> ## Documentation Index
> Fetch the complete documentation index at: https://docs.crypto.westminister.tech/llms.txt
> Use this file to discover all available pages before exploring further.

# Upload Bank Receipt PDF (Proof Of Payment)

> Multipart `file` (PDF). Max size from `OTC_PROOF_MAX_BYTES` (default 10MB). Validates PDF magic bytes and SHA-256. Allowed while `draft`, `priced`, or `pending`.

On success, **`file_url`** and **`deposit.proof_url`** are relative paths such as `/otc-deposits-proof/{deposit_id}/{uuid}.pdf`.
View in a browser or web app by prepending the API base URL, for example `http://13.42.110.185:8080` + `file_url`.
See **`GET /otc-deposits-proof/{deposit_id}/{file_name}`** (no auth).

Files are stored under `OTC_DEPOSITS_PROOF_DIR` (default `/home/ubuntu/coinpool/otc_deposits_pops`).
Triggers optional webhook events when `OTC_EVENTS_WEBHOOK_URL` is set.




## OpenAPI

````yaml /openapi.yaml post /api/v1/auth/otc/deposits/{id}/proof
openapi: 3.1.0
info:
  title: EmaalCoin API
  description: >
    EmaalCoin API reference. These APIs power cryptocurrency exchange between
    USDT and Fiat trading.


    - **On-Ramp**: Buy USDT with fiat (KES) via mobile money (STK Push for
    Kenya)

    - **Off-Ramp**: Sell USDT for KES with mobile money payout (Kenya)

    - **Ethereum, TRON, and Solana**: Multi-chain wallet support

    - **Merchant Offers**: Create and manage trading offers

    - **OTC Flows**: Bank and mobile money deposits/withdrawals for merchants

    - **Pricing engine**: FX quotes and fee profiles for quote-backed orders and
    transfers

    - **P2P/B2B transfers**: Internal and external stablecoin sends (USDT/USDC)
    with optional pricing snapshots

    - **Stablecoin swaps**: Treasury-backed two-leg USDT ↔ USDC conversion with
    BitGo confirmation, inventory reservation, and automatic refunds

    - **Multisig**: Collaborative and platform-managed multisig flows for
    high-value B2B
  version: 1.1.0
servers:
  - url: https://crypto.westminister.tech
    description: Production API (requires DNS for this hostname).
  - url: http://13.42.110.185:8080
    description: >-
      UAT on EC2 (direct). Use this base when building proof PDF URLs if the
      production hostname does not resolve.
security: []
tags:
  - name: Pricing
    description: >-
      Commercial pricing profiles and FX rate quotes (admin). Used with orders
      and transfers for auditable snapshots.
  - name: Transfers
    description: >-
      P2P and B2B stablecoin transfers (USDT/USDC). Optional fiat-equivalent
      pricing fields. B2B multisig behavior depends on wallet registration
      (synchronous completion vs proposal flow).
  - name: Stablecoin Swaps
    description: >-
      Treasury-backed USDT ↔ USDC conversions for BitGo provider-managed wallets
      on `tron`, `ethereum`, or `solana`. Collection confirms before treasury
      payout starts. Completion requires both legs and dual-asset balance
      synchronization.
  - name: Multisig
    description: >-
      Multisig wallet registration and TRON proposal/confirm flows
      (vendor/admin).
  - name: Escrow Wallets
    description: Escrow pool wallet metadata for off-ramp and operations.
  - name: Users
    description: >-
      User-related operations (registration, lookup, updates, counts, status
      changes)
  - name: Wallets-Users
    description: User wallet operations (create, manage, query balances)
  - name: Offers
    description: Offer operations (create, read, list, counts)
  - name: Orders
    description: Order operations (create, update, list, counts, stats)
  - name: Payment
    description: Payment initiation operations
  - name: Merchants
    description: >
      Merchant (vendor) onboarding and hierarchy operations.

      USE **GET /API/V1/AUTH/MERCHANTS** WITH **PAGE_ID** AND **PAGE_SIZE** TO
      PAGE MASTER VENDORS.

      USE **GET /API/V1/AUTH/MERCHANTS/{MERCHANT_ID}** FOR ONE MASTER VENDOR,
      **MERCHANT_WALLETS**, AND ALL **SUBVENDOR** ROWS WITH **WALLETS** (FULL
      TREE).
  - name: OTC Deposits
    description: >
      OTC fiat-to-crypto deposits (bank or mobile money). Rows live in
      **`otc_deposits`**. Merchants create drafts or one-shot deposits.
      **admin**, **otc_officer**, or **treasury** list all deposits.

      B2B bank flow uses draft, quote, submit, proof, assign, claim, settlement,
      and audit. **`credited_to_address`** is the merchant on-chain wallet
      treasury credits (resolved from the default wallet for
      **`requested_network`** on the master merchant ledger user or any
      **sub-vendor** under that merchant).

      **`GET /api/v1/auth/otc/deposits`** backfills missing
      **`credited_to_address`**/**`to_wallet_id`** when a wallet can be
      resolved. One-shot **`POST /api/v1/auth/otc/deposits`** persists the
