Resolve a MANUAL_REVIEW DICT MED operation
Relays a four-eyes ATTACH_BACEN_RESOURCE or CONFIRM_NOT_APPLIED decision for a MANUAL_REVIEW durable MED operation intent. ATTACH_BACEN_RESOURCE authoritative-GETs the proposed BACEN resource and validates it against this operation’s own reserved business identity BEFORE ever associating it, then applies the snapshot and completes the operation. CONFIRM_NOT_APPLIED declares BACEN never received the attempt, freeing the resource for the client’s own retry via its existing X-Idempotency. Idempotent by the request’s own X-Idempotency: a replayed delivery of the SAME decision returns the original outcome without repeating any side effect. A failed GET or a business-identity mismatch never transitions anything — the operation stays MANUAL_REVIEW.
Autorizações
JWT bearer token issued by the identity provider.
Cabeçalhos
The approval's own id — the SAME value on every delivery attempt of this exact decision, so a replayed callback returns the original outcome instead of repeating any side effect.
Parâmetros de caminho
The MANUAL_REVIEW operation's own id (operationId).
Corpo
The human checker's four-eyes decision, relayed unopened from the approval that produced it.
ATTACH_BACEN_RESOURCE, CONFIRM_NOT_APPLIED "ATTACH_BACEN_RESOURCE"
Lowercase-hex SHA-256 that must equal this operation's own requestFingerprint (GET /api/v1/dict/operations/{operationId}) — the callback's authenticity gate against a decision aimed at the wrong operation.
"2c26b46b68ffc68ff99b453c1d30413413422d706483bfa0f98a5e886266e7ae"
BACEN-assigned resource UUID the maker located by other means (e.g. an operator console). Required for ATTACH_BACEN_RESOURCE; must be absent for CONFIRM_NOT_APPLIED.
Resposta
OK
Durable MED operation-intent status.
Operation reservation timestamp (RFC 3339, UTC).
"2026-06-14T12:00:00Z"
MED resource kind this operation concerns.
infraction, refund, fraud_marker, funds_recovery "infraction"
This attempt's own identity; never the business resource's id.
"01930000-0000-7000-8000-000000000000"
Lowercase-hex SHA-256 of this operation's own canonical request — never the request body itself. Required as the digest field of a MANUAL_REVIEW resolution decision (ATTACH_BACEN_RESOURCE or CONFIRM_NOT_APPLIED) so the resolution callback can authenticate it is targeting the right operation.
"2c26b46b68ffc68ff99b453c1d30413413422d706483bfa0f98a5e886266e7ae"
Durable operation-intent lifecycle state — OUR attempt's status, distinct from the business resource's own BACEN-reported status. LOCAL_FAILURE means the attempt never reached BACEN (a local dependency fault, e.g. the DICT signer) — never BACEN's own verdict.
RESERVED, SUBMITTED, CONFIRMED, SYNC_PENDING, REJECTED, UNKNOWN_OUTCOME, MANUAL_REVIEW, ABANDONED, COMPLETED, LOCAL_FAILURE "UNKNOWN_OUTCOME"
Last status-transition timestamp (RFC 3339, UTC).
"2026-06-14T12:00:00Z"
BACEN verb this operation reserved.
create, update, acknowledge, close, cancel, refund "create"
BACEN's own sanitized operational envelope for the last interaction this operation recorded (correlation id + response time only, never payload); omitted when no BACEN interaction has landed yet.
BACEN-assigned resource UUID, once known; absent while a create's outcome is still unresolved.
"550e8400-e29b-41d4-a716-446655440000"

