Handles `POST /v1/wallets/screen`.
Errors
Returns 401 without usable credentials, 422 for an unusable address,
and 500 when a store fails. A repeated Idempotency-Key returns 200
with the original screening instead of screening again.
Authorizations
A tenant API key. Acts for exactly one tenant and cannot conclude a case, because a conclusion records a person.
Body
Wallet screening request body.
Address to screen.
Network the address is on.
Network the address is on, as a code such as ETHEREUM.
A string rather than the enum, so that a network this build does not screen reaches the handler and is refused by name. Typed as the enum it failed deserialization first, which returned a generic malformed-body error - indistinguishable from a typo, and giving an integration no way to tell "you sent rubbish" from "we do not cover that ledger".
Ask the provider again instead of reusing a cached answer.
Tenant's customer, when the wallet belongs to one.
Response
A replayed Idempotency-Key, or a cached screening
Wallet screening response body.
Address that was screened.
Decision outcome. Sentinel recommends; it never enforces.
ALLOW, WARN, BLOCK, HOLD, REVIEW_REQUIRED, FLAG, BLOCK_RECOMMENDED, SUSPEND, END_STREAM Decision record identifier.
References to the retained raw provider response.
Normalized risk exposures.
Mixer signals derived from the exposures.
Provider and data version behind the screening.
Explanation reasons.
Review lifecycle state.
PENDING, APPROVED, OVERTURNED, NOT_REQUIRED Explainable risk level.
LOW, MEDIUM, HIGH, CRITICAL The sanctions publications this answer was reached against.
Present for a clean answer too: a customer being told an address is not designated needs to be able to say which publication that was decided against, and on what date it was retrieved.
Sanctions signals.
Screening record identifier.
Whether the answer was reused from the screening cache.
Entity the address is attributed to.
Where a reused answer came from, and how old it was.
Review case opened for the decision, when one was needed.
The provider's own score, an input signal only.

