> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Authorise payment of an SLB charge

> Submits an SLB0002 authorising payment of a charge BACEN raised with an SLB0001, and returns a correlation id plus a PENDING projection. This request IS the authorisation: receiving the notice authorises nothing, so the decision to pay is made here. The amount must equal the charge in full — SLB admits no partial payment (Catálogo v5.13 Vol I) — and is checked against the stored charge before anything reaches the rail. A charge already settled or withdrawn is refused. When the deployment configures an alçada band covering the amount, the message parks in PENDING_APPROVAL and is not transmitted until the required signatures are collected.



## OpenAPI

````yaml /en/openapi/v3-current/spb.yaml post /v1/str/slb-payments
openapi: 3.1.0
info:
  contact:
    email: contact@lerian.studio
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for Lerian SPB, the direct integration between the
    institution and the Brazilian Payment System (SPB) over the National
    Financial System Network (RSFN). It covers the Reserve Transfer System
    (STR): message registry and capability catalog, operation lifecycle (bank
    transfers, IBS repasses, liquidity transfers, returns and cancellations),
    reserve-account and schedule queries, alçada governance, SME and LDL
    operations, inbound quarantine triage, reconciliation, and event delivery.
  license:
    name: Lerian Studio General License
  title: Lerian SPB API
  version: 1.0.0
servers:
  - url: https://spb.sandbox.lerian.net
security: []
tags:
  - description: Immutable audit-record trails for STR operations and lifecycle events.
    name: Audit
  - description: >-
      STR capability catalog describing supported message types and their
      constraints.
    name: Capabilities
  - description: >-
      ICP-Brasil certificate inventory with hot-reloadable rotation and
      activation.
    name: Certificates
  - description: >-
      STR compulsory-movement (RCO) family: the movements BACEN orders on a
      participant's reserve account, their answers and the periods they belong
      to.
    name: Compulsory
  - description: >-
      Maker-checker approval queue for emissions parked above their alçada band:
      list pending, sign (approve), and deny.
    name: EmissionApprovals
  - description: Webhook event-delivery records with retry control for failed dispatches.
    name: EventDeliveries
  - description: Operation event catalog enumerating the emitted domain event types.
    name: Events
  - description: >-
      Inbound GEN-family notice log (GEN0001 connectivity echo, GEN0004
      transmission error, GEN0005 administrative notice).
    name: GenNotices
  - description: >-
      SPB alçada governance config: value-band table + per-message-type
      signature requirements, hot-reloaded at runtime.
    name: Governance
  - description: >-
      Read raw STR message status: list messages and read a single message by
      NUOp.
    name: Messages
  - description: Aggregated operational summaries and metrics across STR operations.
    name: OperationalIntelligence
  - description: >-
      STR operation lifecycle for bank transfers and IBS repasses, including
      returns and cancellations.
    name: Operations
  - description: >-
      Service readiness state covering startup self-probes and dependency
      health.
    name: Readiness
  - description: Reconciliation cases and the actions that resolve operation discrepancies.
    name: Reconciliation
  - description: >-
      Redesconto do Banco Central: collateralised intraday and one-business-day
      BCB lending against Selic-registered federal securities. One create door
      derives the nine RDC commands from four operator-facing kinds (contract,
      payment, conversion, cancellation), plus the two consultas over
      eligible-security prices and open positions. An accepted rediscount is not
      necessarily a settled one — Selic may hold the request for want of
      securities, and that middle state is reported as its own.
    name: Rediscounts
  - description: >-
      STR Relatórios suite: synchronous, date-ranged aggregate reports
      (movimento financeiro, transações rejeitadas, volumetria) over Lerian
      SPB's own transmission record.
    name: Reports
  - description: >-
      STR0013 reserve-account balance and STR0014 statement (extrato,
      message-mode) queries and their async results.
    name: ReserveQueries
  - description: >-
      GEN0019 participant responsável roster: full-replacement updates announced
      to BACEN.
    name: Responsibles
  - description: STR operating-window schedule governing when operations may be sent.
    name: Schedule
  - description: >-
      STR0001 single-party schedule queries (consulta de horários do STR) and
      their async STR0001R1 grid results.
    name: ScheduleQueries
  - description: >-
      STR lançamentos (SLB) family: the charges BACEN raises against this
      participant, the payments that settle them, payments to BACEN it never
      demanded, and the entry consultas over them.
    name: SLB
  - description: >-
      Reads over an IEME's conta correspondente a moeda eletrônica (CCME):
      SME0003 statement (extrato) queries and their async SME0003R1 results,
      plus the log of SME0001R2/SME0002R2/SME0004R2 movement advices the STR
      delivered about movements this rail did not command.
    name: SMEQueries
  - description: Runtime SPB configuration settings for the STR integration.
