Saldo fictício
O workspace inicia com R$ 100.000,00 fictícios. Use GET /api/v1/sandbox/workspace, o faucet e o reset para organizar seus testes.
Conecte Pix, boleto, checkout, cripto, cartões e Split Payment com contratos estáveis, segurança e visibilidade em cada etapa.

https://sandbox-api.example.invalid
https://sandbox-api.vexuspay.com.br está público com DNS, TLS e health checks validados. Selecione Sandbox acima para apontar os exemplos ao ambiente isolado, que nunca movimenta valores reais.Crie uma credencial marcada como Sandbox em Configurações → Credenciais. Ela começa com vx_sbx_, funciona somente no hostname Sandbox e nunca acessa saldo, carteiras, provedores ou webhooks de produção.

O workspace inicia com R$ 100.000,00 fictícios. Use GET /api/v1/sandbox/workspace, o faucet e o reset para organizar seus testes.
Crie a operação pela rota normal e use os Sandbox Controls para aprovar, falhar, expirar ou reverter sem liquidação financeira.
Endpoints, entregas, tentativas e assinaturas Sandbox não são compartilhados com Produção. O corpo de OTP fica criptografado no pipeline e é redigido na auditoria.
Idempotency-Key. O Sandbox usa a mesma chave por credencial, método, path e corpo; repetir o corpo devolve o resultado lógico e trocar o corpo retorna conflito.X-Vexus-Sandbox-Scenario com success, insufficient_balance, provider_timeout, rate_limited, declined, expired ou webhook_retry. A Produção rejeita esse header.Contratos simples, respostas estruturadas e exemplos prontos para o backend.
Repetições seguras nas operações financeiras sem duplicar movimentações.
Entrega autenticada e retentativas com identificador estável.
As rotas privadas usam duas credenciais enviadas somente pelo seu servidor. Nunca exponha o Client Secret no navegador, aplicativo móvel ou repositório.

Apikey: SEU_CLIENT_ID
X-Client-Secret: SEU_CLIENT_SECRET
Content-Type: application/json
No painel, abra Configurações → Credenciais, escolha o ambiente e os menores escopos necessários. O Client Secret aparece somente na criação ou rotação: armazene-o imediatamente em um cofre.
Escopo e produto são verificações independentes. Cada rota abaixo informa ambos; uma credencial com o escopo correto ainda recebe 403 se o produto da conta estiver desabilitado.
Quando usar a allowlist opcional, cadastre o IP público de saída do seu backend. Nunca tente autenticar diretamente do navegador ou do aplicativo móvel.
Apikey e X-Client-Secret.401 para revisar credencial/ambiente e 403 para revisar conta ativa, produto, escopo, IP permitido ou restrição de User-Agent. Não envie credenciais em ticket, chat, URL ou log.Use de 8 a 100 caracteres e repita a mesma chave somente para o mesmo método, URL e conteúdo. Se não houver resposta conclusiva, consulte a intenção por operation + Idempotency-Key antes de qualquer nova tentativa financeira. No upload multipart, preserve os mesmos bytes e metadados do arquivo; conteúdo divergente retorna conflito. A Idempotency-Key é criada pelo seu próprio servidor antes de chamar uma rota que exige a chave; a VexusPay não a entrega nem a busca no painel.
Use um UUID aleatório para uma intenção de operação, por exemplo uma emissão ou uma recarga.
Inclua Idempotency-Key junto das credenciais e do JSON da operação.
Sem resposta conclusiva, use GET /api/v1/account/operations/by-idempotency/{idempotencyKey}?operation=... com a mesma credencial e repita o contexto de custódia cripto ou de usuário externo do cartão quando aplicável.
Só gere uma nova chave depois de confirmar que a intenção anterior terminou ou falhou definitivamente.
// Node.js
const idempotencyKey = crypto.randomUUID();
// PHP
$idempotencyKey = bin2hex(random_bytes(16));
# Python
idempotency_key = str(uuid.uuid4())
Idempotency-Key: <idempotencyKey>
reconciliation_required=true, mantenha a operação em revisão e não repita a movimentação. Nunca reutilize uma chave antiga para uma nova cobrança, recarga, congelamento ou cancelamento.Erros JSON retornam statusCode, message e error com code, details, correlationId e retryable. Registre o correlationId, nunca as credenciais ou o corpo sensível.
