> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Cargar un certificado del trust-store

> Carga un certificado X.509 codificado en PEM al trust store del tenant como multipart/form-data. Valida el cuerpo PEM/X.509, rechaza los certificados vencidos (422) y con alias/fingerprint duplicados (409), persiste la fila + el evento audit_outbox en una sola transacción y almacena el blob PEM en el almacenamiento de objetos.



## OpenAPI

````yaml es/openapi/v3-current/sta.yaml post /v1/certificates
openapi: 3.1.0
info:
  description: >-
    API de Lerian STA — el rail del lado del participante que conecta la
    institución con el sistema de intercambio de archivos STA (Sistema de
    Transferência de Arquivos) del Banco Central do Brasil. Cubre las
    transferencias de archivos salientes y entrantes, la gestión de credenciales
    de BACEN, la configuración del sondeo de fuentes entrantes y el trust-store
    del tenant para los certificados de firma de mensajes.
  title: Lerian STA API
  version: v1.0.0
servers:
  - url: https://sta.sandbox.lerian.net
security:
  - BearerAuth: []
paths:
  /v1/certificates:
    post:
      tags:
        - trust-store
      summary: Cargar un certificado del trust-store
      description: >-
        Carga un certificado X.509 codificado en PEM al trust store del tenant
        como multipart/form-data. Valida el cuerpo PEM/X.509, rechaza los
        certificados vencidos (422) y con alias/fingerprint duplicados (409),
        persiste la fila + el evento audit_outbox en una sola transacción y
        almacena el blob PEM en el almacenamiento de objetos.
      operationId: uploadCertificate
      requestBody:
        content:
          multipart/form-data:
            encoding:
              certificate:
                contentType: application/octet-stream
              description:
                contentType: text/plain
              name:
                contentType: text/plain
            schema:
              properties:
                certificate:
                  contentEncoding: binary
                  contentMediaType: application/octet-stream
                  description: PEM-encoded X.509 certificate
                  format: binary
                  type: string
                description:
                  description: Human-readable description
                  type: string
                name:
                  description: Unique certificate alias
                  type: string
              required:
                - name
                - certificate
              type: object
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UploadResponse'
          description: Created
        default:
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Detail'
          description: Error
      security:
        - BearerAuth: []
components:
  schemas:
    UploadResponse:
      additionalProperties: false
      properties:
        alias:
          type: string
        description:
          type: string
        fingerprint:
          type: string
        id:
          type: string
        issuer:
          type: string
        serialNumber:
          type: string
        subject:
          type: string
        validFrom:
          type: string
        validUntil:
          type: string
      required:
        - id
        - alias
        - subject
        - issuer
        - serialNumber
        - validFrom
        - validUntil
        - fingerprint
      type: object
    Detail:
      additionalProperties: false
      properties:
        code:
          description: >-
            Stable, machine-readable domain error code scoped to the emitting
            service (format: <SERVICE>-NNNN).
          examples:
            - ERR-0001
          type: string
        detail:
          description: >-
            A human-readable explanation specific to this occurrence of the
            problem.
          examples:
            - Property foo is required but is missing.
          type: string
        errors:
          description: Optional list of individual error details
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type:
            - array
            - 'null'
        instance:
          description: >-
            A URI reference that identifies the specific occurrence of the
            problem.
          examples:
            - https://example.com/error-log/abc123
          format: uri
          type: string
        status:
          description: HTTP status code
          examples:
            - 400
          format: int64
          type: integer
        title:
          description: >-
            A short, human-readable summary of the problem type. This value
            should not change between occurrences of the error.
          examples:
            - Bad Request
          type: string
        type:
          default: about:blank
          description: A URI reference to human-readable documentation for the error.
          examples:
            - https://example.com/errors/example
          format: uri
          type: string
      type: object
    ErrorDetail:
      additionalProperties: false
      properties:
        location:
          description: >-
            Where the error occurred, e.g. 'body.items[3].tags' or
            'path.thing-id'
          type: string
        message:
          description: Error message text
          type: string
        value:
          description: The value at the given location
      type: object
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT bearer token issued by the identity provider.
      scheme: bearer
      type: http

````