> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Complete a BYOK Model-A signing-key import (SaaS)

> Forwards the tenant's already-wrapped, opaque key material (Model A — never cleartext) to KMS via the signer sidecar, then persists ONLY the public certificate + the per-tenant KMS reference + custody_provider=KMS (never key material). RBAC: signing-key:import (admin-only provisioning role). Field presence/type is validated against the schema (422); a malformed ISPB or invalid base64 is a coded 400. Idempotent via the MANDATORY Idempotency-Key header.



## OpenAPI

````yaml en/openapi/v3-current/slc.yaml post /v1/signing-key
openapi: 3.1.0
info:
  description: >-
    API for Lerian SLC — the participant-side rail that connects the institution
    to Núclea's SLC deferred-net card settlement. It covers settlement-operation
    intake and lifecycle, clearing positions, the participant and arrangement
    registry, generated reports, embedded XSD schema introspection, transmission
    recovery and connectivity to Núclea, BYOK Model-A signing-key import, and
    tenant-scoped webhooks.
  title: Lerian SLC API
  version: 1.0.0
servers:
  - url: https://slc.sandbox.lerian.net
security:
  - BearerAuth: []
tags:
  - description: >-
      Settlement operation lifecycle — create, list, query, and control the
      NUliquid-tracked card operations (NUliquid = the 21-position id Núclea
      assigns each accepted operation) through the state machine.
    name: Operations
  - description: >-
      Participant catalog — the acquirers, sub-acquirers, IF Domicílio (bank
      where the merchant receives its sales), and settlement FIs (financial
      institutions) that take part in card settlement.
    name: Participants
  - description: >-
      Card arrangements (bandeira/scheme configurations, e.g. Visa/Master/Elo)
      attached to a participant.
    name: Arrangements
  - description: >-
      Regulated transport orchestration to Núclea/SILOC (the private card
      clearing house that operates the SILOC settlement system) — dispatch,
      recovery, retransmission, and connectivity testing over managed
      file-transfer, message-broker, and REST.
    name: Connectivity
  - description: >-
      Multilateral netting clearing positions — the net amount each participant
      settles per STR cycle (STR = Banco Central reserves-transfer system).
    name: Clearing
  - description: >-
      SaaS BYOK (Bring Your Own Key) signing-key provisioning — import
      parameters and register the client's ICP-Brasil A1 (Brazilian PKI server
      certificate, 1-year validity) certificate material used to sign ASLC
      files; the private key never leaves the client's HSM/KMS/Vault.
    name: SigningKey
  - description: >-
      ASLC file intake and status — passthrough submission and processing status
      of the official Núclea card-settlement XML files (ASLC = Arquivo do
      Sistema de Liquidação de Cartões).
    name: Files
  - description: >-
      Read-only introspection of the embedded Núclea ASLC/RSFN (National
      Financial System Network) XSD schemas used to validate outbound and
      inbound messages.
    name: XSD Schemas
  - description: Read-only regulatory, compliance, and operational settlement reports.
    name: Reports
  - description: >-
      Outbound business-event webhook subscriptions and delivery management for
      consumers (Midaz, client ledgers, Cabine — all optional).
    name: Webhooks
  - description: >-
      Administrative operations — hot-reloadable runtime configuration,
      dead-letter-queue inspection/replay, and outbox redispatch.
    name: Admin
paths:
  /v1/signing-key:
    post:
      tags:
        - SigningKey
      summary: Complete a BYOK Model-A signing-key import (SaaS)
      description: >-
        Forwards the tenant's already-wrapped, opaque key material (Model A —
        never cleartext) to KMS via the signer sidecar, then persists ONLY the
        public certificate + the per-tenant KMS reference + custody_provider=KMS
        (never key material). RBAC: signing-key:import (admin-only provisioning
        role). Field presence/type is validated against the schema (422); a
        malformed ISPB or invalid base64 is a coded 400. Idempotent via the
        MANDATORY Idempotency-Key header.
      operationId: signingKeyImport
      parameters:
        - description: >-
            Idempotency key for safe retries (MANDATORY on this high-sensitivity
            endpoint).
          in: header
          name: Idempotency-Key
          schema:
            description: >-
              Idempotency key for safe retries (MANDATORY on this
              high-sensitivity endpoint).
            examples:
              - 018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SigningKeyImportRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SigningKeyImportResponse'
          description: OK
        '501':
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: >-
            Not Implemented: this capability is not part of this deployment.
            Operations are registered unconditionally so the published contract
            is identical across deploy shapes; when the capability behind one
            did not compose here (authentication disabled, no database, no
            outbound transport, or the feature switched off) it answers this
            coded SLC-0012 problem. It is definitive for this deployment:
            retrying does not help, and the `detail` is deliberately scrubbed
            (any status >= 500 is).
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
components:
  schemas:
    SigningKeyImportRequest:
      additionalProperties: false
      properties:
        encryptedKeyMaterialBase64:
          description: >-
            Base64-encoded wrapped private-key material (Model A — never
            cleartext).
          type: string
        importTokenBase64:
          description: Base64-encoded opaque KMS import token from the import-params step.
          type: string
        keyId:
          description: KMS key id returned by the import-params step.
          examples:
            - 018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e
          type: string
        participantIspb:
          description: Participant ISPB the certificate belongs to (8-digit identifier).
          examples:
            - '29011780'
          type: string
        publicCertPem:
          description: PEM-encoded PUBLIC ICP-Brasil A1 certificate.
          type: string
      required:
        - participantIspb
        - publicCertPem
        - keyId
        - importTokenBase64
        - encryptedKeyMaterialBase64
      type: object
    SigningKeyImportResponse:
      additionalProperties: false
      properties:
        certificateId:
          description: Stored public-certificate id.
          examples:
            - 018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e
          type: string
        kmsRef:
          description: Per-tenant KMS key reference.
          examples:
            - >-
              arn:aws:kms:us-east-1:000000000000:key/018f8a3e-4b2c-7c1a-9e5d-2f6a1b3c4d5e
          type: string
        status:
          description: Import result status.
          examples:
            - imported
          type: string
      required:
        - status
        - certificateId
        - kmsRef
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````