400/413/415/422 indicam request inválido. 401/403 indicam autenticação ou autorização. 404 também protege o isolamento entre contas. 409 exige consultar o recurso ou preservar a intenção original.
Pause pelo tempo informado em Retry-After e aplique backoff exponencial com jitter. Não gere outra intenção nem outra Idempotency-Key.
Em timeout, 500, 502, 503 ou 504, não presuma falha nem sucesso financeiro. Consulte pela Idempotency-Key original antes de qualquer nova POST; se o estado continuar inconclusivo, mantenha em revisão e acione o suporte com o correlationId. Um timeout gerado antes da aplicação pode não conter o envelope JSON.
201 e 202 confirmam criação ou admissão, não liquidação, PIX concluído ou confirmação blockchain. Persista os IDs retornados. Em cripto e no ciclo financeiro do cartão virtual, acompanhe pelas rotas GET: não existe webhook público de ciclo de vida para esses dois módulos. O único webhook público de cartão virtual é o de OTP.A API cripto usa as mesmas credenciais servidor-a-servidor. Consulte o catálogo antes de operar: ele é a fonte de verdade para moedas, redes, confirmações e disponibilidade de entrada ou saída.
Liste /api/v1/crypto/networks e /api/v1/crypto/assets, depois envie network para /api/v1/crypto/wallets. A criação é idempotente por conta e rede.
Consulte o endereço da carteira. A VexusPay monitora a blockchain, aguarda as confirmações da rede e credita o ledger sem ação manual.
Crie uma cotação, execute com uma nova Idempotency-Key da mesma intenção e acompanhe o ID retornado. Reserva, transmissão e confirmação continuam em segundo plano.
*_units e *_minor como strings inteiras na menor unidade, nunca como float. Em saques NET, taxas podem aumentar o débito; em GROSS, elas são descontadas do teto autorizado. Nunca presuma gás patrocinado: use os componentes e a validade retornados pela cotação. O Client Secret fica somente no backend.X-Vexus-Custody-Subject com o identificador interno, opaco, estável e imutável do seu usuário — nunca e-mail, telefone ou documento. O runtime aceita de 1 a 64 caracteres; para novas integrações, prefira pelo menos 8. Para a custódia central da própria White Label, envie somente X-Vexus-Custody-Access: CENTRAL. Os dois modos são mutuamente exclusivos.POST /api/v1/crypto/internal-transfers, envie exatamente um destinatário. Prefira recipient_custody_subject: ele precisa apontar para um subject ACTIVE já existente na mesma White Label e nunca é criado automaticamente por essa rota. recipient_external_user_id permanece apenas como compatibilidade legada./api/v1/crypto/swaps/quote e execute em /api/v1/crypto/swaps, usando apenas pares retornados pelo catálogo. BRL → cripto exige endereço externo e capacidade liberada em /api/v1/crypto/conversions/capabilities. Cripto → BRL está em manutenção: não envie novas cotações ou confirmações nessa direção.wallet.create, withdrawal.quote, withdrawal.execute, swap.quote, swap.execute, transfer.internal, conversion.address, conversion.quote ou conversion.confirm) e preserve corpo e Idempotency-Key.A Central de Suporte conecta o backend de qualquer conta VexusPay habilitada à fila de atendimento. Ela pode ser incorporada ao painel ou sistema próprio do cliente usando as credenciais API da conta e, hoje, está disponível somente em https://api.vexuspay.com.br.
POST /api/v1/support/tickets vincula os IDs e cria o protocolo.POST /api/v1/support/tickets/{ticketId}/messages devolve o ticket para a fila, com estado OPEN.Envie Apikey e X-Client-Secret a partir do backend. Nunca exponha o segredo no painel web, aplicativo móvel ou código entregue ao navegador.
support.manage na credencialsupport habilitadoO titular é determinado pela credencial autenticada, nunca por um ID enviado no corpo. Consulta ou resposta a um ticket de outra conta não revela sua existência.
Toda operação POST, inclusive upload e controle de webhook, usa uma chave de 8 a 100 caracteres. Em um retry, repita a mesma chave, o mesmo corpo e, no multipart, exatamente os mesmos bytes.
