Simulated balance
Use GET /api/v1/sandbox/workspace, the faucet, and reset endpoint to organize deterministic tests.
Connect Pix, boleto, checkout, crypto, cards and Split Payment with stable contracts, security and visibility at each step.

https://api.nodexhub.com.br
https://sandbox-api.vexuspay.com.br to test the published contract without moving real funds. Production credentials never work in Sandbox, and Sandbox credentials never work in Production.Create a credential marked Sandbox under Settings → Credentials. Its identifier starts with vx_sbx_. The isolated workspace has simulated balances, resources, idempotency records, and webhook deliveries; it never calls a financial provider.
Use GET /api/v1/sandbox/workspace, the faucet, and reset endpoint to organize deterministic tests.
Create resources through their regular API routes, then use Sandbox Controls to approve, fail, expire, or reverse pending simulated operations.
Sandbox endpoints, delivery attempts, and signatures never share state with Production. OTP payloads remain encrypted and are redacted from audit output.
X-Vexus-Sandbox-Scenario with success, insufficient_balance, provider_timeout, rate_limited, declined, expired, or webhook_retry. Production rejects this header.Stable contracts, structured responses, and backend-ready examples.
Safe retries for financial operations without duplicate movements.
Authenticated delivery, stable event identifiers, and controlled retries.
Private routes require both credentials below. Send them only from your backend. Never expose the Client Secret in browser code, a mobile application, a URL, a support request, or application logs.
Apikey: YOUR_CLIENT_ID
X-Client-Secret: YOUR_CLIENT_SECRET
Content-Type: application/jsonSelect the correct environment and grant only the required scopes. The Client Secret is displayed once when created or rotated; store it immediately in a secrets vault.
Product access and credential scope are independent checks. HTTP 403 can mean either one is missing even when the credential is valid.
If an IP allowlist is enabled, register the public egress IP of your backend. Do not call private routes directly from a browser or mobile application.
Apikey and X-Client-Secret.Your backend creates an Idempotency-Key of 8–100 characters for each new mutable business intent. Keep the exact method, URL, body, file bytes, and key for retries. A different body with the same key returns a conflict; a new intent always requires a new key.
Use a random UUID before the first request.
Include it with the credentials and request payload.
Without a conclusive response, call GET /api/v1/account/operations/by-idempotency/{idempotencyKey}?operation=... with the same credential.
Create a new key only after the original intent is terminal or definitively failed.
JSON errors provide a stable code, human-readable message, details, correlationId, and retryable. Store the correlation ID, never credentials or sensitive bodies.
400/413/415/422 indicate invalid input. 401 means authentication failed; 403 means authorization failed. 404 also protects account isolation. For 409, inspect the existing resource or original intent.
Wait for Retry-After, then apply exponential backoff with jitter. A retry must preserve the original idempotency key and request body.
Do not assume success or failure after a timeout or 5xx. Look up the original Idempotency-Key before any new POST. If the state remains inconclusive, keep it under review and contact support with the correlationId.
201/202 can mean creation or admission, not PIX settlement or blockchain confirmation. Persist returned IDs and follow the resource by query and webhook until a terminal state.Use the same server-side credentials as the other modules. Always query networks, assets, swap pairs, and conversion capabilities before showing an action: the catalog is the source of truth for current availability.
Wallet creation is idempotent by account and network. For individual White Label custody, send X-Vexus-Custody-Subject with an immutable opaque user ID. For central custody, send only X-Vexus-Custody-Access: CENTRAL. These headers are mutually exclusive.
Use the wallet address, then follow confirmations and deposit status. HTTP 200 or CREDITED does not replace waiting for the documented terminal state.
Amounts ending in _units or _minor are integer strings in the smallest unit—never floating-point values. Quotes define fees, executable limits, and expiry.
Use a new idempotency key for confirmation, persist the returned ID, and follow it to a terminal state. In GROSS mode, fees are deducted from the authorized ceiling; in NET mode, fees may increase the total debit.
Any active Production account with product support and scope support.manage can embed VexusPay support in its own backend. The authenticated credential determines the account; no customer/account identifier is accepted in the body, and cross-account resources are never disclosed.
Create, list, read, reply to, and close tickets through the published routes. All writes require Idempotency-Key.
Upload JPEG, PNG, or WebP in the multipart file field. The maximum is 5 MiB per image and four attachments per message. Downloads always require API credentials and must be proxied by your backend.
Register an HTTPS endpoint for support events. The signing secret is returned once and must be stored in a secrets vault; it is never shown again.
Apikey, X-Client-Secret, signing secrets, or authenticated attachment URLs to browser code. Use your backend as the trusted boundary.Read and preserve the raw request body before parsing JSON. Compute HMAC-SHA256(timestamp + "." + rawBody, signing_secret), compare it in constant time with X-Vexus-Signature, reject stale timestamps, and deduplicate by event_id and X-Vexus-Delivery.
X-Vexus-Event: <event_name>
X-Vexus-Delivery: <uuid>
X-Vexus-Timestamp: <unix_timestamp>
X-Vexus-Signature: v1=<hmac_sha256>2xx quickly, and process it in an internal queue. Transport failures, 408, 409, 425, 429, and 5xx are retried. Duplicate events must never trigger a second financial operation.The following examples are derived from the same contract that generates the OpenAPI and the collection Postman.
Unauthenticated technical availability.
/health/live
Public
Checks whether the HTTP process is running.
const response = await fetch("https://api.nodexhub.com.br/health/live", {
method: 'GET',
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/health/live');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/health/live",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/health/ready
Public
Validates the database, migrations, and internal dependencies required to accept traffic.
const response = await fetch("https://api.nodexhub.com.br/health/ready", {
method: 'GET',
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/health/ready');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/health/ready",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
PIX cash-in, cash-out, QR Code decoding, and payment.

/api/v1/cashin
Credentials
Scope: cashin Product: pix.cash_in Creates a dynamic PIX charge.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cashin", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": 25.9
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cashin');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": 25.9
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": 25.9
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cashin",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": 25.9
}
/api/v1/cashout
Credentials
Scope: cashout Product: pix.cash_out Sends a PIX payment to the supplied key, subject to the account balance, enabled product, and limits.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cashout", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": 20,
"pix_key": "<destination-pix-key>",
"pix_key_type": "random",
"description": "Funds transfer"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cashout');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": 20,
"pix_key": "<destination-pix-key>",
"pix_key_type": "random",
"description": "Funds transfer"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": 20,
"pix_key": "<destination-pix-key>",
"pix_key_type": "random",
"description": "Funds transfer"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cashout",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": 20,
"pix_key": "<destination-pix-key>",
"pix_key_type": "random",
"description": "Funds transfer"
}
/api/v1/pix/qr/decode
Credentials
Scope: cashout Product: pix.cash_out Validates the CRC and decodes a static or dynamic PIX EMV payload without moving funds. The response indicates whether the amount is fixed by the QR Code.
const response = await fetch("https://api.nodexhub.com.br/api/v1/pix/qr/decode", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/pix/qr/decode');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/pix/qr/decode",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE"
}
/api/v1/pix/qr/pay
Credentials
Scope: cashout Product: pix.cash_out Pays a PIX QR Code after validating its CRC, declared amount, balance, and limits. An amount embedded in the QR Code always takes precedence over an amount sent by the integrator.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/pix/qr/pay", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE",
"description": "Supplier"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/pix/qr/pay');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE",
"description": "Supplier"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE",
"description": "Supplier"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/pix/qr/pay",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE",
"description": "Supplier"
}
Boleto issuance, lookup, and payment.

