Skip to main content
PUT
Publishes the token’s instrument record: its identifiers, legal terms, ranking, term, redemption, register and offering documents. There is one record per token and chain, and it is what a lender of record reads before it takes a market on the token. Your instance’s overview can be sent with it under presentation. Only the token’s controller publishes the record. A save is accepted on one of two authorities:
  • Your instance controls the token. One of its verified wallets is the token’s owner(), a T-REX agent or a holder of DEFAULT_ADMIN_ROLE, or the token was issued through your instance. Send the record alone.
  • The controller signed it. Send issuerApproval with the controller’s signature over the message from Request Instrument Approval. Your instance carries the record and needs no role on the token. See the issuer-signed flow.
Everything in the record is an assertion of the instance that publishes it. Identifiers are checked for format and check digits, the issuer identity is resolved from GLEIF, and nothing else is verified against a register or a regulator.

Path Parameters

string
required
The token contract address. It has to be an active import of your instance, or issued through it.

Body Parameters

object
Record fields by key, from Get Instrument Schema. A field you send is set, null or an empty string clears it, and a field you leave out keeps its value.
array
The full document list. Sending it replaces every document; leaving it out keeps them. Each entry is { docType, uri, contentHash, mimeType, bytes, language, issuedAt, cid?, version? }, with contentHash the sha256 of the file as 64 lower-case hex characters. At most 40.
object
Your overview, as in Update Profile. Left out, the overview stays as it is.
boolean
Replace a record another instance asserts. Without issuerApproval this works only when that instance released the record or no longer controls the token. With issuerApproval the controller’s signature is enough.
object
The token controller’s approval of exactly this body.

How an issuer approval is checked

Every check runs before anything is written, cheapest first:
  1. The shape of issuerApproval.
  2. Freshness: signed at most ten minutes ago, at most two minutes in the future.
  3. recordVersion equals the record’s current version, checked again inside the save.
  4. The content digest is rebuilt from the body you sent.
  5. The signature: an ECDSA signature that recovers to signer, or an ERC-1271 isValidSignature answer from the signer contract.
  6. The signer’s role on the token, read on chain now: owner(), isAgent(signer) or hasRole(DEFAULT_ADMIN_ROLE, signer). A former owner or a revoked agent is refused.
The record then stands as asserted by your instance, on the authority of the signer. Its provenance keeps authority { basis, wallet: signer, via: "ISSUER_SIGNATURE" } and the approval with the signature, the digest, the record version, the signing time and the signed message, so any lender can check the signature independently.

Response Fields

object

Error Codes