VexusPayOfficial documentation
Operational API
PT EN ES
VEXUS PUBLIC API · 2026-09-15

A financial API ready for its next great integration.

Connect Pix, boleto, checkout, crypto, cards and Split Payment with stable contracts, security and visibility at each step.

Contract OpenAPI Signed webhooks Sandbox public and isolated
Illustration of payment infrastructure VexusPay
Production URL base — moves real valueshttps://api.nodexhub.com.br
API Ecosystem VexusPay for payments, cards, boleto, crypto and Split
Test environment

Complete, isolated Sandbox

Public SandboxUse https://sandbox-api.vexuspay.com.br to test the published contract without moving real funds. Production credentials never work in Sandbox, and Sandbox credentials never work in Production.

Create a credential marked Sandbox under Settings → Credentials. Its identifier starts with vx_sbx_. The isolated workspace has simulated balances, resources, idempotency records, and webhook deliveries; it never calls a financial provider.

01

Simulated balance

Use GET /api/v1/sandbox/workspace, the faucet, and reset endpoint to organize deterministic tests.

02

Realistic state transitions

Create resources through their regular API routes, then use Sandbox Controls to approve, fail, expire, or reverse pending simulated operations.

03

Separated webhooks

Sandbox endpoints, delivery attempts, and signatures never share state with Production. OTP payloads remain encrypted and are redacted from audit output.

Error scenariosIn Sandbox only, send X-Vexus-Sandbox-Scenario with success, insufficient_balance, provider_timeout, rate_limited, declined, expired, or webhook_retry. Production rejects this header.
01

HTTPS + JSON

Stable contracts, structured responses, and backend-ready examples.

02

Idempotency

Safe retries for financial operations without duplicate movements.

03

Signed webhooks

Authenticated delivery, stable event identifiers, and controlled retries.

Fundamentals

Server-to-server authentication

Private routes require both credentials below. Send them only from your backend. Never expose the Client Secret in browser code, a mobile application, a URL, a support request, or application logs.

Required headers
Apikey: YOUR_CLIENT_ID
X-Client-Secret: YOUR_CLIENT_SECRET
Content-Type: application/json
01

Create the credential

Select the correct environment and grant only the required scopes. The Client Secret is displayed once when created or rotated; store it immediately in a secrets vault.

02

Enable product and scope

Product access and credential scope are independent checks. HTTP 403 can mean either one is missing even when the credential is valid.

03

Restrict the origin

If an IP allowlist is enabled, register the public egress IP of your backend. Do not call private routes directly from a browser or mobile application.

The PIN is a control-plane secretThe six-digit PIN only authorizes administrative panel actions such as creating a credential. Never send it to the integrating application, an AI, browser code, or an API request. The backend uses only Apikey and X-Client-Secret.
Integration ownershipA credential name and domain do not change the account that owns it. In Production, use a dedicated business account or formally authorize sharing the owning account. Products, balances, limits, fees, operations, and callbacks are isolated by account and credential.
Reliability

Idempotency

Your backend creates an Idempotency-Key of 8–100 characters for each new mutable business intent. Keep the exact method, URL, body, file bytes, and key for retries. A different body with the same key returns a conflict; a new intent always requires a new key.

1

Generate one key

Use a random UUID before the first request.

2

Send it in the header

Include it with the credentials and request payload.

3

Look up the intent

Without a conclusive response, call GET /api/v1/account/operations/by-idempotency/{idempotencyKey}?operation=... with the same credential.

4

Reconcile before replacing

Create a new key only after the original intent is terminal or definitively failed.

Reliability

Errors and retries

JSON errors provide a stable code, human-readable message, details, correlationId, and retryable. Store the correlation ID, never credentials or sensitive bodies.

4xx

Correct or inspect state

400/413/415/422 indicate invalid input. 401 means authentication failed; 403 means authorization failed. 404 also protects account isolation. For 409, inspect the existing resource or original intent.

429

Honor Retry-After

Wait for Retry-After, then apply exponential backoff with jitter. A retry must preserve the original idempotency key and request body.

5xx

Fail closed

Do not assume success or failure after a timeout or 5xx. Look up the original Idempotency-Key before any new POST. If the state remains inconclusive, keep it under review and contact support with the correlationId.

Asynchronous acceptanceHTTP 201/202 can mean creation or admission, not PIX settlement or blockchain confirmation. Persist returned IDs and follow the resource by query and webhook until a terminal state.
Cryptocurrency

Wallet, deposit, and transfer flow

Use the same server-side credentials as the other modules. Always query networks, assets, swap pairs, and conversion capabilities before showing an action: the catalog is the source of truth for current availability.

  1. 1
    Create or retrieve the wallet

    Wallet creation is idempotent by account and network. For individual White Label custody, send X-Vexus-Custody-Subject with an immutable opaque user ID. For central custody, send only X-Vexus-Custody-Access: CENTRAL. These headers are mutually exclusive.

  2. 2
    Receive and monitor deposits

    Use the wallet address, then follow confirmations and deposit status. HTTP 200 or CREDITED does not replace waiting for the documented terminal state.

  3. 3
    Quote before every mutable action

    Amounts ending in _units or _minor are integer strings in the smallest unit—never floating-point values. Quotes define fees, executable limits, and expiry.

  4. 4
    Confirm once and reconcile

    Use a new idempotency key for confirmation, persist the returned ID, and follow it to a terminal state. In GROSS mode, fees are deducted from the authorized ceiling; in NET mode, fees may increase the total debit.

Current conversion availabilityBRL-to-crypto requires an external destination and an enabled capability. Crypto-to-BRL remains in maintenance: do not submit new quotes or confirmations until the capabilities endpoint reports it as available.
Operational channel

Support API

Any active Production account with product support and scope support.manage can embed VexusPay support in its own backend. The authenticated credential determines the account; no customer/account identifier is accepted in the body, and cross-account resources are never disclosed.

01

Tickets and messages

Create, list, read, reply to, and close tickets through the published routes. All writes require Idempotency-Key.

02

Private images

Upload JPEG, PNG, or WebP in the multipart file field. The maximum is 5 MiB per image and four attachments per message. Downloads always require API credentials and must be proxied by your backend.

03

Signed events

Register an HTTPS endpoint for support events. The signing secret is returned once and must be stored in a secrets vault; it is never shown again.

Browser safetyNever send Apikey, X-Client-Secret, signing secrets, or authenticated attachment URLs to browser code. Use your backend as the trusted boundary.
Events

Signed webhooks

Read and preserve the raw request body before parsing JSON. Compute HMAC-SHA256(timestamp + "." + rawBody, signing_secret), compare it in constant time with X-Vexus-Signature, reject stale timestamps, and deduplicate by event_id and X-Vexus-Delivery.