/api/v1/boleto/issue
Credentials
Scope: boleto Product: boleto Issues a standalone boleto charge without requiring a Checkout catalog item. The boleto API product must be enabled. Name, CPF/CNPJ, and email come from the account profile; an address is not required.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/boleto/issue", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": 99.9,
"due_date": "2026-09-30",
"description": "Boleto payment request"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/boleto/issue');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": 99.9,
"due_date": "2026-09-30",
"description": "Boleto payment request"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": 99.9,
"due_date": "2026-09-30",
"description": "Boleto payment request"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/boleto/issue",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": 99.9,
"due_date": "2026-09-30",
"description": "Boleto payment request"
}
/api/v1/boleto/info
Credentials
Scope: boleto Product: boleto Queries the provider for the current amount and beneficiary details without moving funds.
const response = await fetch("https://api.nodexhub.com.br/api/v1/boleto/info", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"billetCode": "00190000000000014990000000000000000000000000"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/boleto/info');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"billetCode": "00190000000000014990000000000000000000000000"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"billetCode": "00190000000000014990000000000000000000000000"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/boleto/info",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"billetCode": "00190000000000014990000000000000000000000000"
}
/api/v1/boleto/pay
Credentials
Scope: boleto Product: boleto Rechecks the current amount and beneficiary with the provider, then validates the balance and limits before payment. The integrator sends only the boleto code.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/boleto/pay", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"billetCode": "00190000000000014990000000000000000000000000"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/boleto/pay');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"billetCode": "00190000000000014990000000000000000000000000"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"billetCode": "00190000000000014990000000000000000000000000"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/boleto/pay",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"billetCode": "00190000000000014990000000000000000000000000"
}
Catalog, payment links, enabled methods, and Checkout reporting.

/api/v1/card/config
Production only Credentials
Scope: cards.write Product: card PUBLISHED PRODUCTION ONLY Returns the authorized public key and SDK URL used to tokenize a card in the browser. Never send PAN or CVV to the VexusPay backend.
const response = await fetch("https://api.nodexhub.com.br/api/v1/card/config", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/card/config');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/card/config",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/card/pay
Production only Credentials
Scope: cards.write Product: card PUBLISHED PRODUCTION ONLY Processes a standalone charge without requiring a Checkout catalog item. The card API product must be enabled. Use a card token created once by the SDK returned by the configuration endpoint; PAN and CVV are not accepted.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/card/pay", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": 99.9,
"external_id": "example-order-123",
"buyer_name": "Example Customer",
"buyer_email": "customer@example.com",
"buyer_cpf": "52998224725",
"card_token": "REPLACE_WITH_SINGLE_USE_TOKEN",
"payment_method_id": "visa",
"installments": 1,
"description": "Example order 123"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/card/pay');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": 99.9,
"external_id": "example-order-123",
"buyer_name": "Example Customer",
"buyer_email": "customer@example.com",
"buyer_cpf": "52998224725",
"card_token": "REPLACE_WITH_SINGLE_USE_TOKEN",
"payment_method_id": "visa",
"installments": 1,
"description": "Example order 123"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": 99.9,
"external_id": "example-order-123",
"buyer_name": "Example Customer",
"buyer_email": "customer@example.com",
"buyer_cpf": "52998224725",
"card_token": "REPLACE_WITH_SINGLE_USE_TOKEN",
"payment_method_id": "visa",
"installments": 1,
"description": "Example order 123"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/card/pay",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": 99.9,
"external_id": "example-order-123",
"buyer_name": "Example Customer",
"buyer_email": "customer@example.com",
"buyer_cpf": "52998224725",
"card_token": "REPLACE_WITH_SINGLE_USE_TOKEN",
"payment_method_id": "visa",
"installments": 1,
"description": "Example order 123"
}
/api/v1/checkout/methods
Credentials
Scope: checkout Product: checkout Returns only approved payment methods currently available to the authenticated account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/methods", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/methods');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/checkout/methods",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/report
Credentials
Scope: checkout Product: checkout Returns aggregate metrics for payment links and orders owned by the authenticated account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/report", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/report');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/checkout/report",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/products
Credentials
Scope: checkout Product: checkout Lists active and archived products in the account’s catalog.
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/products", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/products');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/checkout/products",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/products
Credentials
Scope: checkout Product: checkout Creates a catalog product. A payment method that requires an external product identifier may be enabled only when provider_product_id is supplied.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/products", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"name": "Monthly plan",
"price": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/products');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"name": "Monthly plan",
"price": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"name": "Monthly plan",
"price": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/checkout/products",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"name": "Monthly plan",
"price": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
/api/v1/checkout/products/{productId}
Credentials
Scope: checkout Product: checkout Returns a catalog product owned by the authenticated account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/products/{productId}
Credentials
Scope: checkout Product: checkout Updates a product version. Send the version returned by the read endpoint to prevent concurrent overwrites.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID", {
method: 'PUT',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"name": "Updated monthly plan",
"price": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'PUT',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"name": "Updated monthly plan",
"price": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"name": "Updated monthly plan",
"price": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
''')
response = requests.request(
'PUT',
"https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"name": "Updated monthly plan",
"price": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
/api/v1/checkout/products/{productId}
Credentials
Scope: checkout Product: checkout Archives the product and its active links. Requires Idempotency-Key and accepts no request body.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID", {
method: 'DELETE',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'DELETE',
"https://api.nodexhub.com.br/api/v1/checkout/products/REPLACE_WITH_PRODUCT_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/links
Credentials
Scope: checkout Product: checkout Lists payment links, statuses, and metrics for the authenticated account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/links');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/checkout/links",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/links
Credentials
Scope: checkout Product: checkout Creates a standalone link or a link associated with a product. Combine the returned payment_path with the account’s VexusPay domain.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"title": "Service payment",
"amount": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/links');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"title": "Service payment",
"amount": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"title": "Service payment",
"amount": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/checkout/links",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"title": "Service payment",
"amount": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
/api/v1/checkout/links/{linkId}
Credentials
Scope: checkout Product: checkout Returns the configuration and payment_path of a link owned by the authenticated account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/links/{linkId}
Credentials
Scope: checkout Product: checkout Updates a link version. Send the version returned by the read endpoint to prevent concurrent overwrites.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID", {
method: 'PUT',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"title": "Updated service payment",
"amount": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'PUT',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"title": "Updated service payment",
"amount": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"title": "Updated service payment",
"amount": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
''')
response = requests.request(
'PUT',
"https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"title": "Updated service payment",
"amount": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
/api/v1/checkout/links/{linkId}/archive
Credentials
Scope: checkout Product: checkout Archives the link and prevents new payments. Requires Idempotency-Key and accepts no request body.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID/archive", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID/archive');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID/archive",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/links/{linkId}/cancel
Credentials
Scope: checkout Product: checkout Cancels the link with an auditable reason and prevents new payments. Requires Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID/cancel", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"reason": "Cancellation requested by the customer"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID/cancel');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"reason": "Cancellation requested by the customer"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"reason": "Cancellation requested by the customer"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/checkout/links/REPLACE_WITH_LINK_ID/cancel",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"reason": "Cancellation requested by the customer"
}
Catalog, wallets, balances, deposits, withdrawals, swaps, internal transfers, and conversions according to current capabilities.
