> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Replay one quarantined inbound frame

> Puts one parked frame's stored bytes back through the inbound path, exactly as a live delivery runs them, because the reason it was refused — a message code or an element from a newer BACEN catalogue, a datastore that was down — has stopped being true. THE REPLAY SENDS NO NOTICE OF ITS OWN TO BACEN: no second courtesy notice, no correction, no retraction — the notice they already hold for these bytes stays a historical fact. But a frame that decodes and whose processing requires an answer PRODUCES that answer through the normal inbound path, possibly long after the original. The bytes are replayed verbatim; nothing is re-framed, re-addressed or repaired. One frame per command, never a sweep. An unknown parkKey is refused; a frame that was already replayed is refused naming who replayed it and when; a frame that fails again is refused and stays parked and replayable, with the reason readable as lastReplayError on the triage listing. Every attempt is recorded on the audit trail under the operator derived from the bearer token. Requires str-inbound-quarantine:replay — the triage read grant does not carry it.



## OpenAPI

````yaml /en/openapi/v3-current/spb.yaml post /v1/str/inbound-quarantine/{parkKey}/replay
openapi: 3.1.0
info:
  contact:
    email: contact@lerian.studio
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for Lerian SPB, the direct integration between the
    institution and the Brazilian Payment System (SPB) over the National
    Financial System Network (RSFN). It covers the Reserve Transfer System
    (STR): message registry and capability catalog, operation lifecycle (bank
    transfers, IBS repasses, liquidity transfers, returns and cancellations),
    reserve-account and schedule queries, alçada governance, SME and LDL
    operations, inbound quarantine triage, reconciliation, and event delivery.
  license:
    name: Lerian Studio General License
  title: Lerian SPB API
  version: 1.0.0
servers:
  - url: https://spb.sandbox.lerian.net
security: []
tags:
  - description: Immutable audit-record trails for STR operations and lifecycle events.
    name: Audit
  - description: >-
      STR capability catalog describing supported message types and their
      constraints.
    name: Capabilities
  - description: >-
      ICP-Brasil certificate inventory with hot-reloadable rotation and
      activation.
    name: Certificates
  - description: >-
      Maker-checker approval queue for emissions parked above their alçada band:
      list pending, sign (approve), and deny.
    name: EmissionApprovals
  - description: Webhook event-delivery records with retry control for failed dispatches.
    name: EventDeliveries
  - description: Operation event catalog enumerating the emitted domain event types.
    name: Events
  - description: >-
      Inbound GEN-family notice log (GEN0001 connectivity echo, GEN0004
      transmission error, GEN0005 administrative notice).
    name: GenNotices
  - description: >-
      SPB alçada governance config: value-band table + per-message-type
      signature requirements, hot-reloaded at runtime.
    name: Governance
  - description: >-
      Read raw STR message status: list messages and read a single message by
      NUOp.
    name: Messages
  - description: Aggregated operational summaries and metrics across STR operations.
    name: OperationalIntelligence
  - description: >-
      STR operation lifecycle for bank transfers and IBS repasses, including
      returns and cancellations.
    name: Operations
  - description: >-
      Service readiness state covering startup self-probes and dependency
      health.
    name: Readiness
  - description: Reconciliation cases and the actions that resolve operation discrepancies.
    name: Reconciliation
  - description: >-
      STR Relatórios suite: synchronous, date-ranged aggregate reports
      (movimento financeiro, transações rejeitadas, volumetria) over Lerian
      SPB's own transmission record.
    name: Reports
  - description: >-
      STR0013 reserve-account balance and STR0014 statement (extrato,
      message-mode) queries and their async results.
    name: ReserveQueries
  - description: >-
      GEN0019 participant responsável roster: full-replacement updates announced
      to BACEN.
    name: Responsibles
  - description: STR operating-window schedule governing when operations may be sent.
    name: Schedule
  - description: >-
      STR0001 single-party schedule queries (consulta de horários do STR) and
      their async STR0001R1 grid results.
    name: ScheduleQueries
  - description: >-
      Reads over an IEME's conta correspondente a moeda eletrônica (CCME):
      SME0003 statement (extrato) queries and their async SME0003R1 results,
      plus the log of SME0001R2/SME0002R2/SME0004R2 movement advices the STR
      delivered about movements this rail did not command.
