> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Reveal a subscription's full destination (admin only)

> Returns one subscription's FULL delivery destination, unmasked: the webhook URL with its path and query, the queue URL with its account id, the exchange/routing-key pair, the bus name, or the synthesized pull:// URL.

ADMIN ONLY. Every other read on this surface answers with 'endpoint_display', the show-safe rendering that keeps scheme and host and drops everything after them. This route is the one that does not, and the reason it is fenced is that a destination is a CAPABILITY, not a description of one: a webhook path routinely carries a per-subscription callback token, and anyone holding the full value can be delivered to. The operator and viewer roles are refused here by this gateway's own authorization chain, before the request reaches the hub.

The body carries EXACTLY ONE key. No secret, no credential status, no other column of the row: this route answers a single question, and a body that grew the row's other fields would put them behind the admin action as a side effect of nobody deciding to.

The 200 carries 'Cache-Control: private, no-store'. The body is a live delivery capability rather than a view of one, so it must not reach a browser's disk cache, a synced profile or a forward proxy, where it would outlive the session entitled to it.

This is a FORWARD, not a local read: the gateway owns no subscription storage. The hub answers an unknown subscription, a soft-deleted one and another tenant's with the SAME 404, publishing no existence oracle, and that 404 reaches the caller unchanged. That uniformity matters more here than anywhere else on the surface: this route is reached with a strictly stronger grant, so a refusal that read differently would let an administrator of one tenant confirm that an id belongs to another.

The tenant is derived from the validated identity and is never read from the request.



