Skip to main content
POST
Crear marcador de fraude

Autorizaciones

Authorization
string
header
requerido

JWT bearer token issued by the identity provider.

Cuerpo

application/json

Fraud marker to persist locally and report to BACEN synchronously-after-persist, tracked by report_status (PENDING/SENT/FAILED) + request_id; PII inputs (key value, owner tax ID) are hashed before storage

keyValue
string
requerido

Plaintext PIX key value to mark; stored only as an HMAC hash, never in the clear

Ejemplo:

"usuario@example.com"

ownerTaxId
string
requerido

Optional plaintext owner tax ID (CPF/CNPJ); stored only as an HMAC hash, never in the clear

Ejemplo:

"12345678901"

participantISPB
string
requerido

ISPB (8 numeric digits) of the participant raising the fraud marker

Ejemplo:

"12345678"

reason
string
requerido

Free-text justification for the fraud marker

Respuesta

Created

Persisted minimized fraud marker (PII stored only as hashes)

createdAt
string
requerido

Record creation timestamp (RFC 3339, UTC)

Ejemplo:

"2026-06-14T12:00:00Z"

id
string
requerido

Server-assigned fraud-marker record UUID

Ejemplo:

"550e8400-e29b-41d4-a716-446655440002"

keyValueHash
string
requerido

HMAC hash of the marked PIX key value (hex); the plaintext key is never returned

Ejemplo:

"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"

participantISPB
string
requerido

ISPB (8 numeric digits) of the participant that raised the fraud marker

Ejemplo:

"12345678"

reason
string
requerido

Free-text justification for the fraud marker

reportStatus
string
requerido

BACEN report delivery state: PENDING, SENT, or FAILED (FAILED is retryable; the local record stands)

Ejemplo:

"SENT"

status
string
requerido

Local fraud-marker state: ACTIVE (counts toward fraud stats) or INACTIVE (retained for audit only)

Ejemplo:

"ACTIVE"

updatedAt
string
requerido

Last update timestamp (RFC 3339, UTC)

Ejemplo:

"2026-06-14T12:00:00Z"

ownerTaxIdHash
string

HMAC hash of the owner tax ID (hex); omitted when no tax ID was supplied

Ejemplo:

"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"