/api/v1/crypto/networks
Credentials
Scope: cashin Product: crypto Lists BSC and TRON together with maintenance status and deposit, withdrawal, and swap capabilities.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/networks", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/networks');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/networks",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/assets
Credentials
Scope: cashin Product: crypto Lists assets by network, their decimal precision, and the capabilities currently enabled.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/assets", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/assets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/assets",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/swap-pairs
Credentials
Scope: cashin Product: crypto Lists available same-chain pairs and the USDT TRC-20 ↔ USDT BEP-20 cross-chain pair.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/swap-pairs", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/swap-pairs');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/swap-pairs",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/wallets
Credentials
Scope: cashin Product: crypto Lists only wallets owned by the account or by the authenticated custody context.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/wallets", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/wallets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/wallets",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/wallets
Credentials
Scope: cashin Product: crypto Idempotently creates or reuses the account’s BSC or TRON HD wallet. Tokens on the same network share the same address.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/wallets", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"network": "BSC"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/wallets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"network": "BSC"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"network": "BSC"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/crypto/wallets",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"network": "BSC"
}
/api/v1/crypto/wallets/{walletId}
Credentials
Scope: cashin Product: crypto Returns a Vexus wallet owned by the authenticated account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/wallets/{walletId}/balances
Credentials
Scope: cashin Product: crypto Returns ledger, available, reserved, pending, and on-chain balances as integer strings in the asset’s smallest unit.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID/balances", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID/balances');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID/balances",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/wallets/{walletId}/transactions
Credentials
Scope: cashin Product: crypto Lists recent deposits and withdrawals for the wallet.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID/transactions", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID/transactions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/wallets/REPLACE_WITH_WALLET_ID/transactions",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/deposits
Credentials
Scope: cashin Product: crypto Lists only deposits linked to wallets owned by the account or authenticated custody context.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/deposits", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/deposits');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/deposits",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/deposits/{depositId}
Credentials
Scope: cashin Product: crypto Returns the deposit status and confirmation count. CREDITED or HTTP 200 does not replace checking for a terminal state.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/deposits/REPLACE_WITH_DEPOSIT_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/deposits/REPLACE_WITH_DEPOSIT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/deposits/REPLACE_WITH_DEPOSIT_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/withdrawals/quote
Credentials
Scope: cashout Product: crypto Creates an authoritative quote containing fees, net amount, total debit, and validity in *_units. In GROSS mode, the entered amount is the authorized ceiling and fees are deducted from it. This call does not move funds.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/withdrawals/quote", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"network": "BSC",
"asset": "USDT_BSC",
"destination_address": "REPLACE_WITH_BSC_ADDRESS",
"amount_units": "1000000",
"amount_mode": "GROSS"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/withdrawals/quote');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"network": "BSC",
"asset": "USDT_BSC",
"destination_address": "REPLACE_WITH_BSC_ADDRESS",
"amount_units": "1000000",
"amount_mode": "GROSS"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"network": "BSC",
"asset": "USDT_BSC",
"destination_address": "REPLACE_WITH_BSC_ADDRESS",
"amount_units": "1000000",
"amount_mode": "GROSS"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/crypto/withdrawals/quote",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"network": "BSC",
"asset": "USDT_BSC",
"destination_address": "REPLACE_WITH_BSC_ADDRESS",
"amount_units": "1000000",
"amount_mode": "GROSS"
}
/api/v1/crypto/withdrawals
Credentials
Scope: cashout Product: crypto Reserves funds and schedules the withdrawal using quote_id. HTTP 202 does not confirm a blockchain transaction; follow the resource until it reaches a terminal state.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/withdrawals", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"quote_id": "00000000-0000-4000-8000-000000000002"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/withdrawals');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"quote_id": "00000000-0000-4000-8000-000000000002"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"quote_id": "00000000-0000-4000-8000-000000000002"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/crypto/withdrawals",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"quote_id": "00000000-0000-4000-8000-000000000002"
}
/api/v1/crypto/withdrawals/{withdrawalId}
Credentials
Scope: cashout Product: crypto Returns the status, TXID, and actual network cost when available.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/withdrawals/REPLACE_WITH_WITHDRAWAL_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/withdrawals/REPLACE_WITH_WITHDRAWAL_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/withdrawals/REPLACE_WITH_WITHDRAWAL_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/swaps/quote
Credentials
Scope: cashout Product: crypto Creates an authoritative same-chain or USDT cross-chain quote using only published pairs.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/swaps/quote", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"asset_in": "USDT_TRC20",
"asset_out": "USDT_BSC",
"amount_in_units": "1000000",
"slippage_bps": 50
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/swaps/quote');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"asset_in": "USDT_TRC20",
"asset_out": "USDT_BSC",
"amount_in_units": "1000000",
"slippage_bps": 50
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"asset_in": "USDT_TRC20",
"asset_out": "USDT_BSC",
"amount_in_units": "1000000",
"slippage_bps": 50
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/crypto/swaps/quote",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"asset_in": "USDT_TRC20",
"asset_out": "USDT_BSC",
"amount_in_units": "1000000",
"slippage_bps": 50
}
/api/v1/crypto/swaps
Credentials
Scope: cashout Product: crypto Reserves funds and schedules the swap using quote_id. HTTP 202 does not confirm settlement.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/swaps", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"quote_id": "00000000-0000-4000-8000-000000000003"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/swaps');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"quote_id": "00000000-0000-4000-8000-000000000003"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"quote_id": "00000000-0000-4000-8000-000000000003"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/crypto/swaps",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"quote_id": "00000000-0000-4000-8000-000000000003"
}
/api/v1/crypto/swaps/{swapId}
Credentials
Scope: cashout Product: crypto Returns realized amounts, transaction hashes, and the reconciled swap status.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/swaps/REPLACE_WITH_SWAP_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/swaps/REPLACE_WITH_SWAP_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/swaps/REPLACE_WITH_SWAP_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/internal-transfers
Credentials
Scope: cashout Product: crypto Settles between two VexusPay users in the Vexus ledger. It does not create a blockchain transaction or TXID. Supply exactly one recipient: recipient_custody_subject is recommended for White Labels and must identify an existing ACTIVE subject in the same White Label, without automatic creation; recipient_external_user_id remains for compatibility only.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/internal-transfers", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"recipient_custody_subject": "usuario_00000002",
