Audit confidential document access before release; submission handoff requires independent approval
/bsa-filings/{id}/documentsConfidential filing API: dedicated compliance:filings staff scope, actual verified staff identity and no API keys. Writes, approval and export require step-up within five minutes; independent approval binds exact immutable content and successful full schema/business-rule validation. XML/source and actual response bytes are encrypted and excluded from ordinary bank records/audit exports. Preparing, downloading or reporting transmission does not establish FinCEN acceptance; exact complete authenticated acknowledgment and matching transmission correlation are required. Test-environment acknowledgments remain explicitly test-only. Bounded profile: complete CTR/SAR batch XML for the configured native rules ID (CTR v1/v2/v3, SAR v1/v2); joint SARs remain unsupported. Manifest inspection is not complete XSD validation. A native v2 SAR support document (one CSV of at most one megabyte) is a separate encrypted payload: its review access and the batch's submission release require its exact attachment_sha256, and the release returns the batch with the attachment and its <SeqNum>_<OriginalAttachmentFileName> name for the attachment zip file. Imported XML naming an attachment is refused. Documents destroyed under an approved retention disposition are refused.
Path parameters
idstringRequiredHeaders
Idempotency-KeystringRequiredSend on every write that creates or changes money or state; a replay with the same key returns the original result with 200.
Body parameters
attachment_sha256stringOptionalAttachmentSHA256 names the exact support document digest, required exactly when the response carries it: its review access, and the submission release of a batch that names it.
content_sha256stringRequireddocumentstringRequiredBatch, sources, validation, transmission, response, attachment
purposestringRequiredReview or submission; submission only for the batch
reasonstringRequiredReturns
200 OK
contentstring · byteRequiredkindstringRequiredpacket_idstringRequiredsha256stringRequiredsupport_documentobject or nullOptionalReleasedSupportDocument carries the exact retained bytes of a support document.
6 child attributes
activity_sequenceintegerRequiredbytesintegerRequiredcontentstring · byteRequiredfile_namestringRequiredsha256stringRequiredsubmission_file_namestringRequiredErrors
Every error is a problem document with a stable code. See Errors.
400401403404409412413422424429500503