Pular para o conteúdo

Create optimized binding

Creates the Open Finance data consent and the JSR enrollment in a single call, so the payer authenticates only once at the account holder. This is the entry point of the Linked Journey (JSR) — for the Sweeping variant, see Linked journey (Smart Pix) and Create optimized automatic payment.

The request body is the same contract as Create enrollment (POST /jsr/enrollments). The only difference is server-side: the data consent is created automatically and correlated to the enrollment via the journey field sent to the account holder, so the holder presents a single combined authorisation screen (data + payment) instead of two separate ones.

On 201 Created, persist data.id (the enrollment id — use it exactly like a normal JSR enrollment, in Enrollment device options, Register enrollment device, and later JSR payments) and data.dataConsentId (use it on Get data consent), plus data.flowId for observability — then redirect the payer to data.redirectUrl.

POST/api/v1/linked-journey/jsr

Create optimized binding

Creates the data consent and the JSR enrollment in one call and returns redirectUrl and dataConsentId.

Auth: Bearer Token

Headers

2 campos
subTenantId●
headerstring

Target sub-tenant of the request, used together with the token to resolve the tenant context.

X-Client-IP●
headerstring

End-user client IP, forwarded to the account holder as part of the risk signals.

Request body

10 campos
paymentId
bodystring

Id of the single payment associated with this binding (mutually optional with automaticPaymentId).

automaticPaymentId
bodystring

Id of the automatic payment associated with this binding (mutually optional with paymentId).

organisationId●
bodystring

OrganisationId from Get registered participants (max 36 characters).

authorisationServerId●
bodystring

Authorisation server id from Get registered participants (max 36 characters).

businessType
bodystring

Business document type, when the holder is a legal entity.

businessIdentity
bodystring

Business document number (digits only) used on the data consent, when applicable.

productType
bodystring

Product type label.

enrollment●
bodyobject

Enrollment metadata and optional debtor account hints.

document●
bodystring

Payer document (CPF) of the enrollment holder.

externalId
bodystring

Your correlation id for the enrollment.

deviceName
bodystring

Human-readable device label.

debtor
bodyobject

Optional debtor account hints.

accountNumber●
bodystring
accountIssuer●
bodystring
accountIspb●
bodystring
accountType●
bodystring
riskSignals●
bodyobject

Risk signals for the enrollment step. Additional optional fields exist in the OpenAPI spec.

deviceId●
bodystring
userTimeZoneOffset●
bodystring
language●
bodystring
screenDimensions●
bodyobject
width●
bodynumber
height●
bodynumber
accountTenure●
bodystring

Date since when the payer is registered on your platform.

osVersion
bodystring

OS version.

elapsedTimeSinceBoot
bodynumber

Milliseconds since boot.

screenBrightness
bodynumber

Screen brightness where applicable.

isRootedDevice
bodyboolean

Whether the device is rooted.

redirectUri●
bodystring

Relying-party URL after bank confirmation. Must parse fragment parameters code, state, and id_token.

curl --request POST \
  --url 'https://embedded-payment-manager.hml.linaob.com.br/api/v1/linked-journey/jsr' \
  --header 'Content-Type: application/json' \
  --header 'Authorization: Bearer <SEU_TOKEN>' \
  --header 'subTenantId: subtenant_abc123' \
  --header 'X-Client-IP: 198.21.104.1' \
  --data '{
  "paymentId": "payment123",
  "automaticPaymentId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
  "organisationId": "74e929d9-33b6-4d85-8ba7-c146c867a817",
  "authorisationServerId": "c8f0bf49-4744-4933-8960-7add6e590841",
  "businessType": "CNPJ",
  "businessIdentity": "12345678000195",
  "productType": "single_payment",
  "enrollment": {
    "document": "39033521016",
    "externalId": "ext123",
    "deviceName": "device123",
    "debtor": {
      "accountNumber": "1234567890",
      "accountIssuer": "0001",
      "accountIspb": "12345678",
      "accountType": "CACC"
    }
  },
  "riskSignals": {
    "deviceId": "00aa11bb22cc33dd",
    "userTimeZoneOffset": "-03",
    "language": "pt",
    "screenDimensions": {
      "width": 1920,
      "height": 1080
    },
    "accountTenure": "2023-01-01",
    "osVersion": "14",
    "elapsedTimeSinceBoot": 6356027,
    "screenBrightness": 255,
    "isRootedDevice": false
  },
  "redirectUri": "https://example.com/redirect"
}'

Response

201Data consent and JSR enrollment created successfully in the optimized journey.
Response body
object
  • dataobjectrequired
    • idstringrequired

      Enrollment identifier — use it in device registration and later JSR payment calls.

    • redirectUrlstring

      URL where the payer authorises both the data consent and the enrollment at the account holder.

    • dataConsentIdstring· nullable

      Data consent created at Data Link in this journey — use it on Get data consent.

    • flowIdstring· nullable

      Flow correlation identifier, used for observability in Datadog.

  • messagestring

    Response message.

  • typestring

    Envelope type (for example success).

  • statusCodeinteger· nullable

    HTTP status code.

201 · Data consent and JSR enrollment created successfully in the optimized journey.
{
  "type": "success",
  "message": "Enrollment created successfully",
  "data": {
    "id": "enr_abc123",
    "redirectUrl": "https://auth.holder.example.com.br/auth?request=eyJhbGciOi...",
    "dataConsentId": "urn:raidiambank:consent:460338f5-1fa6-4434-92dd-be47be181d18",
    "flowId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
  }
}

Next steps

  • Get data consent — poll dataConsentId until status is AUTHORISED and read userId.
  • Get user accounts — list the payer accounts once the data consent is authorised.
  • Enrollment device options — exchange the bank redirect's fragment parameters for FIDO2 registration options; from here on the flow is identical to a plain JSR enrollment.