Delivery headers
X-Vexus-Event: <event_name>
X-Vexus-Delivery: <uuid>
X-Vexus-Timestamp: <unix_timestamp>
X-Vexus-Signature: v1=<hmac_sha256>
Fast acknowledgementPersist the verified event, return 2xx quickly, and process it in an internal queue. Transport failures, 408, 409, 425, 429, and 5xx are retried. Duplicate events must never trigger a second financial operation.
Complete reference

Published endpoints

The following examples are derived from the same contract that generates the OpenAPI and the collection Postman.

Module

Status

Unauthenticated technical availability.

GET /health/live Public

Liveness

Checks whether the HTTP process is running.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/health/live", {
  method: 'GET',
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /health/ready Public

Readiness

Validates the database, migrations, and internal dependencies required to accept traffic.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/health/ready", {
  method: 'GET',
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Module

PIX

PIX cash-in, cash-out, QR Code decoding, and payment.

API Flow PIX VexusPay, from collection to confirmation webhook
POST /api/v1/cashin Credentials Scope: cashin Product: pix.cash_in

Create PIX charge

Creates a dynamic PIX charge.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cashin", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "amount": 25.9
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "amount": 25.9
}
POST /api/v1/cashout Credentials Scope: cashout Product: pix.cash_out

Send PIX

Sends a PIX payment to the supplied key, subject to the account balance, enabled product, and limits.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cashout", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "amount": 20,
    "pix_key": "<destination-pix-key>",
    "pix_key_type": "random",
    "description": "Funds transfer"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "amount": 20,
    "pix_key": "<destination-pix-key>",
    "pix_key_type": "random",
    "description": "Funds transfer"
}
POST /api/v1/pix/qr/decode Credentials Scope: cashout Product: pix.cash_out

Decode PIX QR Code

Validates the CRC and decodes a static or dynamic PIX EMV payload without moving funds. The response indicates whether the amount is fixed by the QR Code.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/pix/qr/decode", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE"
}
POST /api/v1/pix/qr/pay Credentials Scope: cashout Product: pix.cash_out

Pay PIX QR Code

Pays a PIX QR Code after validating its CRC, declared amount, balance, and limits. An amount embedded in the QR Code always takes precedence over an amount sent by the integrator.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/pix/qr/pay", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE",
    "description": "Supplier"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE",
    "description": "Supplier"
}
Module

Boleto

Boleto issuance, lookup, and payment.

API Flow from boleto VexusPayfrom issue to payment
POST /api/v1/boleto/issue Credentials Scope: boleto Product: boleto

Issue boleto

Issues a standalone boleto charge without requiring a Checkout catalog item. The boleto API product must be enabled. Name, CPF/CNPJ, and email come from the account profile; an address is not required.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/boleto/issue", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "amount": 99.9,
    "due_date": "2026-09-30",
    "description": "Boleto payment request"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "amount": 99.9,
    "due_date": "2026-09-30",
    "description": "Boleto payment request"
}
POST /api/v1/boleto/info Credentials Scope: boleto Product: boleto

Get boleto details

Queries the provider for the current amount and beneficiary details without moving funds.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/boleto/info", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "billetCode": "00190000000000014990000000000000000000000000"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "billetCode": "00190000000000014990000000000000000000000000"
}
POST /api/v1/boleto/pay Credentials Scope: boleto Product: boleto

Pay boleto

Rechecks the current amount and beneficiary with the provider, then validates the balance and limits before payment. The integrator sends only the boleto code.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/boleto/pay", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "billetCode": "00190000000000014990000000000000000000000000"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "billetCode": "00190000000000014990000000000000000000000000"
}
Module

Checkout

Catalog, payment links, enabled methods, and Checkout reporting.

Card API Flow VexusPayfrom checkout to confirmation
POST /api/v1/card/config Production only Credentials Scope: cards.write Product: card PUBLISHED PRODUCTION ONLY

Get tokenization configuration

Returns the authorized public key and SDK URL used to tokenize a card in the browser. Never send PAN or CVV to the VexusPay backend.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/card/config", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
POST /api/v1/card/pay Production only Credentials Scope: cards.write Product: card PUBLISHED PRODUCTION ONLY

Process card payment

Processes a standalone charge without requiring a Checkout catalog item. The card API product must be enabled. Use a card token created once by the SDK returned by the configuration endpoint; PAN and CVV are not accepted.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/card/pay", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "amount": 99.9,
    "external_id": "example-order-123",
    "buyer_name": "Example Customer",
    "buyer_email": "customer@example.com",
    "buyer_cpf": "52998224725",
    "card_token": "REPLACE_WITH_SINGLE_USE_TOKEN",
    "payment_method_id": "visa",
    "installments": 1,
    "description": "Example order 123"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "amount": 99.9,
    "external_id": "example-order-123",
    "buyer_name": "Example Customer",
    "buyer_email": "customer@example.com",
    "buyer_cpf": "52998224725",
    "card_token": "REPLACE_WITH_SINGLE_USE_TOKEN",
    "payment_method_id": "visa",
    "installments": 1,
    "description": "Example order 123"
}
GET /api/v1/checkout/methods Credentials Scope: checkout Product: checkout

List checkout methods

Returns only approved payment methods currently available to the authenticated account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/methods", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/checkout/report Credentials Scope: checkout Product: checkout

Get checkout report

Returns aggregate metrics for payment links and orders owned by the authenticated account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/report", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/checkout/products Credentials Scope: checkout Product: checkout

List checkout products

Lists active and archived products in the account’s catalog.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/products", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/checkout/products Credentials Scope: checkout Product: checkout

Create checkout product

Creates a catalog product. A payment method that requires an external product identifier may be enabled only when provider_product_id is supplied.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/products", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "name": "Monthly plan",
    "price": "49.90",
    "currency": "BRL",
    "payment_methods": [
        "PIX"
    ]
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "name": "Monthly plan",
    "price": "49.90",
    "currency": "BRL",
    "payment_methods": [
        "PIX"
    ]
}
GET /api/v1/checkout/products/{productId} Credentials Scope: checkout Product: checkout

Get checkout product

Returns a catalog product owned by the authenticated account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
PUT /api/v1/checkout/products/{productId} Credentials Scope: checkout Product: checkout

