Skip to content

Open app

Audit and read exact incoming callback evidence

POST
/admin/callback-incoming/{case_id}/evidence

Admin-runtime only; JSON follows x-request-schema and is validated after authentication. Requires claimed/closed case, matching owner_ref and current expected_version. The audit commits before decryption. Replay of this command revalidates current authority. Returns receipt plus evidence containing version, body_base64, signature and signature_header. Raw evidence is sensitive and may contain unverified provider claims. All responses no-store; admin routes are excluded from request/response-body capture. Failed audit or decryption never falls back to an unaudited read. No wallet operation.

case_id
required
string format: uuid

Audited exact evidence envelope and receipt.

Invalid JSON command.

Missing or invalid API key.

Caller is not admin-runtime.

Case or evidence absent.

Stale version

Unconfirmed audit or unreadable evidence; fixed error text.