> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Issue the engine's SOAP channel credential

> Mints the three TAutenticacao values the engine presents to the Courier's /soap. The secret is returned once. Minting while a credential is live is the rotation: the older credentials keep working for the configured overlap window, then stop. The credential is stored only in the tenant's own database: on a send, the tenant manager lists the tenants and the tenant database that holds the legacy code authenticates; there is no shared index.



## OpenAPI

````yaml /pt/openapi/v3-current/jd-courier.yaml post /v1/engines/{engineId}/channel-credential
openapi: 3.1.0
info:
  description: >-
    The JD Courier API. Operators use it to manage the engines, the ownership
    map, the delivery modes and bypass of each rail, the retained messages, the
    SPB send journal and reconciliation. Engines use it to resolve the owner of
    a key, claim their Pix Automático recurrences and declare their Pix
    Automático payment legs.
  title: JD Courier API
  version: v1.0.0
servers: []
security:
  - BearerAuth: []
tags:
  - description: >-
      The engine registry: the cores that consume the JD channel through the
      Courier, each with its participant set
    name: Engines
  - description: 'The ownership map: which engine owns each key. Every change is audited.'
    name: ownership
  - description: >-
      The rails: what each declares about itself, its state per tenant, and the
      bypass declaration
    name: channels
  - description: >-
      The engines' side of the ownership map: resolution for the on-us gate,
      authoritative and never advisory, the claim of a Pix Automático recurrence
      the engine holds, and the declaration of a payment leg it holds.
    name: ownership-query
  - description: >-
      The durable message store: redelivery on demand, without asking the vendor
      again
    name: ledger
  - description: >-
      Count reconciliation per rail: E(m) = C(m) + T(m) + R(m), the sequence
      gaps it saw, and the sends whose return leg never arrived
    name: assurance
  - description: >-
      The SPB send journal: every send, written before it leaves, and the sends
      whose outcome is unknown. A by-hand close records an operator's finding
      and never resends.
    name: send-journal
  - description: >-
      Per-(tenant, channel) state an operator acts on: lifting a durable channel
      halt
    name: channel-leases
  - description: >-
      Messages the Courier holds because no engine could receive them. A routing
      or delivery retention leaves by itself once its cause lifts, or when an
      operator asks for its routing decision to be run again.
    name: retained
paths:
  /v1/engines/{engineId}/channel-credential:
    post:
      tags:
        - Engines
      summary: Issue the engine's SOAP channel credential
      description: >-
        Mints the three TAutenticacao values the engine presents to the
        Courier's /soap. The secret is returned once. Minting while a credential
        is live is the rotation: the older credentials keep working for the
        configured overlap window, then stop. The credential is stored only in
        the tenant's own database: on a send, the tenant manager lists the
        tenants and the tenant database that holds the legacy code
        authenticates; there is no shared index.
      operationId: mintEngineChannelCredential
      parameters:
        - in: path
          name: engineId
          required: true
          schema:
            type: string
        - description: >-
            Idempotency key. The answer carries a one-time secret and is never
            stored: a resend under the same key is refused 409, never replayed;
            a refused mint releases its key.
          in: header
          name: X-Idempotency
          required: true
          schema:
            description: >-
              Idempotency key. The answer carries a one-time secret and is never
              stored: a resend under the same key is refused 409, never
              replayed; a refused mint releases its key.
            type: string
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ChannelCredential'
          description: Created
        '400':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Bad Request
        '401':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unauthorized
        '403':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Forbidden
        '404':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Not Found
        '409':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Conflict
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Internal Server Error
        '503':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Service Unavailable
components:
  schemas:
    ChannelCredential:
      additionalProperties: false
      properties:
        createdAt:
          format: date-time
          type: string
        createdBy:
          type: string
        credentialId:
          description: Id of this credential, for revocation
          type: string
        engineId:
          type: string
        legacyCode:
          description: >-
            The value the engine configures as its JD legacy code (TAutenticacao
            CdLegado): 10 random base62 characters. Returned once.
          type: string
        secret:
          description: >-
            The value the engine configures as its JD password (TAutenticacao
            Senha): 20 random base62 characters. Returned once.
          type: string
        userCode:
          description: >-
            The value the engine configures as its JD user code (TAutenticacao
            CdUsuario): 10 random base62 characters.
          type: string
      required:
        - credentialId
        - engineId
        - legacyCode
        - userCode
        - secret
        - createdAt
        - createdBy
      type: object
    Detail:
      additionalProperties: true
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.