Corgi BankDocumentation
OpenAPI

Prepare one immutable customer accounting artifact from reviewed actual card expenses

POST/cards/spend/exports

Verified bank-bound customer PERSON identity with customer scope, session/device and online account organization membership required. Writes require authentication within five minutes; API keys, staff and service impersonation refused. Existing maker/approver/admin roles and amount limits apply. Expense review requires distinct users AND person customer IDs. Pending/approved allocations reserve exact bank-source and receipt totals; duplicate bytes cannot be relabeled. Actual unreversed committed card journals are revalidated. Pre-export coding corrections preserve source/receipt/amount. Immutable customer-expense-json-1 exports contain balanced customer-book entries, exact review/source proofs and unique expense membership. Preparation/download never claims provider delivery/import, and never posts customer expense codes to bank GLs. See services/cards/spend/README.md.

Headers

Idempotency-KeystringRequired

Send on every write that creates or changes money or state; a replay with the same key returns the original result with 200.

Body parameters

account_idstringRequired

Example acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm

expense_idsarray of stringsRequired
format_versionstringRequired

Returns

200 OK

artifactobjectRequired

Artifact JSON is deterministic in this declaration order. Its hash binds exact reviewed records, actual source journals and the organization authority snapshot.

7 child attributes
account_idstringRequired

Example acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm

created_atstring · date-timeRequired
entriesarray of objectsRequired
9 child attributes
amountintegerRequired
cost_centerstringOptional
currency_codestringRequired
directionstringRequired
expense_idstringRequired
external_account_codestringRequired
memostringRequired
source_journal_idstringRequired

Example jrnl_2tVh8nqLxq4GbDe0K1F6S9zRcWm

source_journal_sha256stringRequired
expensesarray of objectsRequired
10 child attributes
amountintegerRequired
content_sha256stringRequired
created_atstring · date-timeRequired
export_idstringOptional
idstringRequired
replaced_by_expense_idstringOptional
requestobjectRequired
7 child attributes
allocationsarray of objectsRequired
authorization_idstringRequired

Example auth_2tVh8nqLxq4GbDe0K1F6S9zRcWm

coding_evidenceobjectRequired
reasonstringRequired
receiptobjectRequired

Receipt identity is scoped to the organization and the exact processor merchant. A source document can support several partial bank payments, but only up to its declared total. Evidence is retained customer-supplied documentation, not OCR proof.

replaces_expense_idstringOptional
settlement_account_codestringRequired
reviewobject or nullOptional
6 child attributes
approvebooleanRequired
atstring · date-timeRequired
authorityobjectRequired

Authority is the observed current organization membership and separately bank- verified person identity. Neither the request body nor a receipt supplies it.

content_sha256stringRequired
evidenceobjectRequired
reasonstringRequired
sourceobjectRequired
15 child attributes
account_idstringRequired

Example acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm

amountintegerRequired
authorization_idstringRequired

Example auth_2tVh8nqLxq4GbDe0K1F6S9zRcWm

card_idstringRequired

Example card_2tVh8nqLxq4GbDe0K1F6S9zRcWm

card_kindstringRequired
currency_codestringRequired
journalobjectRequired
journal_keystringRequired
journal_sha256stringRequired
kindstringRequired

Purchase or refund, derived from actual bank source

merchant_idstringRequired
merchant_namestringRequired
network_referencestringRequired
organization_customer_idstringRequired

Example cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm

original_authorization_idstringOptional

Example auth_2tVh8nqLxq4GbDe0K1F6S9zRcWm

submitted_byobjectRequired

Authority is the observed current organization membership and separately bank- verified person identity. Neither the request body nor a receipt supplies it.

12 child attributes
account_idstringRequired

Example acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm

device_sha256stringRequired
membership_changed_bystringRequired
membership_updated_atstring · date-timeRequired
observed_atstring · date-timeRequired
organization_customer_idstringRequired

Example cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm

payment_limit_amountintegerRequired
person_customer_idstringRequired

Example cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm

rolestringRequired
session_sha256stringRequired
step_up_atstring · date-timeRequired
user_idstringRequired

Example user_2tVh8nqLxq4GbDe0K1F6S9zRcWm

export_idstringRequired
organization_customer_idstringRequired

Example cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm

versionstringRequired
artifact_sha256stringRequired
created_atstring · date-timeRequired
idstringRequired
prepared_byobjectRequired

Authority is the observed current organization membership and separately bank- verified person identity. Neither the request body nor a receipt supplies it.

12 child attributes
account_idstringRequired

Example acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm

device_sha256stringRequired
membership_changed_bystringRequired
membership_updated_atstring · date-timeRequired
observed_atstring · date-timeRequired
organization_customer_idstringRequired

Example cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm

payment_limit_amountintegerRequired
person_customer_idstringRequired

Example cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm

rolestringRequired
session_sha256stringRequired
step_up_atstring · date-timeRequired
user_idstringRequired

Example user_2tVh8nqLxq4GbDe0K1F6S9zRcWm

requestobjectRequired
3 child attributes
account_idstringRequired

Example acct_2tVh8nqLxq4GbDe0K1F6S9zRcWm

expense_idsarray of stringsRequired
format_versionstringRequired

Errors

Every error is a problem document with a stable code. See Errors.

400401403404409412413422424429500503

to move to open esc to close