## OpenAPI

````yaml /en/openapi/v3-current/consignado.yaml get /v1/subscriptions/{id}/endpoint
openapi: 3.1.0
info:
  contact:
    email: contact@lerian.studio
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for Lerian Consignado — Dataprev. The API covers tenant
    credentials and rail configuration, worker margin, loan auctions and bids,
    contract registration and lifecycle, disbursement confirmation, portability,
    refinancing, renegotiation, FGTS guarantees, reconciliation, funds,
    assignments, usage, throughput, and event subscriptions. Secret material is
    written to the tenant secret store and is never returned by any operation.
  license:
    name: Lerian Studio General License
  title: Lerian Consignado API
  version: v1.0.0
servers:
  - url: https://br-consignado-gw.sandbox.lerian.net
security:
  - BearerAuth: []
tags:
  - description: >-
      Per-tenant Dataprev credential custody and public rail configuration
      (upload, status, rotation, revoke, requester code, and worker portal base
      URL)
    name: Credentials
  - description: >-
      Tenant-scoped consignado gateway usage: priced billable-unit aggregation
      per competência
    name: Consignado Usage
  - description: >-
      Per-tenant streaming-hub subscription control-plane (list, create, get,
      rotate, revoke, and test delivery)
    name: Subscriptions
  - description: >-
      Dataprev payroll-rail surface: FGTS balance and authorization reads, the
      FGTS guarantee execution, contract suspension, reactivation and term
      changes, the rail's own contract documents, and the on-demand reads of
      leilão solicitações, escriturações, repasses and employment terminations
    name: Consignado Rail
  - description: >-
      Synchronous rail command surface: the operations a bancarizador without
      the lender drives over HTTP. Each shares its command implementation with
      the equivalent lender event trigger.
    name: Consignado Rail Commands
  - description: >-
      Gateway-owned disbursement confirmation: a client bank recording money it
      has ALREADY paid to a worker. It crosses no government boundary and
      proxies no Dataprev operation.
    name: Consignado Disbursement
  - description: >-
      Per-tenant self-service outbound Dataprev rail throughput: read and set
      this tenant's own requests-per-second, including a deliberate pause at
      zero
    name: Consignado Throughput
paths:
  /v1/subscriptions/{id}/endpoint:
    get:
      tags:
        - Subscriptions
      summary: Reveal a subscription's full destination (admin only)
      description: >-
        Returns one subscription's FULL delivery destination, unmasked: the
        webhook URL with its path and query, the queue URL with its account id,
        the exchange/routing-key pair, the bus name, or the synthesized pull://
        URL.


        ADMIN ONLY. Every other read on this surface answers with
        'endpoint_display', the show-safe rendering that keeps scheme and host
        and drops everything after them. This route is the one that does not,
        and the reason it is fenced is that a destination is a CAPABILITY, not a
        description of one: a webhook path routinely carries a per-subscription
        callback token, and anyone holding the full value can be delivered to.
        The operator and viewer roles are refused here by this gateway's own
        authorization chain, before the request reaches the hub.


        The body carries EXACTLY ONE key. No secret, no credential status, no
        other column of the row: this route answers a single question, and a
        body that grew the row's other fields would put them behind the admin
        action as a side effect of nobody deciding to.


        The 200 carries 'Cache-Control: private, no-store'. The body is a live
        delivery capability rather than a view of one, so it must not reach a
        browser's disk cache, a synced profile or a forward proxy, where it
        would outlive the session entitled to it.


        This is a FORWARD, not a local read: the gateway owns no subscription
        storage. The hub answers an unknown subscription, a soft-deleted one and
        another tenant's with the SAME 404, publishing no existence oracle, and
        that 404 reaches the caller unchanged. That uniformity matters more here
        than anywhere else on the surface: this route is reached with a strictly
        stronger grant, so a refusal that read differently would let an
        administrator of one tenant confirm that an id belongs to another.


        The tenant is derived from the validated identity and is never read from
        the request.
      operationId: revealSubscriptionEndpoint
      parameters:
        - description: Bearer token, relayed to the streaming-hub as server-to-server auth.
          in: header
          name: Authorization
          schema:
            description: >-
              Bearer token, relayed to the streaming-hub as server-to-server
              auth.
            examples:
              - >-
                Bearer
                eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJvcHMifQ.signature
            type: string
        - description: Subscription id.
          in: path
          name: id
          required: true
          schema:
            description: Subscription id.
            examples:
              - 0192f1a0-0000-7000-8000-0000000000ff
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EndpointResponse'
          description: OK
          headers:
            Cache-Control:
              schema:
                description: >-
                  Always "private, no-store": the body is the unmasked delivery
                  destination and must not be cached.
                type: string
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Internal Server Error
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
      security:
        - BearerAuth: []
components:
  schemas:
    EndpointResponse:
      additionalProperties: false
      properties:
        endpoint:
          description: >-
            The full delivery destination as stored, unmasked: the webhook URL
            with its path and query, the queue URL with its account id, the
            exchange/routing-key pair, the bus name, or the synthesized pull://
            URL.
          examples:
            - https://hooks.example.com/ingest
          type: string
      required:
        - endpoint
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable product error code. One of the enumerated
            values: the CLT-NNNN catalog codes for the general refusal classes;
            the named command conflicts, which a client branches on to tell one
            conflict from another; and the four IDEMPOTENCY_* terminal refusals
            (422), which tell the client to reconcile the original request and
            never retry under a new key.
          enum:
            - AVERBACAO_ARTIFACT_CONFLICT
            - AVERBACAO_CLAIM_CONFLICT
            - BID_PROPOSAL_SLOT_TAKEN
            - BID_SOLICITACAO_TAKEN
            - CLT-0001
            - CLT-0002
            - CLT-0003
            - CLT-0004
            - CLT-0005
            - CLT-0006
            - CLT-0007
            - CLT-0008
            - CLT-0009
            - CLT-0010
            - CLT-0011
            - CONTRACT_ALREADY_REGISTERED
            - DATAPREV_CREDENTIAL_REQUIRED
            - EXCLUSION_AUTHORITY_CONFLICT
            - EXCLUSION_AUTHORITY_QUARANTINED
            - FGTS_EXECUTION_ALREADY_REFUSED
            - FGTS_EXECUTION_CONTRACT_TAKEN
            - FGTS_EXECUTION_OUTCOME_UNRESOLVED
            - FGTS_EXECUTION_PAYLOAD_MISMATCH
            - IDEMPOTENCY_OUTCOME_UNRECORDED
            - IDEMPOTENCY_RECORD_UNREADABLE
            - IDEMPOTENCY_REPLAY_UNAVAILABLE
            - IDEMPOTENCY_STATE_UNRECOGNISED
            - RAIL_COMMAND_ANSWER_NOT_RETAINED
            - RAIL_COMMAND_CLAIM_CONFLICT
            - REVERSAO_WINDOW_EXPIRED
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````