    name: Settings
  - description: Webhook endpoint registration and management for event delivery.
    name: Webhooks
  - description: >-
      Flow (mandatory order): certificate → readiness → connectivity-test →
      submit. Activate a certificate, confirm the rail reports ready, pass a
      connectivity test, then submit an operation. Each step is its own
      resource; a submit must not be attempted before readiness passes.
    name: onboarding
  - description: >-
      Flow (mandatory order): parent operation SETTLED → return/cancel. A return
      or cancellation is a sub-resource of a settled parent operation; the
      {operationId}/{endToEndID} path segment enforces the parent structurally.
    name: lifecycle
paths:
  /v1/str/slb-payments:
    post:
      tags:
        - SLB
      summary: Authorise payment of an SLB charge
      description: >-
        Submits an SLB0002 authorising payment of a charge BACEN raised with an
        SLB0001, and returns a correlation id plus a PENDING projection. This
        request IS the authorisation: receiving the notice authorises nothing,
        so the decision to pay is made here. The amount must equal the charge in
        full — SLB admits no partial payment (Catálogo v5.13 Vol I) — and is
        checked against the stored charge before anything reaches the rail. A
        charge already settled or withdrawn is refused. When the deployment
        configures an alçada band covering the amount, the message parks in
        PENDING_APPROVAL and is not transmitted until the required signatures
        are collected.
      operationId: createSLBPayment
      parameters:
        - description: Idempotency key. Required on every mutation.
          in: header
          name: X-Idempotency
          required: true
          schema:
            description: Idempotency key. Required on every mutation.
            type: string
        - description: Idempotency key TTL in seconds.
          in: header
          name: X-TTL
          schema:
            description: Idempotency key TTL in seconds.
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateSLBPaymentRequest'
        required: true
      responses:
        '202':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SLBSubmissionAccepted'
          description: Accepted
        '400':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Bad Request
        '401':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unauthorized
        '403':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Forbidden
        '409':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Conflict
        '413':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Request Entity Too Large
        '415':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unsupported Media Type
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '429':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Too Many Requests
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Internal Server Error
        '503':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Service Unavailable
        '504':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Gateway Timeout
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
      security:
        - BearerAuth: []
components:
  schemas:
    CreateSLBPaymentRequest:
      additionalProperties: false
      properties:
        amount:
          description: >-
            The charge's FULL value in decimal reais. SLB admits no partial
            payment (Catálogo v5.13 Vol I), so anything other than the notified
            amount is refused.
          examples:
            - '1500.00'
          pattern: ^[1-9][0-9]{0,15}\.[0-9]{2}$|^0\.(0[1-9]|[1-9][0-9])$
          type: string
        controlNumberSLB:
          description: >-
            Control number (NumCtrlSLB) of the charge being paid, as the SLB0001
            notice carried it. Rule RSLB0002 makes it mandatory on the wire: a
            payment that does not name the charge it pays is not a payment of
            that charge.
          examples:
            - SLB20260915000000001
          maxLength: 20
          minLength: 1
          type: string
        preferenceLevel:
          description: Optional processing preference (NivelPref).
          examples:
            - '0001'
          maxLength: 4
          type: string
      required:
        - controlNumberSLB
        - amount
      type: object
    SLBSubmissionAccepted:
      additionalProperties: false
      properties:
        correlationId:
          description: Request-scoped correlation identifier echoing X-Request-ID.
          examples:
            - req-7a3f9c2e
          type: string
        id:
          description: >-
            Correlation id (the outbound NUOp). The answer leg is correlated to
            it.
          examples:
            - '46026562202609150000001'
          type: string
        messageType:
          description: The SLB wire code that was submitted.
          examples:
            - SLB0002
          type: string
        movementDate:
          description: >-
            BACEN business date (DtMovto) stamped on the frame, derived
            server-side.
          examples:
            - '2026-09-15'
          type: string
        numCtrlPart:
          description: >-
            This participant's own control number for the message — the handle
            BACEN quotes back on the answer.
          examples:
            - '20260915000000000001'
          type: string
        status:
          description: >-
            SUBMITTED when the message was queued for the rail, PENDING_APPROVAL
            when the configured alçada band parked it awaiting signatures.
          examples:
            - SUBMITTED
          type: string
        submittedAt:
          description: RFC3339 UTC timestamp the message was submitted.
          examples:
            - '2026-09-15T12:00:00Z'
          type: string
      required:
        - id
        - numCtrlPart
        - messageType
        - status
        - movementDate
        - submittedAt
        - correlationId
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          type: string
        correlationId:
          description: Request-scoped correlation identifier echoing X-Request-ID.
          examples:
            - req-7a3f9c2e
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      required:
        - correlationId
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````