"network": "TRON",
"asset": "USDT_TRC20",
"amount_units": "1000000"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/internal-transfers');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"recipient_custody_subject": "usuario_00000002",
"network": "TRON",
"asset": "USDT_TRC20",
"amount_units": "1000000"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"recipient_custody_subject": "usuario_00000002",
"network": "TRON",
"asset": "USDT_TRC20",
"amount_units": "1000000"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/crypto/internal-transfers",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"recipient_custody_subject": "usuario_00000002",
"network": "TRON",
"asset": "USDT_TRC20",
"amount_units": "1000000"
}
/api/v1/crypto/conversions/capabilities
Credentials
Scope: cashin Product: crypto Returns the available directions, assets, networks, and operational controls without creating an operation.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/capabilities", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/conversions/capabilities');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/conversions/capabilities",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/conversions/markets
Credentials
Scope: cashin Product: crypto Returns indicative partner prices; these are not executable quotes.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/markets", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/conversions/markets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/conversions/markets",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/conversions
Credentials
Scope: cashin Product: crypto Lists the partner’s external addresses owned by the account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/conversions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/conversions",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/conversions/deposit-address
Credentials
Scope: cashin Product: crypto MAINTENANCE Reserved for the crypto-to-BRL flow. New sales are under maintenance; do not use this route until capabilities reports that the direction is available.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/deposit-address", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"asset": "USDT",
"network": "TRX"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/conversions/deposit-address');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"asset": "USDT",
"network": "TRX"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"asset": "USDT",
"network": "TRX"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/crypto/conversions/deposit-address",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"asset": "USDT",
"network": "TRX"
}
/api/v1/crypto/conversion-operations
Credentials
Scope: cashout Product: crypto Lists conversion operations owned by the authenticated context, including historical states.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversion-operations", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/conversion-operations');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/conversion-operations",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/conversions/quote
Credentials
Scope: cashout Product: crypto Creates an executable FIAT_TO_CRYPTO quote only when capabilities enables the asset and network. An external destination is required. CRYPTO_TO_FIAT is under maintenance and is not accepted by this request version.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/quote", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"direction": "FIAT_TO_CRYPTO",
"asset": "USDT",
"network": "TRX",
"brl_amount_minor": "10000",
"destination_address": "REPLACE_WITH_TRC20_ADDRESS"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/conversions/quote');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"direction": "FIAT_TO_CRYPTO",
"asset": "USDT",
"network": "TRX",
"brl_amount_minor": "10000",
"destination_address": "REPLACE_WITH_TRC20_ADDRESS"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"direction": "FIAT_TO_CRYPTO",
"asset": "USDT",
"network": "TRX",
"brl_amount_minor": "10000",
"destination_address": "REPLACE_WITH_TRC20_ADDRESS"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/crypto/conversions/quote",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"direction": "FIAT_TO_CRYPTO",
"asset": "USDT",
"network": "TRX",
"brl_amount_minor": "10000",
"destination_address": "REPLACE_WITH_TRC20_ADDRESS"
}
/api/v1/crypto/conversions/{conversionId}/confirm
Credentials
Scope: cashout Product: crypto Confirms a valid FIAT_TO_CRYPTO quote. HTTP 202 indicates admission only; follow the conversion until it reaches a terminal state.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/REPLACE_WITH_CONVERSION_ID/confirm", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/conversions/REPLACE_WITH_CONVERSION_ID/confirm');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/crypto/conversions/REPLACE_WITH_CONVERSION_ID/confirm",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/crypto/conversions/{conversionId}
Credentials
Scope: cashout Product: crypto Returns the auditable status of the conversion.
const response = await fetch("https://api.nodexhub.com.br/api/v1/crypto/conversions/REPLACE_WITH_CONVERSION_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/crypto/conversions/REPLACE_WITH_CONVERSION_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/crypto/conversions/REPLACE_WITH_CONVERSION_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
Tokenized card payments and authorized virtual-card issuance, lookup, funding, transactions, and status controls.
/api/v1/cards/products
Credentials
Scope: cards.read Product: virtual.cards Returns only the VexusPay card types currently enabled for issuance. The catalog is dynamic: do not cache availability as permanent authorization. Issuer-specific technical codes are not exposed.
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/products", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/products');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/cards/products",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards/rates
Credentials
Scope: cards.read Product: virtual.cards Returns the account’s dynamic commercial fees for issuance, funding, and processing, with GLOBAL, PLAN, or USER origin. Query this endpoint before starting an operation. Issuer fees are confirmed only when issuance or funding is confirmed.
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/rates", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/rates');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/cards/rates",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards/capabilities
Production only Credentials
Scope: cards.read Product: virtual.cards PUBLISHED PRODUCTION ONLY Returns the actions currently available to the account and whether X-Vexus-External-User-Id is required. Query it immediately before showing or starting an action; do not promise issuance, funding, or control while the corresponding action is false.
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/capabilities", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/capabilities');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/cards/capabilities",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards
Credentials
Scope: cards.read Product: virtual.cards When external_user_header_required=true, lists only cards owned by the supplied external user, with balance, status, brand, and last four digits. PAN, CVV, and OTP are never returned.
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'X-Vexus-External-User-Id: witevexus:user:1001',
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'X-Vexus-External-User-Id': 'witevexus:user:1001',
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/cards",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards
Credentials
Scope: cards.write Product: virtual.cards Issues a card only when products and capabilities enable the action. Issuance requires Idempotency-Key. The prepaid USD card is funded from the issuer’s shared treasury supplied in USDT; it does not automatically debit or convert the end user’s Vexus Crypto wallet, and no atomic crypto-to-card operation exists. The White Label must reserve and debit its own user ledger separately. The current technical range is USD 10.00 to USD 1000000.00. When required, external_user_id in the body must match X-Vexus-External-User-Id. Do not retry an ambiguous response with a new key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"product_code": "vexus_international",
"amount": "10.00",
"name_on_card": "EXAMPLE CUSTOMER",
"external_user_id": "witevexus:user:1001"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"product_code": "vexus_international",
"amount": "10.00",
"name_on_card": "EXAMPLE CUSTOMER",
"external_user_id": "witevexus:user:1001"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"product_code": "vexus_international",
"amount": "10.00",
"name_on_card": "EXAMPLE CUSTOMER",
"external_user_id": "witevexus:user:1001"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"product_code": "vexus_international",
"amount": "10.00",
"name_on_card": "EXAMPLE CUSTOMER",
"external_user_id": "witevexus:user:1001"
}
/api/v1/cards/{cardId}
Credentials
Scope: cards.read Product: virtual.cards Synchronizes the current card balance and status for the authenticated external user. PAN, CVV, and OTP are never returned.