Update checkout product

Updates a product version. Send the version returned by the read endpoint to prevent concurrent overwrites.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID", {
  method: 'PUT',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "name": "Updated monthly plan",
    "price": "59.90",
    "currency": "BRL",
    "payment_methods": [
        "PIX"
    ],
    "version": 1
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "name": "Updated monthly plan",
    "price": "59.90",
    "currency": "BRL",
    "payment_methods": [
        "PIX"
    ],
    "version": 1
}
DELETE /api/v1/checkout/products/{productId} Credentials Scope: checkout Product: checkout

Archive checkout product

Archives the product and its active links. Requires Idempotency-Key and accepts no request body.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID", {
  method: 'DELETE',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/checkout/links Credentials Scope: checkout Product: checkout

List checkout links

Lists payment links, statuses, and metrics for the authenticated account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/checkout/links Credentials Scope: checkout Product: checkout

Create checkout link

Creates a standalone link or a link associated with a product. Combine the returned payment_path with the account’s VexusPay domain.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "title": "Service payment",
    "amount": "49.90",
    "currency": "BRL",
    "payment_methods": [
        "PIX"
    ]
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "title": "Service payment",
    "amount": "49.90",
    "currency": "BRL",
    "payment_methods": [
        "PIX"
    ]
}
GET /api/v1/checkout/links/{linkId} Credentials Scope: checkout Product: checkout

Get checkout link

Returns the configuration and payment_path of a link owned by the authenticated account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
PUT /api/v1/checkout/links/{linkId} Credentials Scope: checkout Product: checkout

Update checkout link

Updates a link version. Send the version returned by the read endpoint to prevent concurrent overwrites.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID", {
  method: 'PUT',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "title": "Updated service payment",
    "amount": "59.90",
    "currency": "BRL",
    "payment_methods": [
        "PIX"
    ],
    "version": 1
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "title": "Updated service payment",
    "amount": "59.90",
    "currency": "BRL",
    "payment_methods": [
        "PIX"
    ],
    "version": 1
}
POST /api/v1/checkout/links/{linkId}/archive Credentials Scope: checkout Product: checkout

Archive checkout link

Archives the link and prevents new payments. Requires Idempotency-Key and accepts no request body.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID/archive", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/checkout/links/{linkId}/cancel Credentials Scope: checkout Product: checkout

Cancel checkout link

Cancels the link with an auditable reason and prevents new payments. Requires Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID/cancel", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "reason": "Cancellation requested by the customer"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "reason": "Cancellation requested by the customer"
}
Module

Crypto

Catalog, wallets, balances, deposits, withdrawals, swaps, internal transfers, and conversions according to current capabilities.

GET /api/v1/crypto/networks Credentials Scope: cashin Product: crypto

List crypto networks

Lists BSC and TRON together with maintenance status and deposit, withdrawal, and swap capabilities.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/networks", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/crypto/assets Credentials Scope: cashin Product: crypto

List crypto assets

Lists assets by network, their decimal precision, and the capabilities currently enabled.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/assets", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/crypto/swap-pairs Credentials Scope: cashin Product: crypto

List swap pairs

Lists available same-chain pairs and the USDT TRC-20 ↔ USDT BEP-20 cross-chain pair.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/swap-pairs", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/crypto/wallets Credentials Scope: cashin Product: crypto

List crypto wallets

Lists only wallets owned by the account or by the authenticated custody context.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/wallets", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/crypto/wallets Credentials Scope: cashin Product: crypto

Create or get wallet

Idempotently creates or reuses the account’s BSC or TRON HD wallet. Tokens on the same network share the same address.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/wallets", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "network": "BSC"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "network": "BSC"
}
GET /api/v1/crypto/wallets/{walletId} Credentials Scope: cashin Product: crypto

Get wallet

Returns a Vexus wallet owned by the authenticated account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/crypto/wallets/{walletId}/balances Credentials Scope: cashin Product: crypto

Get wallet balances

Returns ledger, available, reserved, pending, and on-chain balances as integer strings in the asset’s smallest unit.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID/balances", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/crypto/wallets/{walletId}/transactions Credentials Scope: cashin Product: crypto

List wallet transactions

Lists recent deposits and withdrawals for the wallet.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID/transactions", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/crypto/deposits Credentials Scope: cashin Product: crypto

List deposits

Lists only deposits linked to wallets owned by the account or authenticated custody context.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/deposits", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/crypto/deposits/{depositId} Credentials Scope: cashin Product: crypto

Get deposit

Returns the deposit status and confirmation count. CREDITED or HTTP 200 does not replace checking for a terminal state.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/deposits/REPLACE_WITH_DEPOSIT_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/crypto/withdrawals/quote Credentials Scope: cashout Product: crypto

Quote crypto withdrawal

Creates an authoritative quote containing fees, net amount, total debit, and validity in *_units. In GROSS mode, the entered amount is the authorized ceiling and fees are deducted from it. This call does not move funds.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/withdrawals/quote", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "network": "BSC",
    "asset": "USDT_BSC",
    "destination_address": "REPLACE_WITH_BSC_ADDRESS",
    "amount_units": "1000000",
    "amount_mode": "GROSS"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "network": "BSC",
    "asset": "USDT_BSC",
    "destination_address": "REPLACE_WITH_BSC_ADDRESS",
    "amount_units": "1000000",
    "amount_mode": "GROSS"
}
POST /api/v1/crypto/withdrawals Credentials Scope: cashout Product: crypto

Execute quoted crypto withdrawal

Reserves funds and schedules the withdrawal using quote_id. HTTP 202 does not confirm a blockchain transaction; follow the resource until it reaches a terminal state.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/withdrawals", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "quote_id": "00000000-0000-4000-8000-000000000002"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "quote_id": "00000000-0000-4000-8000-000000000002"
}
GET /api/v1/crypto/withdrawals/{withdrawalId} Credentials Scope: cashout Product: crypto

Get crypto withdrawal

Returns the status, TXID, and actual network cost when available.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/withdrawals/REPLACE_WITH_WITHDRAWAL_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/crypto/swaps/quote Credentials Scope: cashout Product: crypto

Quote crypto swap

Creates an authoritative same-chain or USDT cross-chain quote using only published pairs.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/swaps/quote", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "asset_in": "USDT_TRC20",
    "asset_out": "USDT_BSC",
    "amount_in_units": "1000000",
    "slippage_bps": 50
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "asset_in": "USDT_TRC20",
    "asset_out": "USDT_BSC",
    "amount_in_units": "1000000",
    "slippage_bps": 50
}
POST /api/v1/crypto/swaps Credentials Scope: cashout Product: crypto