      payout address when **`requested_network`** is sent.

      Bank proof PDFs upload via `POST .../proof` and are viewed at **`GET
      /otc-deposits-proof/{deposit_id}/{file}.pdf`** (relative
      **`proof_url`**/**`file_url`** plus API base URL).

      Merchants may edit tab-1 draft fields with **`PATCH
      /api/v1/auth/otc/deposits/{id}/draft`** while **`status`** is **`draft`**.
  - name: OTC Withdrawals
    description: >-
      OTC crypto-to-fiat withdrawals (bank or mobile money). Merchants create.
      Admin approves and executes.
  - name: OTC Config
    description: OTC display config (bank details, mobile money paybill) for merchant UI
  - name: Fiat Currencies
    description: >
      Shared platform **fiat_currencies** catalog. **GET
      /api/v1/auth/fiat-currencies** lists active rows for UI pickers. **GET
      /api/v1/auth/fiat-currencies/admin** lists all rows including inactive
      (admin). Admin manages rows with **GET
      /api/v1/auth/fiat-currencies/{id}**, **POST
      /api/v1/auth/fiat-currencies**, **PATCH
      /api/v1/auth/fiat-currencies/{id}**, and **DELETE
      /api/v1/auth/fiat-currencies/{id}**. Use for OTC, pricing, orders,
      remittance, and backoffice — not under **`/otc/...`**. Prefer **PATCH**
      with **`is_active: false`** over delete when a currency is referenced.
  - name: Countries
    description: >-
      Shared platform **countries** catalog. Public **GET /api/v1/countries**
      lists active rows for pickers. Auth **GET /api/v1/auth/countries** returns
      the same active catalog. Admin manages rows with **GET
      /api/v1/auth/countries/admin**, **GET /api/v1/auth/countries/{id}**,
      **POST /api/v1/auth/countries**, **PATCH /api/v1/auth/countries/{id}**,
      and **DELETE /api/v1/auth/countries/{id}**.
  - name: Files
    description: Authenticated file uploads for OTC receipts and proof artifacts.
paths:
  /api/v1/auth/otc/deposits/{id}/proof:
    post:
      tags:
        - OTC Deposits
      summary: Upload Bank Receipt PDF (Proof Of Payment)
      description: >
        Multipart `file` (PDF). Max size from `OTC_PROOF_MAX_BYTES` (default
        10MB). Validates PDF magic bytes and SHA-256. Allowed while `draft`,
        `priced`, or `pending`.


        On success, **`file_url`** and **`deposit.proof_url`** are relative
        paths such as `/otc-deposits-proof/{deposit_id}/{uuid}.pdf`.

        View in a browser or web app by prepending the API base URL, for example
        `http://13.42.110.185:8080` + `file_url`.

        See **`GET /otc-deposits-proof/{deposit_id}/{file_name}`** (no auth).


        Files are stored under `OTC_DEPOSITS_PROOF_DIR` (default
        `/home/ubuntu/coinpool/otc_deposits_pops`).

        Triggers optional webhook events when `OTC_EVENTS_WEBHOOK_URL` is set.
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              type: object
              required:
                - file
              properties:
                file:
                  type: string
                  format: binary
      responses:
        '201':
          description: Proof stored and linked
          content:
            application/json:
              schema:
                type: object
                properties:
                  deposit:
                    $ref: '#/components/schemas/OtcDeposit'
                  proof_file_sha256:
                    type: string
                  size_bytes:
                    type: integer
                  file_url:
                    type: string
                    description: >-
                      Relative path to view the PDF. Prepend API base URL (see
                      `servers`).
                    example: >-
                      /otc-deposits-proof/ce6e4186-16fe-4e0d-a97d-7638f11c6063/8251c719-0941-46da-8792-5acce5e5efc8.pdf
      security:
        - bearerAuth: []
components:
  schemas:
    OtcDeposit:
      type: object
      properties:
        id:
          type: string
          format: uuid
        merchant_id:
          type: string
          format: uuid
        method:
          type: string
          enum:
            - bank
            - mpesa
        fiat_amount:
          type: string
        fiat_currency:
          type: string
        status:
          type: string
          enum:
            - draft
            - priced
            - pending
            - confirmed
            - rejected
            - credited
        payment_reference:
          type: string
          nullable: true
          description: Bank wire reference. Globally unique (case-insensitive) when set.
        proof_url:
          type: string
          nullable: true
          description: >-
            Relative path to the bank proof PDF. Prepend API base URL for `GET`