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'X-Vexus-External-User-Id: witevexus:user:1001',
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'X-Vexus-External-User-Id': 'witevexus:user:1001',
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards/{cardId}
Credentials
Scope: cards.write Product: virtual.cards Permanently cancels a card only while capabilities.actions.cancel=true. The action may return its balance according to card rules and requires Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID", {
method: 'DELETE',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'DELETE',
"https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/cards/{cardId}/fund
Credentials
Scope: cards.write Product: virtual.cards Adds prepaid USD funds only while capabilities.actions.fund=true. Funding uses the issuer’s shared treasury supplied in USDT and does not automatically debit or convert the end user’s Vexus Crypto wallet. The White Label must reserve and debit its own ledger separately. Requires Idempotency-Key, currently accepts USD 10.00 to USD 1000000.00, and returns confirmed fees.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/fund", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": "10.00"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/fund');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": "10.00"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": "10.00"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/fund",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": "10.00"
}
/api/v1/cards/{cardId}/freeze
Credentials
Scope: cards.write Product: virtual.cards Temporarily freezes an active card only while capabilities.actions.freeze=true. Requires Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/freeze", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/freeze');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/freeze",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/cards/{cardId}/unfreeze
Credentials
Scope: cards.write Product: virtual.cards Reactivates a frozen card only while capabilities.actions.unfreeze=true. Requires Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/unfreeze", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/unfreeze');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/unfreeze",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/cards/{cardId}/transactions
Credentials
Scope: cards.read Product: virtual.cards Returns a snapshot of transactions and balance for display and auxiliary reconciliation. The issuer contract does not define a stable identifier, pagination, webhook, or complete lifecycle correlation for authorization, capture, reversal, refund, and chargeback. Do not use this response as an accounting source. OTP codes, PAN, and CVV are never returned.
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/transactions", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/transactions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'X-Vexus-External-User-Id: witevexus:user:1001',
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'X-Vexus-External-User-Id': 'witevexus:user:1001',
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/transactions",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards/{cardId}/display-sessions
Credentials
Scope: cards.write Product: virtual.cards Creates a single-use HTTPS URL, valid for 120 seconds, that displays PAN and CVV directly in the user’s browser. Open display_url directly in an iframe whose origin exactly matches allowed_origin; reload or reuse fails. Never proxy, fetch, capture, persist, or log the URL. When required, X-Vexus-External-User-Id identifies the owner and external_user_id in the body, if sent, must match. Recovery does not re-expose display_url; after expiration create a new session with a new Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/display-sessions", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"allowed_origin": "https://witevexus.fun",
"external_user_id": "witevexus:user:1001"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/display-sessions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"allowed_origin": "https://witevexus.fun",
"external_user_id": "witevexus:user:1001"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"allowed_origin": "https://witevexus.fun",
"external_user_id": "witevexus:user:1001"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/REPLACE_WITH_CARD_ID/display-sessions",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"allowed_origin": "https://witevexus.fun",
"external_user_id": "witevexus:user:1001"
}
/api/v1/cards/webhooks
Credentials
Scope: cards.read Product: virtual.cards Lists only this account’s endpoints subscribed to virtual_card.otp.received. The signing secret is never returned.
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/webhooks');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/cards/webhooks",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards/webhooks
Credentials
Scope: cards.write Product: virtual.cards Creates an HTTPS endpoint for virtual_card.otp.received, the only public virtual-card event. signing_secret appears only in this response and must remain in the backend vault. Events use RFC 3339 UTC createdAt and HMAC over the raw body. Requires Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"label": "Production OTP",
"url": "https://api.exemplo.com/webhooks/vexus"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/webhooks');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"label": "Production OTP",
"url": "https://api.exemplo.com/webhooks/vexus"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"label": "Production OTP",
"url": "https://api.exemplo.com/webhooks/vexus"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/webhooks",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"label": "Production OTP",
"url": "https://api.exemplo.com/webhooks/vexus"
}
/api/v1/cards/webhooks/{webhookId}/rotate-secret
Production only Credentials
Scope: cards.write Product: virtual.cards PUBLISHED PRODUCTION ONLY Immediately revokes the previous secret with no overlap window and returns the new signing_secret once. Coordinate the receiver update. Send an empty JSON object and Idempotency-Key. Recovery never re-exposes the secret.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/rotate-secret", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/rotate-secret');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/rotate-secret",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/cards/webhooks/{webhookId}/activate
Production only Credentials
Scope: cards.write Product: virtual.cards PUBLISHED PRODUCTION ONLY Resumes new virtual_card.otp.received deliveries to an endpoint owned by the account. Send an empty JSON object and Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/activate", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/activate');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/activate",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/cards/webhooks/{webhookId}/deactivate
Production only Credentials
Scope: cards.write Product: virtual.cards PUBLISHED PRODUCTION ONLY Pauses new virtual_card.otp.received deliveries without deleting history. Send an empty JSON object and Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/deactivate", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/deactivate');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/webhooks/REPLACE_WITH_WEBHOOK_ID/deactivate",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
Authorized lookup of account balance, effective financial limits, fees, and idempotent operation recovery.
/api/v1/account/limits
Credentials
Scope: account.read Product: account Returns the account’s effective BRL limits: aggregate, PIX cash-in and cash-out, boleto, and internal transfer. source indicates whether a rule comes from the GLOBAL policy or a USER override.
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/limits", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/account/limits');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/account/limits",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/account/fees
Credentials
Scope: account.read Product: account Returns effective commercial fees for PIX, boleto, cards, virtual cards, internal transfers, and crypto asset/network rules. For crypto, the operation quote is authoritative for network cost, service fee, net amount, and total debit.
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/fees", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/account/fees');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/account/fees",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/account/operations/by-idempotency/{idempotencyKey}
Production only Credentials
Scope: account.read Product: DYNAMIC_FROM_ORIGINAL_OPERATION PUBLISHED PRODUCTION ONLY Returns a sanitized state for the intent created by the same Production credential. Requires account.read and dynamically validates the original product and entitlements. After a timeout or OPERATION_STATUS_AMBIGUOUS, supply the original operation and context headers. In crypto, a recent PENDING intent is still in flight; after 60 seconds it is conservatively promoted to AMBIGUOUS with reconciliation_required=true. Stop polling this recovery route on ACCEPTED. wallet.create, withdrawal.quote, swap.quote, conversion.address, and conversion.quote finish their own intent with terminal=true; follow withdrawal.execute and swap.execute through the authoritative GET for resource_id. Persist conversionId before confirming a conversion because recovery may return ACCEPTED without resource_id; then query the original conversion. ACCEPTED never proves settlement or authorizes a new financial intent. Card display and webhook recovery never re-exposes display_url or signing_secret. An exact replay of the original POST retains its response semantics for 24 hours; an expired display requires a new session and key.
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/operations/by-idempotency/REPLACE_WITH_IDEMPOTENCY_KEY", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/account/operations/by-idempotency/REPLACE_WITH_IDEMPOTENCY_KEY');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'X-Vexus-External-User-Id: witevexus:user:1001',
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'X-Vexus-External-User-Id': 'witevexus:user:1001',
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/account/operations/by-idempotency/REPLACE_WITH_IDEMPOTENCY_KEY",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/account/ted
Production only Credentials
Scope: account.read Product: account PUBLISHED PRODUCTION ONLY Returns the agency, account, check digit, institution, and holder of the authenticated user’s nominal TED account without exposing provider credentials.