Execute quoted swap

Reserves funds and schedules the swap using quote_id. HTTP 202 does not confirm settlement.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/swaps", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "quote_id": "00000000-0000-4000-8000-000000000003"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "quote_id": "00000000-0000-4000-8000-000000000003"
}
GET /api/v1/crypto/swaps/{swapId} Credentials Scope: cashout Product: crypto

Get swap

Returns realized amounts, transaction hashes, and the reconciled swap status.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/swaps/REPLACE_WITH_SWAP_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/crypto/internal-transfers Credentials Scope: cashout Product: crypto

Transfer between users

Settles between two VexusPay users in the Vexus ledger. It does not create a blockchain transaction or TXID. Supply exactly one recipient: recipient_custody_subject is recommended for White Labels and must identify an existing ACTIVE subject in the same White Label, without automatic creation; recipient_external_user_id remains for compatibility only.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/internal-transfers", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "recipient_custody_subject": "usuario_00000002",
    "network": "TRON",
    "asset": "USDT_TRC20",
    "amount_units": "1000000"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "recipient_custody_subject": "usuario_00000002",
    "network": "TRON",
    "asset": "USDT_TRC20",
    "amount_units": "1000000"
}
GET /api/v1/crypto/conversions/capabilities Credentials Scope: cashin Product: crypto

Get conversion capabilities

Returns the available directions, assets, networks, and operational controls without creating an operation.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/capabilities", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/crypto/conversions/markets Credentials Scope: cashin Product: crypto

List conversion markets

Returns indicative partner prices; these are not executable quotes.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/markets", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/crypto/conversions Credentials Scope: cashin Product: crypto

List conversion addresses

Lists the partner’s external addresses owned by the account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/crypto/conversions/deposit-address Credentials Scope: cashin Product: crypto MAINTENANCE

Prepare address for crypto sale

Reserved for the crypto-to-BRL flow. New sales are under maintenance; do not use this route until capabilities reports that the direction is available.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/deposit-address", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "asset": "USDT",
    "network": "TRX"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "asset": "USDT",
    "network": "TRX"
}
GET /api/v1/crypto/conversion-operations Credentials Scope: cashout Product: crypto

List conversions

Lists conversion operations owned by the authenticated context, including historical states.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversion-operations", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/crypto/conversions/quote Credentials Scope: cashout Product: crypto

Quote BRL to crypto

Creates an executable FIAT_TO_CRYPTO quote only when capabilities enables the asset and network. An external destination is required. CRYPTO_TO_FIAT is under maintenance and is not accepted by this request version.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/quote", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "direction": "FIAT_TO_CRYPTO",
    "asset": "USDT",
    "network": "TRX",
    "brl_amount_minor": "10000",
    "destination_address": "REPLACE_WITH_TRC20_ADDRESS"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "direction": "FIAT_TO_CRYPTO",
    "asset": "USDT",
    "network": "TRX",
    "brl_amount_minor": "10000",
    "destination_address": "REPLACE_WITH_TRC20_ADDRESS"
}
POST /api/v1/crypto/conversions/{conversionId}/confirm Credentials Scope: cashout Product: crypto

Confirm conversion

Confirms a valid FIAT_TO_CRYPTO quote. HTTP 202 indicates admission only; follow the conversion until it reaches a terminal state.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/REPLACE_WITH_CONVERSION_ID/confirm", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
GET /api/v1/crypto/conversions/{conversionId} Credentials Scope: cashout Product: crypto

Get conversion

Returns the auditable status of the conversion.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/REPLACE_WITH_CONVERSION_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Module

Cards

Tokenized card payments and authorized virtual-card issuance, lookup, funding, transactions, and status controls.

GET /api/v1/cards/products Credentials Scope: cards.read Product: virtual.cards

List card types

Returns only the VexusPay card types currently enabled for issuance. The catalog is dynamic: do not cache availability as permanent authorization. Issuer-specific technical codes are not exposed.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/products", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/cards/rates Credentials Scope: cards.read Product: virtual.cards

Get card fees

Returns the account’s dynamic commercial fees for issuance, funding, and processing, with GLOBAL, PLAN, or USER origin. Query this endpoint before starting an operation. Issuer fees are confirmed only when issuance or funding is confirmed.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/rates", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/cards/capabilities Production only Credentials Scope: cards.read Product: virtual.cards PUBLISHED PRODUCTION ONLY

Get virtual card capabilities

Returns the actions currently available to the account and whether X-Vexus-External-User-Id is required. Query it immediately before showing or starting an action; do not promise issuance, funding, or control while the corresponding action is false.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/capabilities", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/cards Credentials Scope: cards.read Product: virtual.cards

List cards

When external_user_header_required=true, lists only cards owned by the supplied external user, with balance, status, brand, and last four digits. PAN, CVV, and OTP are never returned.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'X-Vexus-External-User-Id': 'witevexus:user:1001',
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/cards Credentials Scope: cards.write Product: virtual.cards

Create virtual card

Issues a card only when products and capabilities enable the action. Issuance requires Idempotency-Key. The prepaid USD card is funded from the issuer’s shared treasury supplied in USDT; it does not automatically debit or convert the end user’s Vexus Crypto wallet, and no atomic crypto-to-card operation exists. The White Label must reserve and debit its own user ledger separately. The current technical range is USD 10.00 to USD 1000000.00. When required, external_user_id in the body must match X-Vexus-External-User-Id. Do not retry an ambiguous response with a new key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cards", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'X-Vexus-External-User-Id': 'witevexus:user:1001',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "product_code": "vexus_international",
    "amount": "10.00",
    "name_on_card": "EXAMPLE CUSTOMER",
    "external_user_id": "witevexus:user:1001"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "product_code": "vexus_international",
    "amount": "10.00",
    "name_on_card": "EXAMPLE CUSTOMER",
    "external_user_id": "witevexus:user:1001"
}
GET /api/v1/cards/{cardId} Credentials Scope: cards.read Product: virtual.cards

Get card

Synchronizes the current card balance and status for the authenticated external user. PAN, CVV, and OTP are never returned.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'X-Vexus-External-User-Id': 'witevexus:user:1001',
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
DELETE /api/v1/cards/{cardId} Credentials Scope: cards.write Product: virtual.cards

Cancel card

Permanently cancels a card only while capabilities.actions.cancel=true. The action may return its balance according to card rules and requires Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID", {
  method: 'DELETE',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'X-Vexus-External-User-Id': 'witevexus:user:1001',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
POST /api/v1/cards/{cardId}/fund Credentials Scope: cards.write Product: virtual.cards

