> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Upload a trust-store certificate

> Uploads a PEM-encoded X.509 certificate to the tenant trust store as multipart/form-data. Validates the PEM/X.509 body, rejects expired (422) and duplicate alias/fingerprint (409) certificates, persists the row + audit_outbox event in one transaction, and stores the PEM blob in object storage.



## OpenAPI

````yaml en/openapi/v3-current/sta.yaml post /v1/certificates
openapi: 3.1.0
info:
  description: >-
    API for Lerian STA — the participant-side rail that connects the institution
    to Banco Central do Brasil's STA (Sistema de Transferencia de Arquivos)
    file-exchange system. It covers outbound and inbound file transfers, BACEN
    credential management, inbound source polling configuration, and the tenant
    trust-store for message-signing certificates.
  title: Lerian STA API
  version: v1.0.0
servers:
  - url: https://sta.sandbox.lerian.net
security:
  - BearerAuth: []
paths:
  /v1/certificates:
    post:
      tags:
        - trust-store
      summary: Upload a trust-store certificate
      description: >-
        Uploads a PEM-encoded X.509 certificate to the tenant trust store as
        multipart/form-data. Validates the PEM/X.509 body, rejects expired (422)
        and duplicate alias/fingerprint (409) certificates, persists the row +
        audit_outbox event in one transaction, and stores the PEM blob in object
        storage.
      operationId: uploadCertificate
      requestBody:
        content:
          multipart/form-data:
            encoding:
              certificate:
                contentType: application/octet-stream
              description:
                contentType: text/plain
              name:
                contentType: text/plain
            schema:
              properties:
                certificate:
                  contentEncoding: binary
                  contentMediaType: application/octet-stream
                  description: PEM-encoded X.509 certificate
                  format: binary
                  type: string
                description:
                  description: Human-readable description
                  type: string
                name:
                  description: Unique certificate alias
                  type: string
              required:
                - name
                - certificate
              type: object
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UploadResponse'
          description: Created
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
      security:
        - BearerAuth: []
components:
  schemas:
    UploadResponse:
      additionalProperties: false
      properties:
        alias:
          type: string
        description:
          type: string
        fingerprint:
          type: string
        id:
          type: string
        issuer:
          type: string
        serialNumber:
          type: string
        subject:
          type: string
        validFrom:
          type: string
        validUntil:
          type: string
      required:
        - id
        - alias
        - subject
        - issuer
        - serialNumber
        - validFrom
        - validUntil
        - fingerprint
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````