# contractorOps.payments.reveal

Show a contractor's full payment details to an administrator in the dashboard with an audited reason. Not available to API keys or MCP clients.

`POST /api/v1/accounting/contractorOps.payments.reveal`

Permissions: `accounting:read`, `accounting:write`, `accounting:admin` · Roles: admin · Idempotency key required

Not available over MCP: Full bank details would pass through the agent.

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `contractorId` | string (ID) | Yes | The ID of a contractor, from contractors.list. |
| `reason` | string | Yes | A short note saying why, kept in the record's history. 5–500 characters. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/contractorOps.payments.reveal \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "contractorId": "4d5e6f7a-8b9c-4d0e-8f1a-2b3c4d5e6f7a",
  "reason": "Synthetic example from the docs"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/contractorOps.payments.reveal