Fund card

Adds prepaid USD funds only while capabilities.actions.fund=true. Funding uses the issuer’s shared treasury supplied in USDT and does not automatically debit or convert the end user’s Vexus Crypto wallet. The White Label must reserve and debit its own ledger separately. Requires Idempotency-Key, currently accepts USD 10.00 to USD 1000000.00, and returns confirmed fees.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/fund", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'X-Vexus-External-User-Id': 'witevexus:user:1001',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "amount": "10.00"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "amount": "10.00"
}
POST /api/v1/cards/{cardId}/freeze Credentials Scope: cards.write Product: virtual.cards

Freeze card

Temporarily freezes an active card only while capabilities.actions.freeze=true. Requires Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/freeze", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'X-Vexus-External-User-Id': 'witevexus:user:1001',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
POST /api/v1/cards/{cardId}/unfreeze Credentials Scope: cards.write Product: virtual.cards

Unfreeze card

Reactivates a frozen card only while capabilities.actions.unfreeze=true. Requires Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/unfreeze", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'X-Vexus-External-User-Id': 'witevexus:user:1001',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
GET /api/v1/cards/{cardId}/transactions Credentials Scope: cards.read Product: virtual.cards

List card transactions

Returns a snapshot of transactions and balance for display and auxiliary reconciliation. The issuer contract does not define a stable identifier, pagination, webhook, or complete lifecycle correlation for authorization, capture, reversal, refund, and chargeback. Do not use this response as an accounting source. OTP codes, PAN, and CVV are never returned.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/transactions", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'X-Vexus-External-User-Id': 'witevexus:user:1001',
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/cards/{cardId}/display-sessions Credentials Scope: cards.write Product: virtual.cards

Create secure card display

Creates a single-use HTTPS URL, valid for 120 seconds, that displays PAN and CVV directly in the user’s browser. Open display_url directly in an iframe whose origin exactly matches allowed_origin; reload or reuse fails. Never proxy, fetch, capture, persist, or log the URL. When required, X-Vexus-External-User-Id identifies the owner and external_user_id in the body, if sent, must match. Recovery does not re-expose display_url; after expiration create a new session with a new Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/display-sessions", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'X-Vexus-External-User-Id': 'witevexus:user:1001',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "allowed_origin": "https://witevexus.fun",
    "external_user_id": "witevexus:user:1001"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "allowed_origin": "https://witevexus.fun",
    "external_user_id": "witevexus:user:1001"
}
GET /api/v1/cards/webhooks Credentials Scope: cards.read Product: virtual.cards

List OTP webhooks

Lists only this account’s endpoints subscribed to virtual_card.otp.received. The signing secret is never returned.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/cards/webhooks Credentials Scope: cards.write Product: virtual.cards

Configure OTP webhook

Creates an HTTPS endpoint for virtual_card.otp.received, the only public virtual-card event. signing_secret appears only in this response and must remain in the backend vault. Events use RFC 3339 UTC createdAt and HMAC over the raw body. Requires Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "label": "Production OTP",
    "url": "https://api.exemplo.com/webhooks/vexus"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "label": "Production OTP",
    "url": "https://api.exemplo.com/webhooks/vexus"
}
POST /api/v1/cards/webhooks/{webhookId}/rotate-secret Production only Credentials Scope: cards.write Product: virtual.cards PUBLISHED PRODUCTION ONLY

Rotate OTP webhook secret

Immediately revokes the previous secret with no overlap window and returns the new signing_secret once. Coordinate the receiver update. Send an empty JSON object and Idempotency-Key. Recovery never re-exposes the secret.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/rotate-secret", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
POST /api/v1/cards/webhooks/{webhookId}/activate Production only Credentials Scope: cards.write Product: virtual.cards PUBLISHED PRODUCTION ONLY

Activate OTP webhook

Resumes new virtual_card.otp.received deliveries to an endpoint owned by the account. Send an empty JSON object and Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/activate", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
POST /api/v1/cards/webhooks/{webhookId}/deactivate Production only Credentials Scope: cards.write Product: virtual.cards PUBLISHED PRODUCTION ONLY

Deactivate OTP webhook

Pauses new virtual_card.otp.received deliveries without deleting history. Send an empty JSON object and Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/deactivate", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
Module

Account

Authorized lookup of account balance, effective financial limits, fees, and idempotent operation recovery.

GET /api/v1/account/limits Credentials Scope: account.read Product: account

Get account limits

Returns the account’s effective BRL limits: aggregate, PIX cash-in and cash-out, boleto, and internal transfer. source indicates whether a rule comes from the GLOBAL policy or a USER override.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/limits", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/account/fees Credentials Scope: account.read Product: account

Get account fees

Returns effective commercial fees for PIX, boleto, cards, virtual cards, internal transfers, and crypto asset/network rules. For crypto, the operation quote is authoritative for network cost, service fee, net amount, and total debit.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/fees", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/account/operations/by-idempotency/{idempotencyKey} Production only Credentials Scope: account.read Product: DYNAMIC_FROM_ORIGINAL_OPERATION PUBLISHED PRODUCTION ONLY

Get operation by Idempotency-Key

Returns a sanitized state for the intent created by the same Production credential. Requires account.read and dynamically validates the original product and entitlements. After a timeout or OPERATION_STATUS_AMBIGUOUS, supply the original operation and context headers. In crypto, a recent PENDING intent is still in flight; after 60 seconds it is conservatively promoted to AMBIGUOUS with reconciliation_required=true. Stop polling this recovery route on ACCEPTED. wallet.create, withdrawal.quote, swap.quote, conversion.address, and conversion.quote finish their own intent with terminal=true; follow withdrawal.execute and swap.execute through the authoritative GET for resource_id. Persist conversionId before confirming a conversion because recovery may return ACCEPTED without resource_id; then query the original conversion. ACCEPTED never proves settlement or authorizes a new financial intent. Card display and webhook recovery never re-exposes display_url or signing_secret. An exact replay of the original POST retains its response semantics for 24 hours; an expired display requires a new session and key.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/operations/by-idempotency/REPLACE_WITH_IDEMPOTENCY_KEY", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'X-Vexus-External-User-Id': 'witevexus:user:1001',
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/account/ted Production only Credentials Scope: account.read Product: account PUBLISHED PRODUCTION ONLY

Get nominal TED account

Returns the agency, account, check digit, institution, and holder of the authenticated user’s nominal TED account without exposing provider credentials.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/ted", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/account/balance Production only Credentials Scope: account.read Product: account PUBLISHED PRODUCTION ONLY

Get nominal account balance

Returns the authenticated user’s isolated nominal account balance in BRL.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/balance", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/account/transactions Production only Credentials Scope: account.read Product: account PUBLISHED PRODUCTION ONLY

