> ## Documentation Index
> Fetch the complete documentation index at: https://t3sa.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Propose new policy

> Draft: specification in progress. Endpoints and fields may change.

Proposes a new version of the policy. The percentages must add up to 100 and
only supported assets are accepted. The new version applies to future deposits
and serves as the reference for rebalancing proposals. Scope: `admin`.


<Warning>Draft: specification in progress. Endpoints and fields may change.</Warning>


## OpenAPI

````yaml /en/api/openapi.yaml put /politica-de-alocacao
openapi: 3.1.0
info:
  title: TESA API
  version: 0.1.0-rascunho
  description: >
    **Draft: specification in progress. Endpoints and fields may change.**


    TESA's B2B treasury infrastructure API. USDC comes in through Circle's CCTP

    (Ethereum and Solana) and is allocated to tokenized Treasuries (USDY and
    BUIDL).

    The API is non-custodial: it never receives a private key or a signed
    transaction.

    It returns unsigned transactions and approval requests, and the signer is
    the

    company or its custodian.


    Resource paths, field names, event names and error codes are in Portuguese
    by

    design. Amounts are USDC decimal strings with two decimal places, dates are
    ISO

    8601 UTC and lists use cursor pagination (`limite` and `apos`). All example

    values are illustrative.
  contact:
    name: TESA
    email: contact@t3sa.com
    url: https://t3sa.com
servers:
  - url: https://api.t3sa.com/v1
    description: Production (proposed URL, not live yet)
  - url: https://sandbox.api.t3sa.com/v1
    description: Sandbox (proposed URL, not live yet)
security:
  - bearerAuth: []
tags:
  - name: Organization
    description: The client company, owner of all keys and resources.
  - name: Wallets
    description: >-
      Company wallets linked by public address. No key ever passes through the
      API.
  - name: Positions
    description: A snapshot of the cash position, the same as in the dashboard.
  - name: Allocation policy
    description: Assets approved by the company and the proportion between them.
  - name: Proposals
    description: >-
      Every allocation movement starts as a proposal and only executes with
      approval.
  - name: Redemptions
    description: Return of USDC balance to a linked company wallet.
  - name: Records
    description: On-chain audit trail, with the hash of each transaction.
  - name: Yield and charges
    description: Yield calculated per period and the fee charged on it.
  - name: Webhooks
    description: Destinations that receive TESA events.
paths:
  /politica-de-alocacao:
    put:
      tags:
        - Allocation policy
      summary: Propose new policy
      description: >
        Draft: specification in progress. Endpoints and fields may change.


        Proposes a new version of the policy. The percentages must add up to 100
        and

        only supported assets are accepted. The new version applies to future
        deposits

        and serves as the reference for rebalancing proposals. Scope: `admin`.
      operationId: atualizarPolitica
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PoliticaAtualizar'
      responses:
        '200':
          description: New version registered.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PoliticaDeAlocacao'
        '401':
          $ref: '#/components/responses/NaoAutenticado'
        '403':
          $ref: '#/components/responses/SemPermissao'
        '422':
          $ref: '#/components/responses/NaoProcessavel'
      security:
        - bearerAuth: []
        - bearerAuth: []
          tesaTimestamp: []
          tesaSignature: []
components:
  schemas:
    PoliticaAtualizar:
      type: object
      required:
        - alocacao
      properties:
        alocacao:
          type: array
          description: The percentages must add up to 100.
          items:
            $ref: '#/components/schemas/AtivoPercentual'
        comentario:
          type: string
    PoliticaDeAlocacao:
      type: object
      properties:
        versao:
          type: integer
          examples:
            - 3
        alocacao:
          type: array
          items:
            $ref: '#/components/schemas/AtivoPercentual'
        status:
          type: string
          enum:
            - vigente
            - pendente
        aprovada_por:
          type:
            - string
            - 'null'
        vigente_desde:
          type:
            - string
            - 'null'
          format: date-time
    AtivoPercentual:
      type: object
      required:
        - ativo
        - percentual
      properties:
        ativo:
          $ref: '#/components/schemas/Ativo'
        percentual:
          type: number
          examples:
            - 60
    Erro:
      type: object
      properties:
        erro:
          type: object
          properties:
            codigo:
              type: string
              examples:
                - saldo_insuficiente
            mensagem:
              type: string
            campo:
              type:
                - string
                - 'null'
            requisicao_id:
              type: string
              examples:
                - req_9d8c7b
    Ativo:
      type: string
      enum:
        - USDY
        - BUIDL
  responses:
    NaoAutenticado:
      description: Missing, invalid or revoked key, or invalid HMAC signature.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Erro'
    SemPermissao:
      description: Insufficient scope or IP outside the allowlist.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Erro'
    NaoProcessavel:
      description: Business rule violated, such as insufficient balance or invalid policy.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Erro'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        The organization's API key (`tesa_live_...` in production,
        `tesa_test_...` in the sandbox).
    tesaTimestamp:
      type: apiKey
      in: header
      name: Tesa-Timestamp
      description: >-
        Optional in the current proposal. Request time in Unix seconds, used in
        the HMAC signature.
    tesaSignature:
      type: apiKey
      in: header
      name: Tesa-Signature
      description: >-
        Optional in the current proposal. Hex-encoded HMAC-SHA256 of the
        canonical message (timestamp, method, path and raw body).

````