Skip to main content
POST
Resolve a MANUAL_REVIEW DICT MED operation

Autorizaciones

Authorization
string
header
requerido

JWT bearer token issued by the identity provider.

Encabezados

X-Idempotency
string
requerido

The approval's own id — the SAME value on every delivery attempt of this exact decision, so a replayed callback returns the original outcome instead of repeating any side effect.

Parámetros de ruta

operationId
string<uuid>
requerido

The MANUAL_REVIEW operation's own id (operationId).

Cuerpo

application/json
action
enum<string>
requerido

The human checker's four-eyes decision, relayed unopened from the approval that produced it.

Opciones disponibles:
ATTACH_BACEN_RESOURCE,
CONFIRM_NOT_APPLIED
Ejemplo:

"ATTACH_BACEN_RESOURCE"

digest
string
requerido

Lowercase-hex SHA-256 that must equal this operation's own requestFingerprint (GET /api/v1/dict/operations/{operationId}) — the callback's authenticity gate against a decision aimed at the wrong operation.

Ejemplo:

"2c26b46b68ffc68ff99b453c1d30413413422d706483bfa0f98a5e886266e7ae"

bacenResourceId
string<uuid>

BACEN-assigned resource UUID the maker located by other means (e.g. an operator console). Required for ATTACH_BACEN_RESOURCE; must be absent for CONFIRM_NOT_APPLIED.

Respuesta

OK

Durable MED operation-intent status.

createdAt
string
requerido

Operation reservation timestamp (RFC 3339, UTC).

Ejemplo:

"2026-06-14T12:00:00Z"

kind
enum<string>
requerido

MED resource kind this operation concerns.

Opciones disponibles:
infraction,
refund,
fraud_marker,
funds_recovery
Ejemplo:

"infraction"

operationId
string
requerido

This attempt's own identity; never the business resource's id.

Ejemplo:

"01930000-0000-7000-8000-000000000000"

requestFingerprint
string
requerido

Lowercase-hex SHA-256 of this operation's own canonical request — never the request body itself. Required as the digest field of a MANUAL_REVIEW resolution decision (ATTACH_BACEN_RESOURCE or CONFIRM_NOT_APPLIED) so the resolution callback can authenticate it is targeting the right operation.

Ejemplo:

"2c26b46b68ffc68ff99b453c1d30413413422d706483bfa0f98a5e886266e7ae"

status
enum<string>
requerido

Durable operation-intent lifecycle state — OUR attempt's status, distinct from the business resource's own BACEN-reported status. LOCAL_FAILURE means the attempt never reached BACEN (a local dependency fault, e.g. the DICT signer) — never BACEN's own verdict.

Opciones disponibles:
RESERVED,
SUBMITTED,
CONFIRMED,
SYNC_PENDING,
REJECTED,
UNKNOWN_OUTCOME,
MANUAL_REVIEW,
ABANDONED,
COMPLETED,
LOCAL_FAILURE
Ejemplo:

"UNKNOWN_OUTCOME"

updatedAt
string
requerido

Last status-transition timestamp (RFC 3339, UTC).

Ejemplo:

"2026-06-14T12:00:00Z"

verb
enum<string>
requerido

BACEN verb this operation reserved.

Opciones disponibles:
create,
update,
acknowledge,
close,
cancel,
refund
Ejemplo:

"create"

bacen
object

BACEN's own sanitized operational envelope for the last interaction this operation recorded (correlation id + response time only, never payload); omitted when no BACEN interaction has landed yet.

bacenResourceId
string

BACEN-assigned resource UUID, once known; absent while a create's outcome is still unresolved.

Ejemplo:

"550e8400-e29b-41d4-a716-446655440000"