Block an end user's DICT key queries
Stops serving DICT key queries for one end user: DICT 8.4 section 13.2.3’s “o participante deve bloquear imediatamente o(s) usuario(s) em questao”, which the same sentence conditions on a human having verified fundada suspeita and elevado indicio of misuse. Every later key lookup naming this payer is refused 403 before any read — before the retained directory answer and before this deployment’s own registry — because the block is a statement about the person, not about our wire traffic. One identified operator, no second approval, mandatory justification, audited under the caller’s identity before and after the effect. Idempotent: an end user already blocked answers 200 with alreadyApplied. Name the end user by the hash the monitor read reports, or by their CPF/CNPJ, which is hashed here and never stored.
Authorizations
JWT bearer token issued by the identity provider.
Body
Why this end user is being blocked or released — the verified suspicion section 13.2.3 conditions the act on, in the operator's own words. Recorded in the audit trail under the caller's identity. Operator prose only: never a tax id, a Pix key, an account or a holder name.
8 - 384The end user's CPF or CNPJ, digits only — the same identifier their key queries carry in PI-PayerId. Hashed immediately and never stored, logged or returned. Supply this OR payerIdHash, not both.
^([0-9]{11}|[0-9]{14})$"12345678901"
Keyed digest of the end user's CPF/CNPJ, as the monitor read reports it. Supply this OR payerId, not both.
^[0-9a-f]{64}$"9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08"
Response
OK
Whether this end user's DICT key queries are blocked after the call.
true
Keyed digest of the end user this call acted on.
"9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08"
True when the end user was already on the requested side and nothing changed. The call is a success either way and is still audited under the caller's identity, so re-sending a request whose response was lost is safe.

