> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Apply a judicial block on a PIX key

> Mirrors a Banco Central ofício onto this deployment's own key book (DICT 8.4 section 1.1): the key stops resolving on every internal query, which answers the block indication with none of the key's permitted data, and update, delete and claim all refuse it. The ofício reaches the participant on paper, so without this route the rail learns of the block only when a later call to BACEN happens to come back EntryBlocked — and keeps resolving the key with full owner and account data until then. One identified operator, no second approval: mirroring a court order is an obligation and not a judgement call. The ofício reference is mandatory and the act is audited under the caller's identity before and after the effect. Idempotent: a key already blocked answers 200 with alreadyApplied. A key whose current state cannot hold the block (never confirmed by BACEN, or already deregistered) is refused with 422.



## OpenAPI

````yaml /pt/openapi/v3-current/spi-dict.yaml post /api/v1/dict/internal/keys/block
openapi: 3.1.0
info:
  contact:
    email: contact@lerian.studio
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for the DICT (Diretório de Identificadores de Contas
    Transacionais) capability of Lerian SPI, the direct integration between the
    institution and the Brazilian Instant Payment System (SPI/Pix). It covers
    the PIX key lifecycle, portability and ownership claims, the MED 2.0 dispute
    surface (infraction reports, refunds, fraud markers, and funds recoveries),
    antifraud statistics, synchronous DICT reports, and the internal operations
    that keep the key directory consistent.
  license:
    name: Lerian Studio General License
  title: Lerian SPI — DICT API
  version: 1.0.0
servers:
  - url: https://spi.sandbox.lerian.net
security: []
tags:
  - description: 'PIX key lifecycle: register, list, search, lookup, delete, and statistics.'
    name: Keys
  - description: >-
      PIX key portability and ownership claims through their full lifecycle
      (initiate, confirm, reject, cancel, acknowledge, complete).
    name: Claims
  - description: 'DICT infraction reports: list and retrieve.'
    name: Infractions
  - description: 'DICT refund requests: create, list, and retrieve.'
    name: Refunds
  - description: 'PIX fraud markers: create, list, and statistics.'
    name: Fraud Markers
  - description: >-
      Durable MED operation-intent status: the operationId every
      create/lifecycle-transition backlog route returns or references on every
      outcome, queryable independently of the business resource.
    name: Operations
  - description: >-
      Synchronous reports over Lerian SPI's own DICT record: COUNT(*) summaries
      of keys (by type/status) and claims (by type/status + open-past-deadline).
      COUNT-only — DICT holds no money.
    name: Reports
  - description: >-
      Internal DICT operations: reconciliation runs, claim deadline processing,
      and orphaned-key cleanup.
    name: Internal
paths:
  /api/v1/dict/internal/keys/block:
    post:
      tags:
        - Internal
      summary: Apply a judicial block on a PIX key
      description: >-
        Mirrors a Banco Central ofício onto this deployment's own key book (DICT
        8.4 section 1.1): the key stops resolving on every internal query, which
        answers the block indication with none of the key's permitted data, and
        update, delete and claim all refuse it. The ofício reaches the
        participant on paper, so without this route the rail learns of the block
        only when a later call to BACEN happens to come back EntryBlocked — and
        keeps resolving the key with full owner and account data until then. One
        identified operator, no second approval: mirroring a court order is an
        obligation and not a judgement call. The ofício reference is mandatory
        and the act is audited under the caller's identity before and after the
        effect. Idempotent: a key already blocked answers 200 with
        alreadyApplied. A key whose current state cannot hold the block (never
        confirmed by BACEN, or already deregistered) is refused with 422.
      operationId: applyKeyJudicialBlock
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/KeyJudicialBlockRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KeyJudicialBlockResponse'
          description: OK
        '404':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Not Found
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Internal Server Error
        '503':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Service Unavailable
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
      security:
        - BearerAuth: []
components:
  schemas:
    KeyJudicialBlockRequest:
      additionalProperties: false
      properties:
        keyValue:
          description: >-
            PIX key the ofício names, in its canonical format for the key type.
            At most 77 characters, the ceiling BACEN publishes on a DICT key.
          examples:
            - '12345678901'
          maxLength: 77
          minLength: 1
          type: string
        oficioReference:
          description: >-
            Reference of the Banco Central ofício ordering (or revoking) the
            block — process number, document id, whatever the order carries.
            Recorded in the audit trail under the caller's identity and never
            emitted on the event topic. Operator prose only: never a tax id, a
            Pix key, an account or a holder name.
          maxLength: 384
          minLength: 8
          type: string
      required:
        - keyValue
        - oficioReference
      type: object
    KeyJudicialBlockResponse:
      additionalProperties: false
      properties:
        alreadyApplied:
          description: >-
            True when the key was already on the requested side of the block and
            nothing was written. The call is a success either way and is still
            audited under the caller's identity, so re-sending a request whose
            response was lost is safe.
          type: boolean
        keyValue:
          description: The key, as supplied.
          examples:
            - '12345678901'
          type: string
        status:
          description: The key's status after this call.
          enum:
            - ACTIVE
            - INACTIVE
            - PENDING_CLAIM
            - PENDING_BACEN_SYNC
            - BLOCKED
          examples:
            - BLOCKED
          type: string
      required:
        - keyValue
        - status
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          type: string
        correlationId:
          description: Request-scoped correlation identifier echoing X-Request-ID.
          examples:
            - req-7a3f9c2e
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      required:
        - correlationId
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````