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/ted", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/account/ted');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/account/ted",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/account/balance
Production only Credentials
Scope: account.read Product: account PUBLISHED PRODUCTION ONLY Returns the authenticated user’s isolated nominal account balance in BRL.
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/balance", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/account/balance');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/account/balance",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/account/transactions
Production only Credentials
Scope: account.read Product: account PUBLISHED PRODUCTION ONLY Returns the nominal account statement for an interval of up to 31 days with pagination and holder isolation.
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/transactions", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/account/transactions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/account/transactions",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal
Production only Credentials
Scope: account.read Product: account PUBLISHED PRODUCTION ONLY Returns the active nominal account and PIX key linked to the authenticated user. Provider credentials are never exposed.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/ted
Production only Credentials
Scope: account.read Product: account PUBLISHED PRODUCTION ONLY Returns the agency, account, check digit, and institution of the nominal account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/ted", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/ted');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal/ted",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/balance
Production only Credentials
Scope: account.read Product: account PUBLISHED PRODUCTION ONLY Returns the authenticated user’s nominal account balance in BRL.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/balance", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/balance');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal/balance",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/transactions
Production only Credentials
Scope: account.read Product: account PUBLISHED PRODUCTION ONLY Returns deposits, outgoing transfers, and other nominal account entries for an interval of up to 31 days.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/transactions", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/transactions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal/transactions",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/pix-key
Production only Credentials
Scope: account.read Product: account PUBLISHED PRODUCTION ONLY Returns the previously provisioned nominal PIX key.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/pix-key", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/pix-key');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal/pix-key",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/operations/{operationId}
Production only Credentials
Scope: account.read Product: account PUBLISHED PRODUCTION ONLY Returns the idempotent result of a nominal QR or outgoing PIX operation.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/operations/REPLACE_WITH_OPERATION_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/operations/REPLACE_WITH_OPERATION_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal/operations/REPLACE_WITH_OPERATION_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/balance
Credentials
Scope: cashin Product: pix.cash_in Returns the balance exposed by the account contract. Send an empty JSON object.
const response = await fetch("https://api.nodexhub.com.br/api/v1/balance", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/balance');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/balance",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/nominal/pix-key
Production only Credentials
Scope: pix.cash_in Product: pix.cash_in PUBLISHED PRODUCTION ONLY Requests a virtual account from the approved banking provider with a random, email, or CNPJ key. Requires Idempotency-Key and an administratively approved nominal request.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/pix-key", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/pix-key');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/pix-key",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/qr/dynamic
Production only Credentials
Scope: pix.cash_in Product: pix.cash_in PUBLISHED PRODUCTION ONLY Creates a dynamic QR charge in the nominal account. Requires Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/dynamic", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/qr/dynamic');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/qr/dynamic",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/qr/static
Production only Credentials
Scope: pix.cash_in Product: pix.cash_in PUBLISHED PRODUCTION ONLY Creates a static QR in the nominal account. Requires Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/static", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/qr/static');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/qr/static",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/qr/decode
Production only Credentials
Scope: pix.qr_pay Product: pix.qr_pay PUBLISHED PRODUCTION ONLY Reads and validates a PIX QR through the approved banking provider without executing payment.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/decode", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/qr/decode');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/qr/decode",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/qr/pay
Production only Credentials
Scope: pix.qr_pay Product: pix.qr_pay PUBLISHED PRODUCTION ONLY Pays a PIX QR from the nominal account. Processing is asynchronous and requires Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/pay", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/qr/pay');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/qr/pay",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/pix-out
Production only Credentials
Scope: pix.cash_out Product: pix.cash_out PUBLISHED PRODUCTION ONLY Sends PIX from the nominal account. Confirmation arrives by webhook and the request requires Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/pix-out", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/pix-out');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/pix-out",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
The account’s White Label contract, including plan, add-ons, fees, billing, and access status.
/api/v1/white-label
Credentials
Scope: account.read Product: white_label Returns contract status, plan, add-ons, billing, fees, and enabled products in one response. This read-only endpoint remains available when the monthly fee is overdue.
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/white-label');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/white-label",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/plan
Credentials
Scope: account.read Product: white_label Returns the plan and add-ons contracted by the authenticated account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/plan", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/white-label/plan');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/white-label/plan",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/fees
Credentials
Scope: account.read Product: white_label Returns the plan’s commercial fees, including PIX, boleto, virtual card, and crypto asset/network rules.
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/fees", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/white-label/fees');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/white-label/fees",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/billing
Credentials
Scope: account.read Product: white_label Returns the monthly fee, setup fee, outstanding amount, due date, and access status. It does not create a charge or move funds.
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/billing", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/white-label/billing');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/white-label/billing",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/status
Credentials
Scope: account.read Product: white_label Returns only the contract status and whether financial operations through the API are enabled.
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/status", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/white-label/status');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/white-label/status",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/nominal
Production only Credentials
Scope: account.read Product: white_label Lists only requests owned by the White Label account. Documents are masked and identity data comes from the central VexusPay profile.
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/nominal", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/white-label/nominal');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/white-label/nominal",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/nominal
Production only Credentials
Scope: account.read Product: white_label Submits a request for administrative review. Name, CPF, and CNPJ are not accepted in the body; VexusPay uses only the account holder’s approved KYC.
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/nominal", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"reason": "My brand’s operating account for PIX receipts."
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/white-label/nominal');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"reason": "My brand’s operating account for PIX receipts."
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"reason": "My brand’s operating account for PIX receipts."
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/white-label/nominal",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"reason": "My brand’s operating account for PIX receipts."
}
/api/v1/white-label/nominal/bind
Production only Credentials
Scope: account.read Product: white_label Links the White Label customer identifier to an active Vexus nominal account. The identifier is isolated by White Label.
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/nominal/bind", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"nominal_user_id": 1001,
"external_subject": "cliente:1001"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/white-label/nominal/bind');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"nominal_user_id": 1001,
"external_subject": "cliente:1001"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"nominal_user_id": 1001,
"external_subject": "cliente:1001"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/white-label/nominal/bind",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"nominal_user_id": 1001,
"external_subject": "cliente:1001"
}
/api/v1/white-label/nominal/{requestId}
Production only Credentials
Scope: account.read Product: white_label Returns a request owned by the White Label account without exposing a complete document or account credentials.
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/nominal/REPLACE_WITH_REQUEST_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/white-label/nominal/REPLACE_WITH_REQUEST_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/white-label/nominal/REPLACE_WITH_REQUEST_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/nominal/{requestId}
Production only Credentials
Scope: account.read Product: white_label Cancels a request that is still pending or approved. An account that has already been provisioned cannot be canceled through this route.
const response = await fetch("https://api.nodexhub.com.br/api/v1/white-label/nominal/REPLACE_WITH_REQUEST_ID", {
method: 'DELETE',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/white-label/nominal/REPLACE_WITH_REQUEST_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'DELETE',
"https://api.nodexhub.com.br/api/v1/white-label/nominal/REPLACE_WITH_REQUEST_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
Tickets and signed webhooks for any authenticated active account. Production only.