List nominal account transactions

Returns the nominal account statement for an interval of up to 31 days with pagination and holder isolation.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/transactions", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/nominal Production only Credentials Scope: account.read Product: account PUBLISHED PRODUCTION ONLY

Get nominal account

Returns the active nominal account and PIX key linked to the authenticated user. Provider credentials are never exposed.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/nominal/ted Production only Credentials Scope: account.read Product: account PUBLISHED PRODUCTION ONLY

Get nominal agency and account

Returns the agency, account, check digit, and institution of the nominal account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/ted", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/nominal/balance Production only Credentials Scope: account.read Product: account PUBLISHED PRODUCTION ONLY

Get nominal balance

Returns the authenticated user’s nominal account balance in BRL.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/balance", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/nominal/transactions Production only Credentials Scope: account.read Product: account PUBLISHED PRODUCTION ONLY

List nominal transactions

Returns deposits, outgoing transfers, and other nominal account entries for an interval of up to 31 days.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/transactions", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/nominal/pix-key Production only Credentials Scope: account.read Product: account PUBLISHED PRODUCTION ONLY

Get nominal PIX key

Returns the previously provisioned nominal PIX key.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/pix-key", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/nominal/operations/{operationId} Production only Credentials Scope: account.read Product: account PUBLISHED PRODUCTION ONLY

Get nominal operation

Returns the idempotent result of a nominal QR or outgoing PIX operation.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/operations/REPLACE_WITH_OPERATION_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/balance Credentials Scope: cashin Product: pix.cash_in

Get balance

Returns the balance exposed by the account contract. Send an empty JSON object.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/balance", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
Module

Conta nominal

POST /api/v1/nominal/pix-key Production only Credentials Scope: pix.cash_in Product: pix.cash_in PUBLISHED PRODUCTION ONLY

Create nominal PIX key

Requests a virtual account from the approved banking provider with a random, email, or CNPJ key. Requires Idempotency-Key and an administratively approved nominal request.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/pix-key", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/nominal/qr/dynamic Production only Credentials Scope: pix.cash_in Product: pix.cash_in PUBLISHED PRODUCTION ONLY

Create nominal dynamic QR

Creates a dynamic QR charge in the nominal account. Requires Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/dynamic", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/nominal/qr/static Production only Credentials Scope: pix.cash_in Product: pix.cash_in PUBLISHED PRODUCTION ONLY

Create nominal static QR

Creates a static QR in the nominal account. Requires Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/static", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/nominal/qr/decode Production only Credentials Scope: pix.qr_pay Product: pix.qr_pay PUBLISHED PRODUCTION ONLY

Decode nominal QR

Reads and validates a PIX QR through the approved banking provider without executing payment.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/decode", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/nominal/qr/pay Production only Credentials Scope: pix.qr_pay Product: pix.qr_pay PUBLISHED PRODUCTION ONLY

Pay nominal QR

Pays a PIX QR from the nominal account. Processing is asynchronous and requires Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/pay", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/nominal/pix-out Production only Credentials Scope: pix.cash_out Product: pix.cash_out PUBLISHED PRODUCTION ONLY

Send nominal PIX

Sends PIX from the nominal account. Confirmation arrives by webhook and the request requires Idempotency-Key.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/pix-out", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Module

White Label

The account’s White Label contract, including plan, add-ons, fees, billing, and access status.

GET /api/v1/white-label Credentials Scope: account.read Product: white_label

Get White Label contract

Returns contract status, plan, add-ons, billing, fees, and enabled products in one response. This read-only endpoint remains available when the monthly fee is overdue.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/white-label/plan Credentials Scope: account.read Product: white_label

Get White Label plan

Returns the plan and add-ons contracted by the authenticated account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/plan", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/white-label/fees Credentials Scope: account.read Product: white_label

Get White Label fees

Returns the plan’s commercial fees, including PIX, boleto, virtual card, and crypto asset/network rules.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/fees", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/white-label/billing Credentials Scope: account.read Product: white_label

Get White Label billing

Returns the monthly fee, setup fee, outstanding amount, due date, and access status. It does not create a charge or move funds.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/billing", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/white-label/status Credentials Scope: account.read Product: white_label

Get White Label status

Returns only the contract status and whether financial operations through the API are enabled.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/status", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/white-label/nominal Production only Credentials Scope: account.read Product: white_label

List nominal account requests

Lists only requests owned by the White Label account. Documents are masked and identity data comes from the central VexusPay profile.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/nominal", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/white-label/nominal Production only Credentials Scope: account.read Product: white_label

Request nominal account

Submits a request for administrative review. Name, CPF, and CNPJ are not accepted in the body; VexusPay uses only the account holder’s approved KYC.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/nominal", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "reason": "My brand’s operating account for PIX receipts."
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "reason": "My brand’s operating account for PIX receipts."
}
POST /api/v1/white-label/nominal/bind Production only Credentials Scope: account.read Product: white_label

Bind nominal customer

Links the White Label customer identifier to an active Vexus nominal account. The identifier is isolated by White Label.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/nominal/bind", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "nominal_user_id": 1001,
    "external_subject": "cliente:1001"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "nominal_user_id": 1001,
    "external_subject": "cliente:1001"
}
GET /api/v1/white-label/nominal/{requestId} Production only Credentials Scope: account.read Product: white_label

Get nominal account request

Returns a request owned by the White Label account without exposing a complete document or account credentials.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/nominal/REPLACE_WITH_REQUEST_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
DELETE /api/v1/white-label/nominal/{requestId} Production only Credentials Scope: account.read Product: white_label

Cancel nominal account request

Cancels a request that is still pending or approved. An account that has already been provisioned cannot be canceled through this route.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/nominal/REPLACE_WITH_REQUEST_ID", {
  method: 'DELETE',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Module

Support

Tickets and signed webhooks for any authenticated active account. Production only.

