{
  "openapi": "3.0.3",
  "info": {
    "title": "Monetae Conecta — Partner / Rail API (Credicomer v2.3)",
    "version": "2.3-sandbox",
    "description": "PROPOSED / SANDBOX SECURITY. PRODUCTION BLOCKED — PARTNER AUTHENTICATION AGREEMENT REQUIRED.\n\nPendiente de integración:\n- Esquema de autenticación partner (HMAC/mTLS/IP allowlist) — pendiente de acuerdo.\n- PARTNER CONTRACT GAP (Stop Condition #9): pre-authorize no trae una referencia inequívoca de la transacción; la idempotencia productiva no puede garantizarse.\n- Tipos, formatos y longitudes de cada campo de pre-authorize/notification (v2.3 lista nombres, no formatos).\n- Valores de `status` y `transaction_type` de notification y su significado (qué valor = fondos recibidos).\n- Semántica de first_name/last_name en la respuesta de pre-authorize (eco del ordenante o titular Monetae).\n- A quién refieren `bank_code` y `client_name` en notification (ordenante o beneficiario).\n- Formato de entry_date / exit_date y catálogo definitivo de error_code.\n- Semántica de respuesta de /transfer/outgoing (síncrona vs. aceptación) y credenciales reales de /authenticate/bel."
  },
  "servers": [
    {
      "url": "https://conectademo.monetae.io/api/public/rails/credicomer"
    }
  ],
  "paths": {
    "/v2/transfer/pre-authorize": {
      "post": {
        "tags": [
          "Pay-in"
        ],
        "summary": "Pre-autorización de transferencia entrante",
        "description": "Campos exactos de v2.3. Respuesta binaria: valid_transaction=true solo con decisión aprobada; review/unavailable ⇒ false. transaction_token opaco generado por Monetae. PARTNER CONTRACT GAP: el request no trae referencia inequívoca, por lo que la idempotencia productiva está PRODUCTION BLOCKED; en sandbox, mismo cuerpo dentro de 90 s ⇒ mismo token.",
        "parameters": [
          {
            "name": "X-Key-Id",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "X-Timestamp",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "X-Signature",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "HMAC-SHA256 (sandbox)"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "origin_bank",
                  "origin_bank_code",
                  "origin_account",
                  "first_name",
                  "last_name",
                  "amount",
                  "monetae_account",
                  "document_number"
                ],
                "properties": {
                  "origin_bank": {
                    "type": "string"
                  },
                  "origin_bank_code": {
                    "type": "string"
                  },
                  "origin_account": {
                    "type": "string"
                  },
                  "first_name": {
                    "type": "string"
                  },
                  "last_name": {
                    "type": "string"
                  },
                  "amount": {
                    "type": "number",
                    "maximum": 120000
                  },
                  "monetae_account": {
                    "type": "string"
                  },
                  "document_number": {
                    "type": "string"
                  },
                  "comments": {
                    "type": "string",
                    "nullable": true
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Decisión",
            "content": {
              "application/json": {
                "example": {
                  "valid_transaction": true,
                  "first_name": "Ana",
                  "last_name": "Pérez",
                  "authorized_amount": 150,
                  "transaction_token": "tt_…"
                }
              }
            }
          },
          "401": {
            "description": "Autenticación partner inválida"
          }
        }
      }
    },
    "/v2/transfer/notification": {
      "post": {
        "tags": [
          "Pay-in"
        ],
        "summary": "Notificación de transferencia procesada (callback contractual)",
        "description": "Correlación por transaction_token, dedupe por reference_credicomer y comparación material. Rechazo/no recibido ⇒ sin efecto financiero. Valor recibido con inconsistencia ⇒ Suspense → Requires Review (nunca se acredita ni se descarta). Valores de status: INTEGRATION PENDING.",
        "parameters": [
          {
            "name": "X-Key-Id",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "X-Timestamp",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            }
          },
          {
            "name": "X-Signature",
            "in": "header",
            "required": true,
            "schema": {
              "type": "string"
            },
            "description": "HMAC-SHA256 (sandbox)"
          }
        ],
        "requestBody": {
          "required": true,
          "content": {
            "application/json": {
              "schema": {
                "type": "object",
                "required": [
                  "reference_credicomer",
                  "status",
                  "account",
                  "amount",
                  "transaction_token"
                ],
                "properties": {
                  "reference_credicomer": {
                    "type": "string"
                  },
                  "status": {
                    "type": "string"
                  },
                  "transaction_type": {
                    "type": "string"
                  },
                  "error_code": {
                    "type": "string"
                  },
                  "rejection_reason": {
                    "type": "string"
                  },
                  "account": {
                    "type": "string"
                  },
                  "bank_code": {
                    "type": "string"
                  },
                  "amount": {
                    "type": "number"
                  },
                  "client_name": {
                    "type": "string"
                  },
                  "transaction_token": {
                    "type": "string"
                  },
                  "entry_date": {
                    "type": "string"
                  },
                  "exit_date": {
                    "type": "string"
                  }
                }
              }
            }
          }
        },
        "responses": {
          "200": {
            "description": "Aceptada: credited | suspense_requires_review | none (o repetición)"
          },
          "202": {
            "description": "Estado no final: sin efecto financiero"
          },
          "403": {
            "description": "PRODUCTION BLOCKED"
          }
        }
      }
    }
  }
}