/api/v1/support/tickets
Production only Credentials
Scope: support.manage Product: support Production only. Lists up to the 100 most recently updated tickets owned by the credential’s account. It never returns another account’s tickets or message contents.
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/tickets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/support/tickets",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/support/tickets
Production only Credentials
Scope: support.manage Product: support Production only. Opens a ticket for the authenticated account in the VexusPay support queue. Send text, up to four previously uploaded attachment_ids, or both. Never include HTML, bytes/base64, or credentials in the JSON body.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"category": "IMPLEMENTATION",
"subject": "Question about the PIX integration",
"message": "We need to validate how our integration handles the asynchronous response.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/tickets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"category": "IMPLEMENTATION",
"subject": "Question about the PIX integration",
"message": "We need to validate how our integration handles the asynchronous response.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"category": "IMPLEMENTATION",
"subject": "Question about the PIX integration",
"message": "We need to validate how our integration handles the asynchronous response.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/tickets",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"category": "IMPLEMENTATION",
"subject": "Question about the PIX integration",
"message": "We need to validate how our integration handles the asynchronous response.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
/api/v1/support/tickets/{ticketId}
Production only Credentials
Scope: support.manage Product: support Production only. Returns the ticket and chronological conversation only when the ticket belongs to the credential’s account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/support/tickets/{ticketId}/messages
Production only Credentials
Scope: support.manage Product: support Production only. Adds text, up to four previously uploaded attachment_ids, or both to the account’s ticket. A reply returns the ticket to OPEN. CLOSED tickets reject new messages.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID/messages", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"message": "We applied the change and sent a new correlation ID for analysis.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID/messages');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"message": "We applied the change and sent a new correlation ID for analysis.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"message": "We applied the change and sent a new correlation ID for analysis.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID/messages",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"message": "We applied the change and sent a new correlation ID for analysis.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
/api/v1/support/tickets/{ticketId}/close
Production only Credentials
Scope: support.manage Product: support Production only. Confirms closure of the account’s ticket. Send an empty JSON object and preserve Idempotency-Key if the request must be retried.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID/close", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID/close');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/tickets/REPLACE_WITH_TICKET_ID/close",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/support/attachments
Production only Credentials
Scope: support.manage Product: support Production only. Accepts one image in the multipart file field, verifies its actual MIME type, normalizes the bitmap, and returns a pending attachment_id. JPEG, PNG, and WebP up to 5 MiB are accepted; an unlinked ID expires after 24 hours.
Idempotency-Key.import crypto from 'node:crypto';
import { readFile } from 'node:fs/promises';
const idempotencyKey = crypto.randomUUID();
const image = await readFile('/path/to/evidence.png');
const form = new FormData();
form.append('file', new Blob([image], { type: 'image/png' }), 'evidencia.png');
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/attachments", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
body: form,
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/attachments');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
CURLOPT_POSTFIELDS => ['file' => new CURLFile('/path/to/evidence.png', 'image/png', 'evidencia.png')],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
image_file = open('/path/to/evidence.png', 'rb')
files = {'file': ('evidencia.png', image_file, 'image/png')}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/attachments",
headers=headers,
files=files,
timeout=30,
)
image_file.close()
response.raise_for_status()
print(response.json())
/api/v1/support/attachments/{attachmentId}
Production only Credentials
Scope: support.manage Product: support Production only. Returns the private binary of an image owned by the account. Every download requires API credentials, uses Cache-Control: no-store, and must be proxied by the integration backend. Never expose the Client Secret to the browser.
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/attachments/REPLACE_WITH_ATTACHMENT_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
const imageBytes = Buffer.from(await response.arrayBuffer());
console.log(response.headers.get('content-type'), imageBytes.length);
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/attachments/REPLACE_WITH_ATTACHMENT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
file_put_contents('/path/to/support-attachment', $response);
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/support/attachments/REPLACE_WITH_ATTACHMENT_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
with open('./anexo-suporte', 'wb') as output:
output.write(response.content)
/api/v1/support/webhooks
Production only Credentials
Scope: support.manage Product: support Production only. Lists this account’s endpoints subscribed to support events. URLs are reduced to their HTTPS origin and signing secrets are never returned.
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/webhooks');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/support/webhooks",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/support/webhooks
Production only Credentials
Scope: support.manage Product: support Production only. Creates an HTTPS endpoint for support events. signing_secret appears only in this response and must be stored immediately in a secure vault. If events is omitted, all five support events are subscribed.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"label": "Production support",
"url": "https://api.exemplo.com/webhooks/vexus/support",
"events": [
"support.message.created",
"support.ticket.status_changed",
"support.ticket.closed"
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/webhooks');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"label": "Production support",
"url": "https://api.exemplo.com/webhooks/vexus/support",
"events": [
"support.message.created",
"support.ticket.status_changed",
"support.ticket.closed"
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"label": "Production support",
"url": "https://api.exemplo.com/webhooks/vexus/support",
"events": [
"support.message.created",
"support.ticket.status_changed",
"support.ticket.closed"
]
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/webhooks",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"label": "Production support",
"url": "https://api.exemplo.com/webhooks/vexus/support",
"events": [
"support.message.created",
"support.ticket.status_changed",
"support.ticket.closed"
]
}
/api/v1/support/webhooks/{webhookId}/rotate-secret
Production only Credentials
Scope: support.manage Product: support Production only. Invalidates the previous secret and returns the new signing_secret once. Send an empty JSON object and update the receiver before relying on new deliveries.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/rotate-secret", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/rotate-secret');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/rotate-secret",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/support/webhooks/{webhookId}/activate
Production only Credentials
Scope: support.manage Product: support Production only. Reactivates an endpoint owned by the account and clears its failure circuit. Send an empty JSON object.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/activate", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/activate');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/activate",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/support/webhooks/{webhookId}/deactivate
Production only Credentials
Scope: support.manage Product: support Production only. Pauses new deliveries to the endpoint without deleting its history. Send an empty JSON object.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/deactivate", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/deactivate');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/webhooks/REPLACE_WITH_WEBHOOK_ID/deactivate",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
Split Payment rules, execution, lookup, cancellation, refunds, and reporting.

/api/v1/splits/rules
Credentials
Scope: split Product: split Lists split rules owned by the authenticated account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/rules", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/splits/rules');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/splits/rules",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/splits/rules
Credentials
Scope: split Product: split Creates a versioned split rule using percentages or fixed amounts.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/rules", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"name": "Partners",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "partner-account",
"percentage": "20.00"
}
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/splits/rules');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"name": "Partners",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "partner-account",
"percentage": "20.00"
}
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"name": "Partners",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "partner-account",
"percentage": "20.00"
}
]
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/splits/rules",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"name": "Partners",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "partner-account",
"percentage": "20.00"
}
]
}
/api/v1/splits/rules/{ruleId}
Credentials
Scope: split Product: split Archives the previous rule version and creates a new version.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/rules/REPLACE_WITH_RULE_ID", {
method: 'PUT',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"name": "Partners v2",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "partner-account",
"percentage": "25.00"
}
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/splits/rules/REPLACE_WITH_RULE_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'PUT',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"name": "Partners v2",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "partner-account",
"percentage": "25.00"
}
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"name": "Partners v2",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "partner-account",
"percentage": "25.00"
}
]
}
''')
response = requests.request(
'PUT',
"https://api.nodexhub.com.br/api/v1/splits/rules/REPLACE_WITH_RULE_ID",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"name": "Partners v2",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "partner-account",
"percentage": "25.00"
}
]
}
/api/v1/splits/rules/{ruleId}
Credentials
Scope: split Product: split Archives a rule owned by the account. This operation accepts no request body.