            in browsers (`GET /otc-deposits-proof/...`, no auth).
          example: >-
            /otc-deposits-proof/ce6e4186-16fe-4e0d-a97d-7638f11c6063/8251c719-0941-46da-8792-5acce5e5efc8.pdf
        transfer_date:
          type: string
          format: date-time
          nullable: true
        merchant_request_id:
          type: string
          nullable: true
        checkout_request_id:
          type: string
          nullable: true
        mpesa_receipt_number:
          type: string
          nullable: true
        mpesa_phone_number:
          type: string
          nullable: true
        sender_account_name:
          type: string
          nullable: true
        sender_account_number_last4:
          type: string
          nullable: true
        sender_bank_name:
          type: string
          nullable: true
        sender_bank_branch:
          type: string
          nullable: true
        receipt_number:
          type: string
          nullable: true
        receipt_uploaded_at:
          type: string
          format: date-time
          nullable: true
        proof_file_name:
          type: string
          nullable: true
        proof_mime_type:
          type: string
          nullable: true
        proof_size_bytes:
          type: integer
          format: int64
          nullable: true
        proof_file_sha256:
          type: string
          nullable: true
        requested_asset:
          type: string
          nullable: true
        requested_network:
          type: string
          nullable: true
        requested_crypto_amount:
          type: string
          nullable: true
        pricing_profile_id:
          type: string
          format: uuid
          nullable: true
        fx_rate_quote_id:
          type: string
          format: uuid
          nullable: true
        negotiated_fx_reference_id:
          type: string
          format: uuid
          nullable: true
        confirmed_at:
          type: string
          format: date-time
          nullable: true
        confirmed_by:
          type: string
          format: uuid
          nullable: true
        rejected_at:
          type: string
          format: date-time
          nullable: true
        rejected_by:
          type: string
          format: uuid
          nullable: true
        rejection_reason:
          type: string
          nullable: true
        internal_note:
          type: string
          nullable: true
        credited_at:
          type: string
          format: date-time
          nullable: true
        credited_by:
          type: string
          format: uuid
          nullable: true
        usdt_amount:
          type: string
          nullable: true
        credited_asset:
          type: string
          nullable: true
        credited_crypto_amount:
          type: string
          nullable: true
        credited_to_address:
          type: string
          nullable: true
          description: >-
            Merchant blockchain address to receive USDT/USDC on treasury credit.
            Resolved from the default wallet for **requested_network** on the
            master merchant ledger or a **sub-vendor** under that merchant. Set
            on draft, one-shot create (when **requested_network** is sent),
            quote refresh, and list backfill when missing.
          example: TJyF42dRr18tSiXV9Cf7JtYUtTbqAGZg94
        to_wallet_id:
          type: string
          format: uuid
          nullable: true
          description: Internal **wallets.id** paired with **credited_to_address**.
        payout_to_address:
          type: string
          nullable: true
          readOnly: true
          description: >-
            Same as **credited_to_address** when the API enriches the response
            (list/detail). Omitted when no wallet can be resolved.
        payout_to_wallet_id:
          type: string
          format: uuid
          nullable: true
          readOnly: true
          description: Same as **to_wallet_id** on enriched responses.
        payout_network:
          type: string
          nullable: true
          readOnly: true
          description: Network from the resolved payout wallet (**tron** or **ethereum**).
        payout_asset:
          type: string
          nullable: true
          readOnly: true
          description: Mirrors **requested_asset** when enrichment runs.
        transfer_id:
          type: string
          format: uuid
          nullable: true
        idempotency_key:
          type: string
          nullable: true
        submitted_at:
          type: string
          format: date-time
          nullable: true
        assigned_to_user_id:
          type: string
          format: uuid
          nullable: true
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: PASETO

````