Create an insurance import

Starts verification and extraction for a Certificate of Insurance already uploaded as a VaultFile. The import is owned by the request account context. Replacing the file before submission uses the PATCH re-upload path and consumes another import attempt. insuranceMonitorId is an optional matching hint only; monitors independently evaluate whether verified policies satisfy their configured requirements.

Supplying an externalId already in use for this account returns 409 ResourceConflict — create is not an upsert. There is no list operation on this resource, so recover by holding the id from the original create. externalId and metadata are settable here only: the PATCH on this resource re-uploads the certificate and re-runs extraction, so correcting externalId or metadata through it would mean re-uploading the document.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

Create request for an immutable COI import. Attaching the file at create is what starts extraction, so fileId is schema-required and the edge validator rejects a body without one.

string
required

An already-uploaded VaultFile containing the Certificate of Insurance. Must be private and owned by the request account context.

string

Optional monitor hint used to prioritize policy matching.

string

Caller-supplied reconciliation id, unique per account. A duplicate returns 409 ResourceConflict.

metadata
object

Free-form key-value pairs. Max 50 keys; key length at most 40 characters; value length at most 500 characters. Where a list endpoint declares metadata filtering, it uses the QueryQL namespace via filter[metadata.{key}][eq]=value or filter[metadata.{key}][in][]=value. Endpoints that do not declare the dynamic Metadata filter do not support Metadata filtering.

Headers
string
length between 1 and 255
^[\x21-\x7e]{1,255}$

Optional idempotency token for authenticated POST and PATCH requests. Reusing the same key and body returns the cached response for 24 hours, except credential operations that explicitly document a 409 because one-time secret material is never cached; reusing it with a different body returns 409 IdempotencyKeyConflict. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json