GET não usam a chavehttps://api.vexuspay.com.br/api/v1/support/attachmentsRecebe no campo multipart file uma imagem JPEG, PNG ou WebP de até 5 MiB.
/api/v1/support/attachments/{attachmentId}Baixa o binário privado com autenticação; o navegador deve acessá-lo pelo backend do integrador.
/api/v1/support/ticketsAbre um ticket com category, subject e texto, até quatro attachment_ids, ou ambos.
/api/v1/support/ticketsLista somente os tickets pertencentes à conta autenticada.
/api/v1/support/tickets/{ticketId}Retorna o ticket e sua conversa cronológica.
/api/v1/support/tickets/{ticketId}/messagesEnvia texto de até 5.000 caracteres, até quatro attachment_ids, ou ambos.
/api/v1/support/tickets/{ticketId}/closeConfirma o fechamento do ticket.
/api/v1/support/webhooksLista os endpoints de suporte da própria conta, sem reexibir o segredo.
/api/v1/support/webhooksCadastra uma URL HTTPS e entrega o segredo de assinatura uma única vez.
/api/v1/support/webhooks/{webhookId}/rotate-secretRevoga o segredo anterior e retorna o novo uma única vez.
/api/v1/support/webhooks/{webhookId}/activateReativa a entrega para o endpoint.
/api/v1/support/webhooks/{webhookId}/deactivatePausa novas entregas para o endpoint.
curl --request POST 'https://api.vexuspay.com.br/api/v1/support/attachments' \
--header 'Apikey: SEU_CLIENT_ID' \
--header 'X-Client-Secret: SEU_CLIENT_SECRET' \
--header 'Idempotency-Key: 14f759ee-a6f4-420a-924a-8ce85de34717' \
--form 'file=@/caminho/evidencia.png;type=image/png'
PENDING válido por 24 horas; cada conta pode manter 20 pendentes e enviar, numa janela móvel de 24 horas, até 100 arquivos ou 100 MiB. Vincule até quatro IDs no JSON do ticket ou da mensagem. O download_url exige credenciais API: o backend deve baixar ou fazer proxy autorizado, nunca repassar Apikey ou X-Client-Secret ao navegador. Mensagens e webhooks carregam somente metadados e URL, jamais bytes/base64.curl --request POST 'https://api.vexuspay.com.br/api/v1/support/tickets' \
--header 'Apikey: SEU_CLIENT_ID' \
--header 'X-Client-Secret: SEU_CLIENT_SECRET' \
--header 'Idempotency-Key: 9cb6dffc-a856-4c52-a417-4be6012dde8a' \
--header 'Content-Type: application/json' \
--data '{
"category": "IMPLEMENTATION",
"subject": "Dúvida na integração",
"message": "Precisamos validar o retorno do endpoint de cobrança.",
"attachment_ids": ["d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"]
}'
curl --request POST 'https://api.vexuspay.com.br/api/v1/support/webhooks' \
--header 'Apikey: SEU_CLIENT_ID' \
--header 'X-Client-Secret: SEU_CLIENT_SECRET' \
--header 'Idempotency-Key: 672980ad-209c-4557-9ff8-d6a22430bf09' \
--header 'Content-Type: application/json' \
--data '{
"label": "Suporte produção",
"url": "https://seu-dominio.com.br/webhooks/vexus/support"
}'
FINANCIAL Financeiro
TECHNICAL Técnico / TI
IMPLEMENTATION Implementação / API
COMMERCIAL Comercial / Conta
OTHER Outros
O assunto deve ter de 3 a 180 caracteres. O texto aceita até 5.000 caracteres e pode ficar vazio quando houver ao menos uma imagem válida.
OPENIN_PROGRESSWAITING_CUSTOMERRESOLVEDCLOSEDSucessos seguem {"statusCode": ..., "data": ...}. Erros informam código estável, correlationId e se a falha é retentável.
