Core Platform
Attach immutable provenance evidence to a Finance Core intake submission
POST
/finance-core/intake/submissions/{submissionUid}/evidence
Contract
Records provenance metadata and SHA-256 content identity only. FinanceGPT does not fetch source_uri and this operation cannot execute accounting actions.
Authentication
Bearer credential required
Required scope
finance-core:evidence:write
Status
Published
Parameters
| Name | Location | Type | Required | Description |
|---|---|---|---|---|
submissionUid |
path | string | Yes | — |
Request body
application/json
·
required
{
"evidence_type": "string",
"source_reference": "string",
"source_uri": "string",
"content_sha256": "string",
"observed_at": "2026-08-16T12:00:00Z",
"metadata": []
}
Code examples
These examples compose a request only. Public reference pages never transmit your credential or execute the operation.
curl
curl -X POST \
-H "Authorization: Bearer $FINANCEGPT_API_KEY" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
--data '{
"evidence_type": "string",
"source_reference": "string",
"source_uri": "string",
"content_sha256": "string",
"observed_at": "2026-08-16T12:00:00Z",
"metadata": []
}' \
"https://financegpt.dev/api/v2/finance-core/intake/submissions/{submissionUid}/evidence"
javascript
const response = await fetch("https:\/\/financegpt.dev\/api\/v2\/finance-core\/intake\/submissions\/{submissionUid}\/evidence", {
method: "POST",
headers: {
Authorization: `Bearer ${FINANCEGPT_API_KEY}`,
Accept: 'application/json',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"evidence_type": "string",
"source_reference": "string",
"source_uri": "string",
"content_sha256": "string",
"observed_at": "2026-08-16T12:00:00Z",
"metadata": []
}),
});
const data = await response.json();
python
import json
import os
import requests
response = requests.request(
'POST',
'https://financegpt.dev/api/v2/finance-core/intake/submissions/{submissionUid}/evidence',
headers={
'Authorization': 'Bearer ' + os.environ['FINANCEGPT_API_KEY'],
'Accept': 'application/json',
},
json=json.loads('{"evidence_type":"string","source_reference":"string","source_uri":"string","content_sha256":"string","observed_at":"2026-08-16T12:00:00Z","metadata":[]}'),
)
response.raise_for_status()
print(response.json())
php
<?php
$ch = curl_init('https://financegpt.dev/api/v2/finance-core/intake/submissions/{submissionUid}/evidence');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer '.getenv('FINANCEGPT_API_KEY'),
'Accept: application/json',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => json_encode(array (
'evidence_type' => 'string',
'source_reference' => 'string',
'source_uri' => 'string',
'content_sha256' => 'string',
'observed_at' => '2026-08-16T12:00:00Z',
'metadata' =>
array (
),
)),
]);
$response = curl_exec($ch);
curl_close($ch);
echo $response;
Responses
| Status | Description |
|---|---|
201 |
Immutable provenance evidence attached |
200 |
Idempotent replay of existing identical evidence |
422 |
Invalid evidence or execution intent |
Authority boundary
A developer credential proves application identity and permits only its scopes. It does not grant model promotion, policy override, QLM rebinding, or Financial Actions execution authority unless those separate controls are satisfied.
finance-core:evidence:write