# matching.receiptConsolidation.confirm

Dashboard-only confirmation after a finance member reviews the current original documents and source-backed payment identity. Requires exact preview fingerprint, revisions and original IDs. Adds a receipt association and alias without changing bank amounts, allocations, financial fields, tax or review status. API, MCP and automatic actors cannot approve.

`POST /api/v1/accounting/matching.receiptConsolidation.confirm`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance · Idempotency key required

Not available over MCP: A person must review the current originals and exact payment group in Oatmilk before changing a receipt association.

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `receiptEntryId` | string (ID) | Yes | The ID of the related record. |
| `expectedReceiptRevision` | integer | Yes | The related record's current revision, from the last time you read it. at most 9007199254740991; greater than 0. |
| `targetEntryId` | string (ID) | Yes | The ID of the related record. |
| `expectedTargetRevision` | integer | Yes | The related record's current revision, from the last time you read it. at most 9007199254740991; greater than 0. |
| `mode` | enum | Yes | One of: `same_order`, `wise_card_settlement`. |
| `transactions` | array of objects | Yes | 1–20 items. |
| `transactions[].id` | string (ID) | Yes | The record's ID. |
| `transactions[].expectedRevision` | integer | Yes | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. at most 9007199254740991; greater than 0. |
| `expectedSourceFingerprint` | string | Yes | SHA-256 hash as 64 lowercase hex characters. |
| `reviewedOriginalEvidenceIds` | array of strings (ID) | Yes | A list of record IDs. 1–60 items. |
| `originalsReviewed` | true | Yes |  |
| `reason` | string | Yes | A short note saying why, kept in the record's history. 10–1000 characters. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/matching.receiptConsolidation.confirm \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "receiptEntryId": "7f0f6c1e-1c1f-4b5e-9c8d-2f5e8e3c1a10",
  "expectedReceiptRevision": 3,
  "targetEntryId": "4d5e6f7a-8b9c-4d0e-8f1a-2b3c4d5e6f7a",
  "expectedTargetRevision": 3,
  "mode": "same_order",
  "transactions": [
    {
      "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
      "expectedRevision": 3
    }
  ],
  "expectedSourceFingerprint": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c",
  "reviewedOriginalEvidenceIds": [
    "1a2b3c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
  ],
  "originalsReviewed": true,
  "reason": "Synthetic example from the docs"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/matching.receiptConsolidation.confirm