401 como credencial ausente ou inválida.403 como produto, escopo ou elegibilidade ausente.413/415 como tamanho ou tipo de imagem inválido; não tente converter no navegador.429 e X-RateLimit-Reset; o limite padrão é 120 requisições por minuto por credencial.Preserve o corpo bruto e use o segredo retornado na criação ou rotação do endpoint:
json_decode.HMAC-SHA256(timestamp + "." + rawBody, signing_secret) e compare em tempo constante com X-Vexus-Signature.X-Vexus-Timestamp e deduplique por event_id e X-Vexus-Delivery.2xx rapidamente e processe o trabalho em fila interna.support.ticket.created, support.ticket.assigned, support.message.created, support.ticket.status_changed e support.ticket.closed. Em mensagens com imagens, o evento contém somente metadados e download_url protegida, nunca bytes/base64. Falhas transitórias são reenviadas com backoff exponencial e jitter; após o limite configurado, a entrega fica em DEAD. Veja também a seção Webhooks.Valide a assinatura usando o corpo bruto recebido antes de interpretar o JSON. Respostas 2xx confirmam a entrega.

X-Vexus-Event: checkout.order.status_changed | virtual_card.otp.received | support.message.created
X-Vexus-Delivery: <uuid>
X-Vexus-Timestamp: <unix_timestamp>
X-Vexus-Signature: v1=<hmac_sha256>
HMAC-SHA256(timestamp + "." + rawBody, signing_secret). Compare em tempo constante, aceite somente timestamps recentes e use event_id/X-Vexus-Delivery para ignorar repetição. A entrega retenta falhas de transporte, 408, 409, 425, 429 e 5xx; webhooks de suporte estão disponíveis somente em Produção.Os exemplos abaixo são derivados do mesmo contrato que gera o OpenAPI e a coleção Postman.
Disponibilidade técnica sem autenticação.
/health/live
Público
Verifica se o processo HTTP está ativo.
const response = await fetch("https://sandbox-api.example.invalid/health/live", {
method: 'GET',
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/health/live');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/health/live",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/health/ready
Público
Valida banco, migrações e dependências internas necessárias para receber tráfego.
const response = await fetch("https://sandbox-api.example.invalid/health/ready", {
method: 'GET',
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/health/ready');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/health/ready",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
Entrada, saída, leitura e pagamento de QR Code PIX.

/api/v1/cashin
Credenciais
Escopo: cashin Produto: pix.cash_in Cria uma cobrança PIX dinâmica. Use uma nova Idempotency-Key para cada nova cobrança; reutilize a chave somente ao repetir exatamente a mesma intenção.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cashin", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": 25.9
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cashin');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": 25.9
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": 25.9
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/cashin",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": 25.9
}
/api/v1/cashout
Credenciais
Escopo: cashout Produto: pix.cash_out Envia um PIX para a chave informada, sujeito a saldo, produto e limites da conta.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cashout", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": 20,
"pix_key": "<chave-pix-destino>",
"pix_key_type": "random",
"description": "Repasse"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cashout');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": 20,
"pix_key": "<chave-pix-destino>",
"pix_key_type": "random",
"description": "Repasse"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": 20,
"pix_key": "<chave-pix-destino>",
"pix_key_type": "random",
"description": "Repasse"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/cashout",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": 20,
"pix_key": "<chave-pix-destino>",
"pix_key_type": "random",
"description": "Repasse"
}
/api/v1/pix/qr/decode
Credenciais
Escopo: cashout Produto: pix.cash_out Valida o CRC e decodifica um payload EMV PIX sem movimentar saldo. A resposta informa se o valor está fixado no próprio QR.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/pix/qr/decode", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/pix/qr/decode');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/pix/qr/decode",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE"
}
/api/v1/pix/qr/pay
Credenciais
Escopo: cashout Produto: pix.cash_out Paga um QR Code PIX após validar CRC, valor declarado, saldo e limites. Um valor presente no QR sempre prevalece sobre o valor enviado pelo integrador.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/pix/qr/pay", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE",
"description": "Fornecedor"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/pix/qr/pay');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE",
"description": "Fornecedor"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE",
"description": "Fornecedor"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/pix/qr/pay",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"payload": "00020101021226810014br.gov.bcb.pix2559https://example.invalid/pix/cobranca-exemplo520400005303986540539.905802BR5905VEXUS6009SAO PAULO62070503***6304B9CE",
"description": "Fornecedor"
}
Emissão, consulta e pagamento de boleto.

