Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

Authorization: Bearer <token>. Accepts EITHER a Keycloak access token (scopes-in-token) OR an opaque POS session token; both resolve to the same pos.* scope vocabulary the route guards enforce.

Body

application/json
transactionRef
string
required
Minimum string length: 1
outcome
enum<string>
required
Available options:
pass,
block,
needs_check
at
string<date-time>

ISO-8601 instant the check was performed at.

Minimum string length: 1
id
string
Minimum string length: 1

Response

The appended attestation, with the operator stamped from the caller's own token.

The appended attestation, with the operator stamped from the caller's own token.

id
string
required
operatorId
string
required
transactionRef
string
required
at
string<date-time>
required
Pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
outcome
enum<string>
required
Available options:
pass,
block,
needs_check