    name: SMEQueries
  - description: Runtime SPB configuration settings for the STR integration.
    name: Settings
  - description: Webhook endpoint registration and management for event delivery.
    name: Webhooks
  - description: >-
      Flow (mandatory order): certificate → readiness → connectivity-test →
      submit. Activate a certificate, confirm the rail reports ready, pass a
      connectivity test, then submit an operation. Each step is its own
      resource; a submit must not be attempted before readiness passes.
    name: onboarding
  - description: >-
      Flow (mandatory order): parent operation SETTLED → return/cancel. A return
      or cancellation is a sub-resource of a settled parent operation; the
      {operationId}/{endToEndID} path segment enforces the parent structurally.
    name: lifecycle
paths:
  /v1/str/inbound-quarantine/{parkKey}/replay:
    post:
      tags:
        - Reconciliation
      summary: Replay one quarantined inbound frame
      description: >-
        Puts one parked frame's stored bytes back through the inbound path,
        exactly as a live delivery runs them, because the reason it was refused
        — a message code or an element from a newer BACEN catalogue, a datastore
        that was down — has stopped being true. THE REPLAY SENDS NO NOTICE OF
        ITS OWN TO BACEN: no second courtesy notice, no correction, no
        retraction — the notice they already hold for these bytes stays a
        historical fact. But a frame that decodes and whose processing requires
        an answer PRODUCES that answer through the normal inbound path, possibly
        long after the original. The bytes are replayed verbatim; nothing is
        re-framed, re-addressed or repaired. One frame per command, never a
        sweep. An unknown parkKey is refused; a frame that was already replayed
        is refused naming who replayed it and when; a frame that fails again is
        refused and stays parked and replayable, with the reason readable as
        lastReplayError on the triage listing. Every attempt is recorded on the
        audit trail under the operator derived from the bearer token. Requires
        str-inbound-quarantine:replay — the triage read grant does not carry it.
      operationId: replayInboundQuarantineFrame
      parameters:
        - description: >-
            The frame's identity: the 64-character lowercase sha256 hex of the
            raw parked bytes, as published on the triage listing.
          in: path
          name: parkKey
          required: true
          schema:
            description: >-
              The frame's identity: the 64-character lowercase sha256 hex of the
              raw parked bytes, as published on the triage listing.
            type: string
        - description: Idempotency key. Required on every mutation.
          in: header
          name: X-Idempotency
          required: true
          schema:
            description: Idempotency key. Required on every mutation.
            type: string
        - description: Idempotency key TTL in seconds (overrides the service default).
          in: header
          name: X-TTL
          schema:
            description: Idempotency key TTL in seconds (overrides the service default).
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InboundQuarantineReplayResponse'
          description: OK
        '401':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unauthorized
        '403':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Forbidden
        '404':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Not Found
        '409':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Conflict
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '429':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Too Many Requests
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Internal Server Error
        '503':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Service Unavailable
        '504':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Gateway Timeout
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
      security:
        - BearerAuth: []
components:
  schemas:
    InboundQuarantineReplayResponse:
      additionalProperties: false
      properties:
        correlationId:
          description: >-
            Request-scoped correlation identifier echoing X-Request-ID, for
            pivoting from response to trace.
          type: string
        parkKey:
          description: The frame's identity, echoed back.
          examples:
            - 0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
          type: string
        processed:
          description: >-
            True when this command both put the frame back through the inbound
            path and claimed the row. A concurrent command that lost the claim
            is refused with 409 instead.
          type: boolean
        quarantineId:
          description: Evidence row UUID of the frame that was replayed.
          examples:
            - 2f8d1c40-0a1b-4c2d-8e3f-000000000001
          type: string
        stage:
          description: The stage the frame had originally been parked at.
          examples:
            - envelope_decode
          type: string
      required:
        - quarantineId
        - parkKey
        - stage
        - processed
        - correlationId
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - SPB-0001
          type: string
        correlationId:
          description: Request-scoped correlation identifier echoing X-Request-ID.
          examples:
            - req-7a3f9c2e
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      required:
        - correlationId
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````