HYBRID-CHAINDEVELOPERS
DOCUMENTATIONv2
GET

Transfer compliance

List reviews

/api/v2/transfer-compliance/reviews
AUTHENTICATIONBearer token · compliance:reviewAUTHORITATIVE OWNERtransfer-compliance-serviceCONTRACT AUTHORITYCapability registry · plannedSTATUSPlanned · not executable
PLANNING CONTRACT · NOT CALLABLE

This page describes intended capability and integration boundaries so people and agents can prepare safely. Do not send this request or register it as an executable tool. Wait until the capability registry marks it implemented-contract, then re-fetch the deployed OpenAPI document and build the request from that machine contract.

PURPOSE + BUSINESS CONTEXT

Planned capability: list transfers and counterparties awaiting authorized review.

WHEN THIS CALL IS USEFUL

Do not call or register this operation as an executable agent tool yet. Use this page to plan the future reviews workflow; enable it only after the status becomes implemented-contract and the exact operation appears in deployed OpenAPI.

OUTCOME · Planned · Discover

What changes

None today: this route is not executable. Its intended behavior is: read-only projection; it grants no mutation, settlement, traffic, or authority change.

WHY IT MATTERS

  • Lets people and agents prepare for reviews without falsely presenting roadmap scope as a live capability.
  • Gives people and agents a contract-backed way to discover reviews.
  • Supports policy-compliant transfer coordination while minimizing personal data and separating compliance evidence from value movement.

ISOLATION + AUTHORITY

Owner, workspace, counterparty, VASP, credential issuer, wallet controller, transfer, reviewer, disclosure recipient, purpose, and retention boundaries remain distinct. A credential, preparation, decision, manifest, envelope, disclosure, or Explorer record neither moves value nor substitutes for wallet authorization, sanctions policy, rail admission, settlement, or finality. This planning record grants no runtime authority, and only deployed OpenAPI can define an executable public contract.

BEFORE YOU CALL

  • First confirm that this operation is marked implemented-contract and exists in the currently deployed OpenAPI document; until then, no production request is valid.
  • Its capability-registry profile is provisional integration guidance, not an executable request schema.
  • Authenticate at the documented boundary: bearer+scope.
  • Treat the capability-registry profile as design guidance only; deployed OpenAPI must define the executable request and response shapes.
  • Resolve the transfer parties, network, policy jurisdiction, required credential and proof classes, disclosure purpose, recipient, and retention basis.

WHAT TO DO NEXT

  • Keep this operation disabled in clients, agents, SDKs, and workflow automation while it remains planned-contract.
  • Use the stated owner, lifecycle, authority boundary, and provisional reviews profile to prepare requirements and conformance tests without sending a request.
  • Monitor the capability registry for implemented-contract, then re-fetch deployed OpenAPI and validate its exact security, parameters, schemas, responses, and agent metadata before enabling the integration.

AGENT GUIDANCE

  • Never call this planned contract, include it in an executable tool registry, or infer runtime availability from this readable page.
  • Its capability-registry profile is provisional integration guidance, not an executable request schema.
  • Use reviews only for the purpose and lifecycle stage described by this operation; do not treat it as authority for an adjacent action.
  • Treat the capability-registry profile as design guidance only; deployed OpenAPI must define the executable request and response shapes.
  • Keep counterparty registration, credential validity, wallet-control proof, transfer intent, data preparation, review decision, disclosure authorization, delivery, value movement, and settlement as separate facts.
  • Use response links and canonical identifiers instead of constructing internal service URLs or scraping the website.
  • When implementation lands, discard generated requests based on this planning record and rebuild them from the deployed OpenAPI operation.
MACHINE CONTRACT

This operation is a non-executable planning contract. Its capability-registry record defines the intended owner, parameters, responses, and integration boundary until an implemented Rust OpenAPI operation replaces it.

EXTENDED INTEGRATION GUIDANCE

Readable request and response reference

Examples describe the reviewed planning contract and remain non-executable until promoted into OpenAPI.

PARAMETERS

Headers, path, query, and body

NAMELOCATIONPRESENCETYPE / RULES / PURPOSE
AuthorizationheaderRequired

Bearer tokenCredential containing compliance:review authority.EXAMPLEBearer hc_live_…

resource_typequeryOptional

TRANSFER | COUNTERPARTYRestrict the future authorized review queue to one resource class.EXAMPLEresource-type-01

statusqueryOptional

PENDING | INFORMATION_REQUIRED | REVIEWRestrict results to an exact review posture.EXAMPLEACTIVE

cursorqueryOptional

opaque stringCursor returned by the previous page.EXAMPLEeyJvZmZzZXQiOjUwfQ

limitqueryOptional

integer · 1–200Maximum records to return.EXAMPLE100

RESPONSES

Status and payload examples

200Canonical resource projection.Not executable · JSON RESPONSE+
{
  "result": "See the operation's authoritative OpenAPI response schema."
}
INTEGRATION DECISION
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from transfer-policy definitions, credentials, attestations, reviews, commitments, decisions, and revocations through an implemented operation.
ESCALATE WHEN
Escalate when minimized compliance evidence, issuer authority, policy version, jurisdiction, or decision lineage cannot be verified.
401Bearer credential is missing, expired, or invalid.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "Bearer credential is missing, expired, or invalid."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from transfer-policy definitions, credentials, attestations, reviews, commitments, decisions, and revocations through an implemented operation.
ESCALATE WHEN
Escalate when minimized compliance evidence, issuer authority, policy version, jurisdiction, or decision lineage cannot be verified.
403The principal lacks the required scope, role, tenant, or step-up authority.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "The principal lacks the required scope, role, tenant, or step-up authority."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from transfer-policy definitions, credentials, attestations, reviews, commitments, decisions, and revocations through an implemented operation.
ESCALATE WHEN
Escalate when minimized compliance evidence, issuer authority, policy version, jurisdiction, or decision lineage cannot be verified.
422Path, query, or body validation failed.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "Path, query, or body validation failed."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from transfer-policy definitions, credentials, attestations, reviews, commitments, decisions, and revocations through an implemented operation.
ESCALATE WHEN
Escalate when minimized compliance evidence, issuer authority, policy version, jurisdiction, or decision lineage cannot be verified.
503The authoritative service or read model is unavailable.Not executable · JSON RESPONSE+
{
  "code": "request_failed",
  "message": "The authoritative service or read model is unavailable."
}
INTEGRATION DECISIONrequest_failed
CALLER ACTION
Do not send this request or register it as an executable agent tool. Use the implemented alternatives linked by the module guide.
RETRY SAFETY
Do not retry on a timer. Re-fetch production OpenAPI and proceed only after this exact operation appears there.
STATE RECONCILIATION
No runtime state exists to reconcile for this planning contract. Continue from transfer-policy definitions, credentials, attestations, reviews, commitments, decisions, and revocations through an implemented operation.
ESCALATE WHEN
Escalate when minimized compliance evidence, issuer authority, policy version, jurisdiction, or decision lineage cannot be verified.

OPERATIONAL NOTES

Security and lifecycle guarantees

  • The Rust gateway validates the public contract and routes only to the authoritative owner; clients never address internal services directly.
DOCUMENTATION STATUS

This planned contract now defines its public parameters, authorization boundary, replay behavior, responses, and authoritative owner. It remains non-executable until its owner adapter and conformance tests are promoted into the Rust gateway.

Return to the V2 directory