Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

Authorization: Bearer <token>. Accepts EITHER a Keycloak access token (scopes-in-token) OR an opaque POS session token; both resolve to the same pos.* scope vocabulary the route guards enforce.

Body

application/json
transactionRef
string
required

Reference of the sale/transaction (ticket) the check was performed for.

Minimum string length: 1
outcome
enum<string>
required

The decision the till acted on: pass, block or needs_check.

Available options:
pass,
block,
needs_check
at
string<date-time>

ISO-8601 instant the check was performed at.

Minimum string length: 1
id
string

Optional client-supplied id, for idempotency — reuse it to make a retry safe.

Minimum string length: 1

Response

The appended attestation, with the operator stamped from the caller's own token.

The appended attestation, with the operator stamped from the caller's own token.

id
string
required
operatorId
string
required
transactionRef
string
required
at
string<date-time>
required
Pattern: ^(?:(?:\d\d[2468][048]|\d\d[13579][26]|\d\d0[48]|[02468][048]00|[13579][26]00)-02-29|\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\d|30)|(?:02)-(?:0[1-9]|1\d|2[0-8])))T(?:(?:[01]\d|2[0-3]):[0-5]\d(?::[0-5]\d(?:\.\d+)?)?(?:Z))$
outcome
enum<string>
required
Available options:
pass,
block,
needs_check