Skip to main content
POST
Rescore a beneficiary

Authorizations

DPoP
string
header
required

Per-request DPoP proof JWT (RFC 9449). MUST accompany the Authorization: DPoP <access_token> header on every protected operation. The proof is signed by the merchant's private DPoP key and carries htm, htu, iat, jti, and ath claims.

Headers

Idempotency-Key
string
required

Unique key identifying this operation. Sending the same key twice returns the original response instead of creating a duplicate. Keys are retained for 24 hours.

Maximum string length: 255

Path Parameters

id
string
required
Pattern: ^ben_[a-zA-Z0-9]+$

Response

Rescore complete.

data
object
required

Result of a manual Payee-pillar rescore. Scores are 0–1000 integers where higher is ALWAYS worse — the same orientation as risk_score on the beneficiary resource. The previous_* fields are absent when the engine had no prior evaluation on record.