did not mint is
              refused, never restarted from the top.
            examples:
              - >-
                eyJ2IjoxLCJyIjoiYm9hcmQiLCJ0IjoiMjAyNi0wOC0xNFQwOToxMjozM1oiLCJrIjpbImMwMDEyIl19
            type: string
        - description: >-
            Maximum number of confirmations to return. Omitted means the ceiling
            of 200.
          explode: false
          in: query
          name: limit
          schema:
            description: >-
              Maximum number of confirmations to return. Omitted means the
              ceiling of 200.
            examples:
              - 50
            format: int64
            maximum: 200
            minimum: 1
            type: integer
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DisbursementConfirmationsPage'
          description: OK
        '401':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unauthorized
        '403':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Forbidden
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '429':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Too Many Requests
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Internal Server Error
        '501':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Not Implemented
        '503':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Service Unavailable
      security:
        - BearerAuth: []
components:
  schemas:
    DisbursementConfirmationsPage:
      additionalProperties: false
      properties:
        items:
          items:
            $ref: '#/components/schemas/DisbursementConfirmationItem'
          type: array
        page:
          $ref: '#/components/schemas/KeysetPageMetadata'
      required:
        - items
        - page
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    DisbursementConfirmationItem:
      additionalProperties: false
      properties:
        amount:
          description: The canonical BRL decimal string the client asserted, byte for byte.
          examples:
            - '1234.56'
          type: string
        confirmation_id:
          description: The gateway's identity for this confirmation.
          examples:
            - 1f5b9c26-6f5a-4f77-9c1c-5d1c0f0a9b21
          type: string
        confirmed_at:
          description: >-
            When THIS GATEWAY stamped the confirmation, in UTC. It is the
            ordering column.
          examples:
            - '2026-08-14T09:12:33Z'
          format: date-time
          type: string
        numero_contrato:
          description: The contract the client says it paid against.
          examples:
            - 99999999999AN1
          type: string
        orphan:
          description: >-
            True when this deployment holds no averbado contract under
            numero_contrato. Derived on every read, never stored.
          examples:
            - true
          type: boolean
        paid_at:
          description: >-
            When the CLIENT says the money left, in UTC. Declared, never
            observed, which is why it never orders this read.
          examples:
            - '2026-08-14T09:05:00Z'
          format: date-time
          type: string
        payload_digest:
          description: Lowercase hex SHA-256 over the canonical published payload.
          examples:
            - 3b1f2c9d5a47e08b6c1d4f2a8e7b0c93d6a51f84b2c7e903a1d5f6b8c2e4079a
          type: string
        payment_reference:
          description: The client's own identifier for the payment.
          examples:
            - PIX-2026-08-14-000123
          type: string
      required:
        - confirmation_id
        - numero_contrato
        - amount
        - paid_at
        - payment_reference
        - confirmed_at
        - payload_digest
        - orphan
      type: object
    KeysetPageMetadata:
      additionalProperties: false
      properties:
        after:
          description: >-
            The cursor this page resumed from, echoed back. Null when the read
            started at the beginning.
          examples:
            - >-
              eyJ2IjoxLCJyIjoiYm9hcmQiLCJ0IjoiMjAyNi0wOC0xNFQwOToxMjozM1oiLCJrIjpbImMwMDEyIl19
          type:
            - string
            - 'null'
        has_more:
          description: Whether at least one further page exists.
          examples:
            - true
          type: boolean
        next_after:
          description: >-
            The cursor for the page after this one. Null exactly when has_more
            is false.
          examples:
            - >-
              eyJ2IjoxLCJyIjoiYm9hcmQiLCJ0IjoiMjAyNi0wOC0xNFQwOTowNzo1MVoiLCJrIjpbImMwMDM3Il19
          type:
            - string
            - 'null'
      required:
        - after
        - next_after
        - has_more
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````