GET /api/v1/support/tickets Production only Credentials Scope: support.manage Product: support

List support tickets

Production only. Lists up to the 100 most recently updated tickets owned by the credential’s account. It never returns another account’s tickets or message contents.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/support/tickets Production only Credentials Scope: support.manage Product: support

Open support ticket

Production only. Opens a ticket for the authenticated account in the VexusPay support queue. Send text, up to four previously uploaded attachment_ids, or both. Never include HTML, bytes/base64, or credentials in the JSON body.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "category": "IMPLEMENTATION",
    "subject": "Question about the PIX integration",
    "message": "We need to validate how our integration handles the asynchronous response.",
    "attachment_ids": [
        "d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
    ]
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "category": "IMPLEMENTATION",
    "subject": "Question about the PIX integration",
    "message": "We need to validate how our integration handles the asynchronous response.",
    "attachment_ids": [
        "d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
    ]
}
GET /api/v1/support/tickets/{ticketId} Production only Credentials Scope: support.manage Product: support

Get support ticket

Production only. Returns the ticket and chronological conversation only when the ticket belongs to the credential’s account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/support/tickets/{ticketId}/messages Production only Credentials Scope: support.manage Product: support

Reply to support ticket

Production only. Adds text, up to four previously uploaded attachment_ids, or both to the account’s ticket. A reply returns the ticket to OPEN. CLOSED tickets reject new messages.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID/messages", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "message": "We applied the change and sent a new correlation ID for analysis.",
    "attachment_ids": [
        "d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
    ]
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "message": "We applied the change and sent a new correlation ID for analysis.",
    "attachment_ids": [
        "d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
    ]
}
POST /api/v1/support/tickets/{ticketId}/close Production only Credentials Scope: support.manage Product: support

Close support ticket

Production only. Confirms closure of the account’s ticket. Send an empty JSON object and preserve Idempotency-Key if the request must be retried.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID/close", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
POST /api/v1/support/attachments Production only Credentials Scope: support.manage Product: support

Upload support image

Production only. Accepts one image in the multipart file field, verifies its actual MIME type, normalizes the bitmap, and returns a pending attachment_id. JPEG, PNG, and WebP up to 5 MiB are accepted; an unlinked ID expires after 24 hours.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';
import { readFile } from 'node:fs/promises';

const idempotencyKey = crypto.randomUUID();

const image = await readFile('/path/to/evidence.png');
const form = new FormData();
form.append('file', new Blob([image], { type: 'image/png' }), 'evidencia.png');

const response = await fetch("https://api.nodexhub.com.br/api/v1/support/attachments", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
  },
  body: form,
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
GET /api/v1/support/attachments/{attachmentId} Production only Credentials Scope: support.manage Product: support

Download support image

Production only. Returns the private binary of an image owned by the account. Every download requires API credentials, uses Cache-Control: no-store, and must be proxied by the integration backend. Never expose the Client Secret to the browser.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/attachments/REPLACE_WITH_ATTACHMENT_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
const imageBytes = Buffer.from(await response.arrayBuffer());
console.log(response.headers.get('content-type'), imageBytes.length);
GET /api/v1/support/webhooks Production only Credentials Scope: support.manage Product: support

List support webhooks

Production only. Lists this account’s endpoints subscribed to support events. URLs are reduced to their HTTPS origin and signing secrets are never returned.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/support/webhooks Production only Credentials Scope: support.manage Product: support

Create support webhook

Production only. Creates an HTTPS endpoint for support events. signing_secret appears only in this response and must be stored immediately in a secure vault. If events is omitted, all five support events are subscribed.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "label": "Production support",
    "url": "https://api.exemplo.com/webhooks/vexus/support",
    "events": [
        "support.message.created",
        "support.ticket.status_changed",
        "support.ticket.closed"
    ]
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "label": "Production support",
    "url": "https://api.exemplo.com/webhooks/vexus/support",
    "events": [
        "support.message.created",
        "support.ticket.status_changed",
        "support.ticket.closed"
    ]
}
POST /api/v1/support/webhooks/{webhookId}/rotate-secret Production only Credentials Scope: support.manage Product: support

Rotate support webhook secret

Production only. Invalidates the previous secret and returns the new signing_secret once. Send an empty JSON object and update the receiver before relying on new deliveries.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/rotate-secret", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
POST /api/v1/support/webhooks/{webhookId}/activate Production only Credentials Scope: support.manage Product: support

Activate support webhook

Production only. Reactivates an endpoint owned by the account and clears its failure circuit. Send an empty JSON object.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/activate", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
POST /api/v1/support/webhooks/{webhookId}/deactivate Production only Credentials Scope: support.manage Product: support

Deactivate support webhook

Production only. Pauses new deliveries to the endpoint without deleting its history. Send an empty JSON object.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/deactivate", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
Module

Split

Split Payment rules, execution, lookup, cancellation, refunds, and reporting.

Split Payment API Flow VexusPay among recipients
GET /api/v1/splits/rules Credentials Scope: split Product: split

List split rules

Lists split rules owned by the authenticated account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/rules", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/splits/rules Credentials Scope: split Product: split

Create split rule

Creates a versioned split rule using percentages or fixed amounts.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/rules", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "name": "Partners",
    "mode": "PERCENTAGE",
    "currency": "BRL",
    "participants": [
        {
            "handle": "partner-account",
            "percentage": "20.00"
        }
    ]
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "name": "Partners",
    "mode": "PERCENTAGE",
    "currency": "BRL",
    "participants": [
        {
            "handle": "partner-account",
            "percentage": "20.00"
        }
    ]
}
PUT /api/v1/splits/rules/{ruleId} Credentials Scope: split Product: split

Revise split rule

Archives the previous rule version and creates a new version.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/rules/REPLACE_WITH_RULE_ID", {
  method: 'PUT',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "name": "Partners v2",
    "mode": "PERCENTAGE",
    "currency": "BRL",
    "participants": [
        {
            "handle": "partner-account",
            "percentage": "25.00"
        }
    ]
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "name": "Partners v2",
    "mode": "PERCENTAGE",
    "currency": "BRL",
    "participants": [
        {
            "handle": "partner-account",
            "percentage": "25.00"
        }
    ]
}
DELETE /api/v1/splits/rules/{ruleId} Credentials Scope: split Product: split

Archive split rule

Archives a rule owned by the account. This operation accepts no request body.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/rules/REPLACE_WITH_RULE_ID", {
  method: 'DELETE',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/splits Credentials Scope: split Product: split

Create split

Creates the financial operation and allocations from an active rule. The account must have an approved Split settlement route; rule management remains available without one.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/splits", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "rule_id": "00000000-0000-4000-8000-000000000001",
    "amount": 100,
    "payer": {
        "name": "Example Customer",
        "document": "52998224725",
        "email": "customer@example.com"
    }
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "rule_id": "00000000-0000-4000-8000-000000000001",
    "amount": 100,
    "payer": {
        "name": "Example Customer",
        "document": "52998224725",
        "email": "customer@example.com"
    }
}
GET /api/v1/splits/{splitId} Credentials Scope: split Product: split

Get split

Returns the operation and allocations visible to the owning account.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/splits/{splitId}/cancel Credentials Scope: split Product: split

Cancel split

Cancels a split only when its financial state allows it. Accepts no request body.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID/cancel", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/splits/{splitId}/refund Credentials Scope: split Product: split

Request split refund

Requests a partial or full refund. HTTP 202 indicates asynchronous processing, not completion.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID/refund", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "amount": 25,
    "comment": "Partial refund requested by the customer"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "amount": 25,
    "comment": "Partial refund requested by the customer"
}
GET /api/v1/splits/report Credentials Scope: split Product: split

Get participant report

Returns items owned by the authenticated account within the supplied UTC interval.

