# tax.sources.confirm

Verify uploaded company/tax source original bytes and preserve evidence without creating accounting entries. Returns an evidence ID for source references.

`POST /api/v1/accounting/tax.sources.confirm`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance · Idempotency key required

Not available over MCP: Accountants' corrections grant isn't offered over MCP yet: phase 1 is read and comment only.

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `submissionId` | string (ID) | Yes | The ID of an upload, returned by uploads.prepare or uploads.inline. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/tax.sources.confirm \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "submissionId": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/tax.sources.confirm
