> ## Documentation Index
> Fetch the complete documentation index at: https://docs.terabusinessfinance.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Mark a Supplier-held Document as stored



## OpenAPI

````yaml /openapi.json post /v1/supplier-submissions/documents/finalize
openapi: 3.1.0
info:
  title: Tera Contracted Supplier API
  version: 1.0.0
  description: >-
    Generated from @tera/validation Supplier Submission Zod contracts. Do not
    hand-edit.
servers:
  - url: https://sandbox-api.terabusinessfinance.com
    description: Live sandbox API. Test credentials only (`tcs_test_`).
  - url: https://api.terabusinessfinance.com
    description: >-
      Intended production host. Live credentials only (`tcs_live_`). Production
      is not yet available: no READY production API deployment, and production
      traffic is disabled.
security: []
tags:
  - name: Submissions
  - name: Corrections
  - name: Promotion
  - name: Documents
paths:
  /v1/supplier-submissions/documents/finalize:
    post:
      tags:
        - Documents
      summary: Mark a Supplier-held Document as stored
      operationId: finalizeSupplierHeldDocument
      parameters:
        - name: X-Request-Id
          in: header
          required: false
          description: >-
            Optional caller correlation id. Tera always returns X-Request-Id;
            that header is the only correlation identifier.
          schema:
            type: string
            minLength: 1
            maxLength: 128
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $schema: https://json-schema.org/draft/2020-12/schema
              type: object
              properties:
                external_reference:
                  type: string
                  minLength: 1
                  maxLength: 128
                document_id:
                  type: string
                  format: uuid
                  pattern: >-
                    ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
              required:
                - external_reference
                - document_id
              additionalProperties: false
      responses:
        '200':
          description: Supplier-held Document stored against the supplier reference.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SupplierHeldDocumentFinalizeResponse'
              examples:
                finalized:
                  summary: Stored Supplier-held bank statement awaiting scan.
                  value:
                    document_id: 11111111-1111-4111-8111-111111111111
                    category: bank_statements
                    scan_status: pending_scan
        '400':
          description: 'Error codes: bad_request'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SupplierApiError'
              examples:
                bad_request:
                  summary: Malformed JSON or missing required query.
                  value:
                    error:
                      code: bad_request
                      message: Malformed JSON
        '401':
          description: 'Error codes: unauthorized'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SupplierApiError'
              examples:
                unauthorized:
                  summary: Missing or invalid credential.
                  value:
                    error:
                      code: unauthorized
                      message: Authentication failed
        '403':
          description: 'Error codes: forbidden'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SupplierApiError'
              examples:
                forbidden:
                  summary: Valid credential without permission for this operation.
                  value:
                    error:
                      code: forbidden
                      message: Credential is not authorised for this operation
        '404':
          description: 'Error codes: not_found'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SupplierApiError'
              examples:
                not_found:
                  summary: Unknown or cross-tenant submission.
                  value:
                    error:
                      code: not_found
                      message: Submission not found
        '422':
          description: 'Error codes: validation_error'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SupplierApiError'
              examples:
                validation_error:
                  summary: JSON parsed but failed the level schema.
                  value:
                    error:
                      code: validation_error
                      message: Request does not match the submission contract
                      details:
                        - path: funding_amount
                          message: Minimum amount is £1,000
        '429':
          description: 'Error codes: rate_limited'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
            Retry-After:
              $ref: '#/components/headers/RetryAfter'
            RateLimit-Limit:
              $ref: '#/components/headers/RateLimitLimit'
            RateLimit-Remaining:
              $ref: '#/components/headers/RateLimitRemaining'
            RateLimit-Reset:
              $ref: '#/components/headers/RateLimitReset'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SupplierApiError'
              examples:
                rate_limited:
                  summary: Identity, IP, or failed-auth limiter.
                  value:
                    error:
                      code: rate_limited
                      message: Rate limit exceeded. Retry after the Retry-After header.
        '503':
          description: 'Error codes: service_unavailable'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/XRequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SupplierApiError'
              examples:
                service_unavailable:
                  summary: Temporary upstream or platform unavailability.
                  value:
                    error:
                      code: service_unavailable
                      message: Operation could not be completed
      security:
        - SupplierBearer: []
components:
  headers:
    XRequestId:
      description: >-
        Canonical correlation id for this request. Safe to log. Not included in
        the JSON error body.
      schema:
        type: string
    RetryAfter:
      description: Seconds until the client may retry after HTTP 429.
      schema:
        type: integer
        minimum: 1
    RateLimitLimit:
      description: Steady or burst limit for the current bucket.
      schema:
        type: integer
        minimum: 0
    RateLimitRemaining:
      description: Remaining requests in the current window.
      schema:
        type: integer
        minimum: 0
    RateLimitReset:
      description: Unix timestamp when the current window resets.
      schema:
        type: integer
        minimum: 0
  schemas:
    SupplierHeldDocumentFinalizeResponse:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        document_id:
          type: string
          format: uuid
          pattern: >-
            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
        category:
          type: string
          enum:
            - bank_statements
            - accounts
            - id
        scan_status:
          type: string
          const: pending_scan
      required:
        - document_id
        - category
        - scan_status
      additionalProperties: false
    SupplierApiError:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - bad_request
                - unauthorized
                - forbidden
                - not_found
                - external_reference_conflict
                - revision_conflict
                - idempotency_conflict
                - concurrent_promotion
                - payload_too_large
                - validation_error
                - rate_limited
                - service_unavailable
            message:
              type: string
              minLength: 1
              maxLength: 200
            details: {}
          required:
            - code
            - message
          additionalProperties: false
      required:
        - error
      additionalProperties: false
  securitySchemes:
    SupplierBearer:
      type: http
      scheme: bearer
      description: >-
        Canonical form uses underscore only: tcs_test_<public_id>_<secret> or
        tcs_live_<public_id>_<secret>. Scopes:
        supplier_submissions:create:basic,
        supplier_submissions:create:application, supplier_submissions:read,
        supplier_submissions:correct, supplier_submissions:promote. Effective
        permission is account ∩ credential ∩ environment. HMAC pepper is
        SUPPLIER_API_KEY_PEPPER.

````