# tax.financialCounterparts.review

Classify a supported CAD transfer with an explicit incoming advance, outgoing advance, incoming repayment or outgoing repayment. Uses current source/review/obligation revisions, original evidence, owner attestations, a posting preview and a retry key. Repayments allocate existing obligations and cannot overpay. Atomically saves the separate counterpart, balances and audit without duplicating imported cash or touching other companies. Legacy shareholder and share-capital purposes require dashboard confirmation.

`POST /api/v1/accounting/tax.financialCounterparts.review`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance · Idempotency key required · Send `expectedRevision`

Not available over MCP: Legacy untyped loans and share capital still require a person in Oatmilk. Explicit intercompany advances and repayments use the same authorized posting service through MCP, API and the dashboard.

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `entryId` | string (ID) | Yes | The ID of an accounting entry, from entries.list or attention.mine. |
| `expectedEntryRevision` | integer | Yes | The related record's current revision, from the last time you read it. at most 9007199254740991; greater than 0. |
| `expectedRevision` | integer | Yes | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. 0 to 9007199254740991. |
| `sourceFingerprint` | string | Yes | SHA-256 hash as 64 lowercase hex characters. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |
| `purpose` | enum | Yes | One of: `incoming_advance`, `outgoing_advance`, `incoming_repayment`, `outgoing_repayment`, `due_to_other`, `due_from_other`, `due_to_shareholder`, `due_from_shareholder`, `common_shares`. |
| `label` | string | Yes | 1–100 characters. |
| `reason` | string | Yes | A short note saying why, kept in the record's history. 10–500 characters. |
| `evidence` | array of objects | Yes | 1–20 items. |
| `evidence[].kind` | enum | Yes | Which kind of record or job this is. One of: `bank_original`, `receipt_original`, `company_original`. |
| `evidence[].id` | string (ID) | Yes | The record's ID. |
| `evidence[].sha256` | string | Yes | The SHA-256 hash of the file's exact bytes, as 64 lowercase hex characters. SHA-256 hash as 64 lowercase hex characters. |
| `expectedSupportingSourceFingerprint` | string |  | SHA-256 hash as 64 lowercase hex characters. |
| `counterpartyId` | string (ID) |  | The ID of the related record. |
| `allocations` | array of objects |  | at most 20 items. |
| `allocations[].obligationId` | string (ID) | Yes | The ID of the related record. |
| `allocations[].expectedRevision` | integer | Yes | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. at most 9007199254740991; greater than 0. |
| `allocations[].amountMinor` | string | Yes | An amount in cents (the currency's smallest unit), written as a whole-number string such as "1250" for $12.50. Matches ^[1-9][0-9]{0,18}$. |
| `attestations` | array of objects |  | at most 20 items. |
| `attestations[].kind` | "owner_attestation" | Yes | Which kind of record or job this is. |
| `attestations[].statement` | string | Yes | 10–2000 characters. |
| `attestations[].attestedBy` | string | Yes | 1–100 characters. |
| `attestations[].attestedAt` | string (date-time) | Yes | A date and time in ISO 8601 format. |
| `instruction` | string |  | 10–2000 characters. |
| `confirmed` | true | Yes |  |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/tax.financialCounterparts.review \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "entryId": "7f0f6c1e-1c1f-4b5e-9c8d-2f5e8e3c1a10",
  "expectedEntryRevision": 3,
  "expectedRevision": 3,
  "sourceFingerprint": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c",
  "purpose": "incoming_advance",
  "label": "example",
  "reason": "Synthetic example from the docs",
  "evidence": [
    {
      "kind": "bank_original",
      "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
      "sha256": "9f2b5c1d7e3a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4c"
    }
  ],
  "confirmed": true
}'
```

Reference page: https://app.getoatmilk.com/docs/api/tax.financialCounterparts.review
