Skip to main content
PUT
Set the policy document
Sets the policy document for a filing belonging to the authenticated upstream entity to a Surplus Lines file you already uploaded, identified by fileDocumentId. Returns the filing with the policy document in place. It replaces Upload the Policy Document, which is deprecated. Send a JSON body with one field: fileDocumentId.

The flow

  1. Upload the file with Upload a Document, using the category Surplus Lines. The file can be a PDF, DOC, DOCX, JPEG or PNG, up to 10 MB.
  2. Read the _id of the document the upload returns. That is the fileDocumentId.
  3. Call this endpoint with the filing’s id and that fileDocumentId.
Every Surplus Lines upload creates a new document, so nothing is shared between two uploads of the same file.

Replacing a policy document

Setting the policy document again replaces the existing one. The previous file is soft-deleted at the moment the new one is set, and a filing never holds two policy documents. Retrying the same request with the same fileDocumentId is safe.

Which files are accepted

The file must be a Surplus Lines upload of your own that is not on any filing yet. Anything else returns 404, the same response as an unrecognized id, so a caller cannot tell “does not exist” from “not yours to use”. That covers a file that is already on a filing, a file in another category, a file another organization uploaded, and a file that has been deleted. This endpoint supports idempotency. If you include an idempotency-key header, duplicate requests within 1 hour return the original response without reprocessing. See Idempotency.

Error Scenarios

Bad Request (400)

Returned when filingId or fileDocumentId is not a valid MongoDB ObjectId.

Filing or File Not Found (404)

Returned when filingId does not exist or belongs to a different upstream entity, or the file is not an unattached Surplus Lines upload of yours.

Unauthorized (401)

Missing or invalid authentication token. See Authentication.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Headers

idempotency-key
string

UUID to ensure idempotent request processing

Example:

"550e8400-e29b-41d4-a716-446655440000"

x-idempotency-key
string

Alternative UUID header for idempotent request processing

Example:

"550e8400-e29b-41d4-a716-446655440000"

Path Parameters

filingId
string
required

Unique identifier of the surplus-lines filing

Example:

"6650a1b2c3d4e5f6a7b8c9d0"

Body

application/json
fileDocumentId
string
required

The fileDocumentId the upload returned for a Surplus Lines file that is not yet on any filing

Example:

"6650a1b2c3d4e5f6a7b8c9d2"

Response

Filing with the policy document in place

data
object
required
requestId
string
required

Unique request identifier

Example:

"dev-2c5e7cf2-9acf-4c8c-ab2f-b81f39d775a8"

timestamp
string
required

Response timestamp

Example:

"2025-11-12T20:49:03.293Z"