> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Read DICT request-limiting buckets

> Projects the DICT's own request-limiting state for this participant, verbatim: available tokens, bucket capacity, refill amount and refill period per policy, plus the category (A→H) the BCB assigned — which is what fixes the size and refill of the key-query bucket. Read live from BACEN on every call (nothing is cached here) and never computed locally, so it is the authoritative answer to 'how much DICT quota do we have left'. Supply ?policy=<name> to read a single bucket. Internal admin endpoint.



## OpenAPI

````yaml /pt/openapi/v3-current/spi-dict.yaml get /api/v1/dict/internal/policies
openapi: 3.1.0
info:
  contact:
    email: contact@lerian.studio
    name: Lerian Studio
    url: https://lerian.studio
  description: >-
    OpenAPI 3.1 surface for the DICT (Diretório de Identificadores de Contas
    Transacionais) capability of Lerian SPI, the direct integration between the
    institution and the Brazilian Instant Payment System (SPI/Pix). It covers
    the PIX key lifecycle, portability and ownership claims, the MED 2.0 dispute
    surface (infraction reports, refunds, fraud markers, and funds recoveries),
    antifraud statistics, synchronous DICT reports, and the internal operations
    that keep the key directory consistent.
  license:
    name: Lerian Studio General License
  title: Lerian SPI — DICT API
  version: 1.0.0
servers:
  - url: https://spi.sandbox.lerian.net
security: []
tags:
  - description: 'PIX key lifecycle: register, list, search, lookup, delete, and statistics.'
    name: Keys
  - description: >-
      PIX key portability and ownership claims through their full lifecycle
      (initiate, confirm, reject, cancel, acknowledge, complete).
    name: Claims
  - description: 'DICT infraction reports: list and retrieve.'
    name: Infractions
  - description: 'DICT refund requests: create, list, and retrieve.'
    name: Refunds
  - description: 'PIX fraud markers: create, list, and statistics.'
    name: Fraud Markers
  - description: >-
      Durable MED operation-intent status: the operationId every
      create/lifecycle-transition backlog route returns or references on every
      outcome, queryable independently of the business resource.
    name: Operations
  - description: >-
      Synchronous reports over Lerian SPI's own DICT record: COUNT(*) summaries
      of keys (by type/status) and claims (by type/status + open-past-deadline).
      COUNT-only — DICT holds no money.
    name: Reports
  - description: >-
      Internal DICT operations: reconciliation runs, claim deadline processing,
      and orphaned-key cleanup.
    name: Internal
paths:
  /api/v1/dict/internal/policies:
    get:
      tags:
        - Internal
      summary: Read DICT request-limiting buckets
      description: >-
        Projects the DICT's own request-limiting state for this participant,
        verbatim: available tokens, bucket capacity, refill amount and refill
        period per policy, plus the category (A→H) the BCB assigned — which is
        what fixes the size and refill of the key-query bucket. Read live from
        BACEN on every call (nothing is cached here) and never computed locally,
        so it is the authoritative answer to 'how much DICT quota do we have
        left'. Supply ?policy=<name> to read a single bucket. Internal admin
        endpoint.
      operationId: readDICTPolicyBuckets
      parameters:
        - description: >-
            Read a single bucket by BACEN's own policy name instead of the whole
            list. Absent reads every bucket. A name BACEN does not know is
            answered by BACEN's own refusal, never by an empty bucket.
          explode: false
          in: query
          name: policy
          schema:
            description: >-
              Read a single bucket by BACEN's own policy name instead of the
              whole list. Absent reads every bucket. A name BACEN does not know
              is answered by BACEN's own refusal, never by an empty bucket.
            examples:
              - ENTRIES_READ_PARTICIPANT_ANTISCAN
            type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DICTPolicyBucketsResponse'
                description: >-
                  This deployment's live DICT request-limiting buckets and
                  category.
          description: OK
        '422':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Unprocessable Entity
        '429':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Too Many Requests
        '500':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Internal Server Error
        '503':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Service Unavailable
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
      security:
        - BearerAuth: []
components:
  schemas:
    DICTPolicyBucketsResponse:
      additionalProperties: false
      properties:
        category:
          description: >-
            The request-limiting category the BCB assigned this participant
            (A→H), which fixes the size and refill of the key-query bucket. The
            BCB assigns it and communicates changes; a letter outside A→H is
            reported verbatim rather than hidden, and is logged as an anomaly.
          examples:
            - A
          type: string
        correlationId:
          description: >-
            BACEN's own correlation identifier for this read, for operational
            support.
          examples:
            - B20220902101925801123456781A6998
          type: string
        policies:
          description: >-
            The buckets BACEN reported — every policy on the unfiltered read,
            exactly one when a policy name was supplied.
          items:
            $ref: '#/components/schemas/DICTPolicyBucketResponse'
          type: array
        responseTime:
          description: >-
            When BACEN answered (RFC 3339, UTC) — the instant the reported
            bucket states were true.
          examples:
            - '2026-08-21T13:19:25Z'
          type: string
      required:
        - category
        - policies
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          type: string
        correlationId:
          description: Request-scoped correlation identifier echoing X-Request-ID.
          examples:
            - req-7a3f9c2e
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
        upstream:
          $ref: '#/components/schemas/Upstream'
          description: >-
            RFC 9457 extension member: the error a proxied third-party provider
            reported. Absent unless the emitting service explicitly surfaced
            one.
      required:
        - correlationId
      type: object
    DICTPolicyBucketResponse:
      additionalProperties: false
      properties:
        availableTokens:
          description: >-
            Fichas left in the bucket at the instant BACEN answered. Not a live
            counter — re-read it.
          examples:
            - 49985
          format: int64
          type: integer
        capacity:
          description: The bucket's total size.
          examples:
            - 50000
          format: int64
          type: integer
        name:
          description: BACEN's own policy name, verbatim.
          examples:
            - ENTRIES_READ_PARTICIPANT_ANTISCAN
          type: string
        refillPeriodSec:
          description: The refill period, in seconds.
          examples:
            - 60
          format: int64
          type: integer
        refillTokens:
          description: Fichas BACEN puts back each refillPeriodSec.
          examples:
            - 25000
          format: int64
          type: integer
      required:
        - name
        - availableTokens
        - capacity
        - refillTokens
        - refillPeriodSec
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
    Upstream:
      additionalProperties: false
      properties:
        code:
          description: The upstream provider's own error code, verbatim.
          examples:
            - E4001
          type: string
        message:
          description: >-
            The upstream provider's own error message, verbatim (bounded, never
            its raw response body).
          examples:
            - account not found at provider
          type: string
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````