Integration examples
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/report", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Module

Sandbox Controls

Sandbox-only controls used to simulate states without moving real funds.

GET /api/v1/sandbox/workspace Credentials Scope: sandbox.manage

Get Sandbox workspace

Returns only the authenticated account’s simulated balances and resources.

Integration examples
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/workspace", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/sandbox/faucet Credentials Scope: sandbox.manage

Credit Sandbox faucet

Credits a simulated asset to the isolated Sandbox ledger.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/faucet", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "asset": "USDT_BEP20",
    "amount": "25.00"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "asset": "USDT_BEP20",
    "amount": "25.00"
}
POST /api/v1/sandbox/reset Credentials Scope: sandbox.manage

Reset Sandbox workspace

Deletes only this account’s Sandbox resources and recreates its initial simulated balance.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/reset", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "confirmation": "RESET_SANDBOX"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "confirmation": "RESET_SANDBOX"
}
POST /api/v1/sandbox/resources/{resourceType}/{resourceId}/actions Credentials Scope: sandbox.manage

Transition Sandbox resource

Approves, fails, expires, or reverses a pending simulated operation.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/resources/REPLACE_WITH_RESOURCE_TYPE/REPLACE_WITH_RESOURCE_ID/actions", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "action": "APPROVE"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "action": "APPROVE"
}
POST /api/v1/sandbox/crypto/deposits Credentials Scope: sandbox.manage

Simulate crypto deposit

Creates a simulated deposit without broadcasting or querying a blockchain. Use wallet_id returned when creating or listing a Sandbox wallet owned by the same account.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/crypto/deposits", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "wallet_id": "00000000-0000-4000-8000-000000000003",
    "amount": "10.00",
    "confirmations": 0
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "wallet_id": "00000000-0000-4000-8000-000000000003",
    "amount": "10.00",
    "confirmations": 0
}
POST /api/v1/sandbox/cards/{cardId}/transactions Credentials Scope: sandbox.manage

Simulate card transaction

Simulates approval, decline, reversal, or refund for a simulated card.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/cards/REPLACE_WITH_CARD_ID/transactions", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "amount": "12.50",
    "currency": "USD",
    "outcome": "APPROVED"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "amount": "12.50",
    "currency": "USD",
    "outcome": "APPROVED"
}
POST /api/v1/sandbox/cards/{cardId}/otp Credentials Scope: sandbox.manage

Generate digital-wallet OTP

Generates a simulated OTP and delivers it only through the Sandbox webhook pipeline.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/cards/REPLACE_WITH_CARD_ID/otp", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({
    "wallet_type": "GOOGLE_PAY"
}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{
    "wallet_type": "GOOGLE_PAY"
}
GET /api/v1/sandbox/webhook-deliveries Credentials Scope: sandbox.manage

List webhook deliveries

Lists webhook deliveries and attempts from the Sandbox environment.

Integration examples
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries", {
  method: 'GET',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
  },
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
POST /api/v1/sandbox/webhook-deliveries/{deliveryId}/retry Credentials Scope: sandbox.manage

Retry Sandbox webhook

Schedules a Sandbox delivery again without affecting production webhooks.

Exige Idempotency-Key.
Integration examples
import crypto from 'node:crypto';

const idempotencyKey = crypto.randomUUID();

const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries/REPLACE_WITH_DELIVERY_ID/retry", {
  method: 'POST',
  headers: {
    'Apikey': process.env.VEXUS_CLIENT_ID,
    'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
    'Idempotency-Key': idempotencyKey,
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({}),
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
Ver corpo de exemplo
{}
Transparency

Availability

PIX cash-in, cash-out, and QR Code PUBLISHED
Boleto issuance, lookup, and payment PUBLISHED
Vexus Crypto — catalog, wallets, and depositsNão existe webhook público de ciclo de vida cripto; consulte o recurso até estado terminal. PUBLISHED
Vexus Crypto — withdrawalsQuote, idempotent execution, and tracking to a terminal state. PUBLISHED
Vexus Crypto — swapsSame-chain BSC/TRON and cross-chain USDT only for published pairs. PUBLISHED
Vexus Crypto — internal transfersLedger-only settlement; no TXID is created. PUBLISHED
Crypto — BRL to cryptoRequires an external destination, enabled capability, and valid quote. Assets and networks come from the catalog and capabilities endpoints. == sync, corrected by elderman == @elder man
Crypto — crypto to BRLNew sales remain blocked until the complete receipt and settlement contract is published. Do not submit quotes or confirmations in this direction. MAINTENANCE
Public SandboxPublic DNS, TLS, and health checks validated. It does not use Production balances, credentials, providers, or webhooks. EVALUABLE
Split rules, creation, lookup, cancellation, refund, and report PUBLISHED
Operation recovery by Idempotency-KeyThe same credential looks up operation + Idempotency-Key after a timeout or ambiguous response without repeating the financial movement. PUBLISHED PRODUCTION ONLY
VexusPay CardsRequires product virtual.cards, cards.read/cards.write permissions, and entitlement virtual.card.api. PAN and CVV are not exposed. OTP is delivered only by the signed virtual_card.otp.received webhook. == sync, corrected by elderman == @elder man
Traditional card payment (card.pay)Standalone charge without a Checkout catalog item. Requires product card and accepts only a single-use token created by the configured SDK, never PAN or CVV. PUBLISHED PRODUCTION ONLY
Checkout management APIProducts, links, enabled methods, and reports require product checkout and scope checkout. PUBLISHED
White Label contract APILooks up plan, add-ons, fees, billing, and status. Read operations remain available while OVERDUE or SUSPENDED; operational APIs return WHITE_LABEL_OVERDUE or WHITE_LABEL_SUSPENDED. == sync, corrected by elderman == @elder man
Support tickets, image attachments, and webhooksAvailable to active accounts with product support and scope support.manage. Private images use separate multipart upload and authenticated download and are never embedded as bytes/base64 in webhooks. PUBLISHED PRODUCTION ONLY
Client webhooksPublished events: checkout.order.status_changed, financial.operation.status_changed, virtual_card.otp.received, and the five support.* events. PUBLISHED
Public MED/dispute APIDisputes are handled through the dashboard and support. No public route should be inferred. Not PUBLISHED