Handles document intake for cases and applications: virus scanning, document-type classification, sensitivity labeling (CUI / Privacy), and text extraction. Extracted text carries page references so AI answers can cite the exact page they came from.
Reference design by Iron Brick LLC. Not an official government system; endpoints and data models are adapted to each agency's systems of record during implementation.
Base URLs
https://dev.ironbrick.us/sandbox/documents/v1Iron Brick sandbox (synthetic data; free developer account)https://{agency-gateway}/documents/v1Agency deployment (behind the agency API gateway)
Authentication
Send an OAuth 2.0 bearer token from POST https://dev.ironbrick.us/oauth/token in the Authorization header. Your application must hold the scope listed on each operation. How authentication works.
| Scope | Grants |
|---|---|
documents:read | Read documents and extracted text |
documents:write | Upload documents |
POST /documents
Upload a document · requires scope documents:write
Multipart upload. The document is scanned before it becomes available.
Request body multipart/form-data
file=string&caseId=string&category=supporting_evidenceResponses
| 202 | Document accepted for scanning |
| 400 | Invalid request |
| 401 | Missing or invalid access token |
| 403 | Caller lacks the required scope |
| 422 | Business rule violation |
curl -X POST "https://dev.ironbrick.us/sandbox/documents/v1/documents" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"file": "string", "caseId": "string", "category": "supporting_evidence"}'{
"documentId": "DOC-551920",
"fileName": "lease-agreement.pdf",
"mediaType": "application/pdf",
"sizeBytes": 284113,
"sha256": "9b1f0c4e3a6d...",
"classification": "proof_of_residence",
"sensitivity": "cui_privacy",
"status": "available",
"createdAt": "2026-10-01T12:00:00Z"
}GET /documents/{documentId}
Get document metadata · requires scope documents:read
Parameters
| Name | In | Type | Description |
|---|---|---|---|
documentId required | path | string | Document identifier. |
Responses
| 200 | Document metadata |
| 401 | Missing or invalid access token |
| 403 | Caller lacks the required scope |
| 404 | Resource not found |
curl -X GET "https://dev.ironbrick.us/sandbox/documents/v1/documents/{documentId}" \
-H "Authorization: Bearer $TOKEN"{
"documentId": "DOC-551920",
"fileName": "lease-agreement.pdf",
"mediaType": "application/pdf",
"sizeBytes": 284113,
"sha256": "9b1f0c4e3a6d...",
"classification": "proof_of_residence",
"sensitivity": "cui_privacy",
"status": "available",
"createdAt": "2026-10-01T12:00:00Z"
}GET /documents/{documentId}/content
Download document content · requires scope documents:read
Returns a short-lived signed URL. Every download is written to the audit log.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
documentId required | path | string | Document identifier. |
Responses
| 200 | Signed download URL |
| 401 | Missing or invalid access token |
| 403 | Caller lacks the required scope |
| 404 | Resource not found |
curl -X GET "https://dev.ironbrick.us/sandbox/documents/v1/documents/{documentId}/content" \
-H "Authorization: Bearer $TOKEN"{
"url": "https://example.gov/resource",
"expiresAt": "2026-10-01T12:00:00Z"
}GET /documents/{documentId}/text
Get extracted text · requires scope documents:read
Page-level text for search and AI retrieval, with page numbers for citations.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
documentId required | path | string | Document identifier. |
Responses
| 200 | Extracted text |
| 401 | Missing or invalid access token |
| 403 | Caller lacks the required scope |
| 404 | Resource not found |
curl -X GET "https://dev.ironbrick.us/sandbox/documents/v1/documents/{documentId}/text" \
-H "Authorization: Bearer $TOKEN"{
"documentId": "string",
"pages": [
{
"page": 1,
"text": "RESIDENTIAL LEASE AGREEMENT ..."
}
]
}Schemas
Document
| Field | Type | Description |
|---|---|---|
documentId | string | |
fileName | string | |
mediaType | string | |
sizeBytes | integer | |
sha256 | string | |
classification | string | |
sensitivity | string (public | cui | cui_privacy) | |
status | string (uploaded | scanning | available | quarantined) | |
createdAt | string (date-time) |