Skip to main content
RECOGNITION · PROGRAMMES · ECOSYSTEM · TRUST FinanceGPT Developers
Core Platform

Attach immutable provenance evidence to a Finance Core intake submission

POST /finance-core/intake/submissions/{submissionUid}/evidence

Contract

Records provenance metadata and SHA-256 content identity only. FinanceGPT does not fetch source_uri and this operation cannot execute accounting actions.

Authentication
Bearer credential required
Required scope
finance-core:evidence:write
Status
Published

Parameters

Name Location Type Required Description
submissionUid path string Yes

Request body

application/json · required
{
    "evidence_type": "string",
    "source_reference": "string",
    "source_uri": "string",
    "content_sha256": "string",
    "observed_at": "2026-08-16T12:00:00Z",
    "metadata": []
}

Code examples

These examples compose a request only. Public reference pages never transmit your credential or execute the operation.

curl

curl -X POST \
  -H "Authorization: Bearer $FINANCEGPT_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  --data '{
    "evidence_type": "string",
    "source_reference": "string",
    "source_uri": "string",
    "content_sha256": "string",
    "observed_at": "2026-08-16T12:00:00Z",
    "metadata": []
}' \
  "https://financegpt.dev/api/v2/finance-core/intake/submissions/{submissionUid}/evidence"

javascript

const response = await fetch("https:\/\/financegpt.dev\/api\/v2\/finance-core\/intake\/submissions\/{submissionUid}\/evidence", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${FINANCEGPT_API_KEY}`,
    Accept: 'application/json',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "evidence_type": "string",
    "source_reference": "string",
    "source_uri": "string",
    "content_sha256": "string",
    "observed_at": "2026-08-16T12:00:00Z",
    "metadata": []
}),
});
const data = await response.json();

python

import json
import os
import requests

response = requests.request(
    'POST',
    'https://financegpt.dev/api/v2/finance-core/intake/submissions/{submissionUid}/evidence',
    headers={
        'Authorization': 'Bearer ' + os.environ['FINANCEGPT_API_KEY'],
        'Accept': 'application/json',
    },
    json=json.loads('{"evidence_type":"string","source_reference":"string","source_uri":"string","content_sha256":"string","observed_at":"2026-08-16T12:00:00Z","metadata":[]}'),
)
response.raise_for_status()
print(response.json())

php

<?php
$ch = curl_init('https://financegpt.dev/api/v2/finance-core/intake/submissions/{submissionUid}/evidence');
curl_setopt_array($ch, [
    CURLOPT_CUSTOMREQUEST => 'POST',
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => [
        'Authorization: Bearer '.getenv('FINANCEGPT_API_KEY'),
        'Accept: application/json',
        'Content-Type: application/json',
    ],
    CURLOPT_POSTFIELDS => json_encode(array (
  'evidence_type' => 'string',
  'source_reference' => 'string',
  'source_uri' => 'string',
  'content_sha256' => 'string',
  'observed_at' => '2026-08-16T12:00:00Z',
  'metadata' => 
  array (
  ),
)),
]);
$response = curl_exec($ch);
curl_close($ch);
echo $response;

Responses

Status Description
201 Immutable provenance evidence attached
200 Idempotent replay of existing identical evidence
422 Invalid evidence or execution intent

Authority boundary

A developer credential proves application identity and permits only its scopes. It does not grant model promotion, policy override, QLM rebinding, or Financial Actions execution authority unless those separate controls are satisfied.

finance-core:evidence:write

Machine-readable sources