Skip to navigation

Presign a limit-request document upload

Returns a 15-minute PUT URL. The browser uploads the bytes directly. The file then goes through the same quarantine, antivirus and sanitizer pipeline as MED evidence. Call .../evidence/add with the returned key. Allowed while the request is awaiting_documents or info_requested. documentType must belong to the account catalog, or be other when the reviewer asked for it.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Path parameters

accountIdstringRequired
Account identifier.
requestIdstringRequired
Limit request id.

Headers

X-Tenant-IdstringRequired
Tenant context used for authorization and routing.
X-Acting-DocumentstringOptional
CPF of the human performing the operation. Required on cashout routes when the credential enforces a transaction PIN.
Idempotency-KeystringOptional

Optional client-generated idempotency token (recommended for safe retries).

X-Request-TimestampstringRequired

Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).

X-Content-SHA256stringRequired

Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.

X-Request-SignaturestringRequired

Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.

Request

This endpoint expects an object.

Response

Presigned PUT.

Errors

409
Conflict Error
413
Content Too Large Error
422
Unprocessable Entity Error