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/rules/REPLACE_WITH_RULE_ID", {
method: 'DELETE',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/splits/rules/REPLACE_WITH_RULE_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'DELETE',
"https://api.nodexhub.com.br/api/v1/splits/rules/REPLACE_WITH_RULE_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/splits
Credentials
Scope: split Product: split Creates the financial operation and allocations from an active rule. The account must have an approved Split settlement route; rule management remains available without one.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"rule_id": "00000000-0000-4000-8000-000000000001",
"amount": 100,
"payer": {
"name": "Example Customer",
"document": "52998224725",
"email": "customer@example.com"
}
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/splits');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"rule_id": "00000000-0000-4000-8000-000000000001",
"amount": 100,
"payer": {
"name": "Example Customer",
"document": "52998224725",
"email": "customer@example.com"
}
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"rule_id": "00000000-0000-4000-8000-000000000001",
"amount": 100,
"payer": {
"name": "Example Customer",
"document": "52998224725",
"email": "customer@example.com"
}
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/splits",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"rule_id": "00000000-0000-4000-8000-000000000001",
"amount": 100,
"payer": {
"name": "Example Customer",
"document": "52998224725",
"email": "customer@example.com"
}
}
/api/v1/splits/{splitId}
Credentials
Scope: split Product: split Returns the operation and allocations visible to the owning account.
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/splits/{splitId}/cancel
Credentials
Scope: split Product: split Cancels a split only when its financial state allows it. Accepts no request body.
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID/cancel", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID/cancel');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID/cancel",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/splits/{splitId}/refund
Credentials
Scope: split Product: split Requests a partial or full refund. HTTP 202 indicates asynchronous processing, not completion.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID/refund", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": 25,
"comment": "Partial refund requested by the customer"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID/refund');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": 25,
"comment": "Partial refund requested by the customer"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": 25,
"comment": "Partial refund requested by the customer"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/splits/REPLACE_WITH_SPLIT_ID/refund",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": 25,
"comment": "Partial refund requested by the customer"
}
/api/v1/splits/report
Credentials
Scope: split Product: split Returns items owned by the authenticated account within the supplied UTC interval.
const response = await fetch("https://api.nodexhub.com.br/api/v1/splits/report", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/splits/report');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/splits/report",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
Sandbox-only controls used to simulate states without moving real funds.
/api/v1/sandbox/workspace
Credentials
Scope: sandbox.manage Returns only the authenticated account’s simulated balances and resources.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/workspace", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/workspace');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/sandbox/workspace",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/sandbox/faucet
Credentials
Scope: sandbox.manage Credits a simulated asset to the isolated Sandbox ledger.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/faucet", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"asset": "USDT_BEP20",
"amount": "25.00"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/faucet');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"asset": "USDT_BEP20",
"amount": "25.00"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"asset": "USDT_BEP20",
"amount": "25.00"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/faucet",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"asset": "USDT_BEP20",
"amount": "25.00"
}
/api/v1/sandbox/reset
Credentials
Scope: sandbox.manage Deletes only this account’s Sandbox resources and recreates its initial simulated balance.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/reset", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"confirmation": "RESET_SANDBOX"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/reset');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"confirmation": "RESET_SANDBOX"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"confirmation": "RESET_SANDBOX"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/reset",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"confirmation": "RESET_SANDBOX"
}
/api/v1/sandbox/resources/{resourceType}/{resourceId}/actions
Credentials
Scope: sandbox.manage Approves, fails, expires, or reverses a pending simulated operation.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/resources/REPLACE_WITH_RESOURCE_TYPE/REPLACE_WITH_RESOURCE_ID/actions", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"action": "APPROVE"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/resources/REPLACE_WITH_RESOURCE_TYPE/REPLACE_WITH_RESOURCE_ID/actions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"action": "APPROVE"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"action": "APPROVE"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/resources/REPLACE_WITH_RESOURCE_TYPE/REPLACE_WITH_RESOURCE_ID/actions",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"action": "APPROVE"
}
/api/v1/sandbox/crypto/deposits
Credentials
Scope: sandbox.manage Creates a simulated deposit without broadcasting or querying a blockchain. Use wallet_id returned when creating or listing a Sandbox wallet owned by the same account.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/crypto/deposits", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"wallet_id": "00000000-0000-4000-8000-000000000003",
"amount": "10.00",
"confirmations": 0
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/crypto/deposits');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"wallet_id": "00000000-0000-4000-8000-000000000003",
"amount": "10.00",
"confirmations": 0
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"wallet_id": "00000000-0000-4000-8000-000000000003",
"amount": "10.00",
"confirmations": 0
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/crypto/deposits",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"wallet_id": "00000000-0000-4000-8000-000000000003",
"amount": "10.00",
"confirmations": 0
}
/api/v1/sandbox/cards/{cardId}/transactions
Credentials
Scope: sandbox.manage Simulates approval, decline, reversal, or refund for a simulated card.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/cards/REPLACE_WITH_CARD_ID/transactions", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": "12.50",
"currency": "USD",
"outcome": "APPROVED"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/cards/REPLACE_WITH_CARD_ID/transactions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": "12.50",
"currency": "USD",
"outcome": "APPROVED"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": "12.50",
"currency": "USD",
"outcome": "APPROVED"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/cards/REPLACE_WITH_CARD_ID/transactions",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": "12.50",
"currency": "USD",
"outcome": "APPROVED"
}
/api/v1/sandbox/cards/{cardId}/otp
Credentials
Scope: sandbox.manage Generates a simulated OTP and delivers it only through the Sandbox webhook pipeline.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/cards/REPLACE_WITH_CARD_ID/otp", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"wallet_type": "GOOGLE_PAY"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/cards/REPLACE_WITH_CARD_ID/otp');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"wallet_type": "GOOGLE_PAY"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"wallet_type": "GOOGLE_PAY"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/cards/REPLACE_WITH_CARD_ID/otp",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"wallet_type": "GOOGLE_PAY"
}
/api/v1/sandbox/webhook-deliveries
Credentials
Scope: sandbox.manage Lists webhook deliveries and attempts from the Sandbox environment.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/sandbox/webhook-deliveries/{deliveryId}/retry
Credentials
Scope: sandbox.manage Schedules a Sandbox delivery again without affecting production webhooks.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries/REPLACE_WITH_DELIVERY_ID/retry", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries/REPLACE_WITH_DELIVERY_ID/retry');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries/REPLACE_WITH_DELIVERY_ID/retry",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}