/api/v1/boleto/issue
Credenciais
Escopo: boleto Produto: boleto Emite uma cobrança direta sem exigir um item no catálogo do Checkout. O produto de API boleto precisa estar habilitado. Nome, CPF/CNPJ e e-mail são obtidos do cadastro; o endereço não é obrigatório.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/boleto/issue", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": 99.9,
"due_date": "2026-09-30",
"description": "Cobrança por boleto"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/boleto/issue');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": 99.9,
"due_date": "2026-09-30",
"description": "Cobrança por boleto"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": 99.9,
"due_date": "2026-09-30",
"description": "Cobrança por boleto"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/boleto/issue",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": 99.9,
"due_date": "2026-09-30",
"description": "Cobrança por boleto"
}
/api/v1/boleto/info
Credenciais
Escopo: boleto Produto: boleto Consulta no provedor, sem movimentar saldo, o valor atualizado e os dados do beneficiário.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/boleto/info", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"billetCode": "00190000000000014990000000000000000000000000"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/boleto/info');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"billetCode": "00190000000000014990000000000000000000000000"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"billetCode": "00190000000000014990000000000000000000000000"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/boleto/info",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"billetCode": "00190000000000014990000000000000000000000000"
}
/api/v1/boleto/pay
Credenciais
Escopo: boleto Produto: boleto Reconsulta no provedor o valor atualizado e o beneficiário, então valida saldo e limites antes do pagamento. O integrador envia somente o código.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/boleto/pay", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"billetCode": "00190000000000014990000000000000000000000000"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/boleto/pay');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"billetCode": "00190000000000014990000000000000000000000000"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"billetCode": "00190000000000014990000000000000000000000000"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/boleto/pay",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"billetCode": "00190000000000014990000000000000000000000000"
}
Catálogo, links, meios habilitados e relatório de checkout.

/api/v1/card/config
Somente produção Credenciais
Escopo: cards.write Produto: card PUBLISHED_PRODUCTION_ONLY Retorna a chave pública e a URL do SDK autorizados para tokenizar o cartão no navegador. Nunca envie PAN ou CVV ao backend da VexusPay.
const response = await fetch("https://api.nodexhub.com.br/api/v1/card/config", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/card/config');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/card/config",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/card/pay
Somente produção Credenciais
Escopo: cards.write Produto: card PUBLISHED_PRODUCTION_ONLY Processa uma cobrança avulsa sem exigir um item no catálogo do Checkout. O produto de API card precisa estar habilitado. Use um cartão já tokenizado pelo SDK indicado na configuração; esta rota exige token de uso único e não aceita PAN ou CVV.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/card/pay", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": 99.9,
"external_id": "pedido-zoe-123",
"buyer_name": "Cliente de Exemplo",
"buyer_email": "cliente@example.com",
"buyer_cpf": "52998224725",
"card_token": "SUBSTITUA_PELO_TOKEN_DE_USO_UNICO",
"payment_method_id": "visa",
"installments": 1,
"description": "Pedido ZoePay 123"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/card/pay');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": 99.9,
"external_id": "pedido-zoe-123",
"buyer_name": "Cliente de Exemplo",
"buyer_email": "cliente@example.com",
"buyer_cpf": "52998224725",
"card_token": "SUBSTITUA_PELO_TOKEN_DE_USO_UNICO",
"payment_method_id": "visa",
"installments": 1,
"description": "Pedido ZoePay 123"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": 99.9,
"external_id": "pedido-zoe-123",
"buyer_name": "Cliente de Exemplo",
"buyer_email": "cliente@example.com",
"buyer_cpf": "52998224725",
"card_token": "SUBSTITUA_PELO_TOKEN_DE_USO_UNICO",
"payment_method_id": "visa",
"installments": 1,
"description": "Pedido ZoePay 123"
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/card/pay",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": 99.9,
"external_id": "pedido-zoe-123",
"buyer_name": "Cliente de Exemplo",
"buyer_email": "cliente@example.com",
"buyer_cpf": "52998224725",
"card_token": "SUBSTITUA_PELO_TOKEN_DE_USO_UNICO",
"payment_method_id": "visa",
"installments": 1,
"description": "Pedido ZoePay 123"
}
/api/v1/checkout/methods
Credenciais
Escopo: checkout Produto: checkout Retorna somente meios de pagamento homologados e disponíveis para a conta autenticada.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/methods", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/methods');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/checkout/methods",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/report
Credenciais
Escopo: checkout Produto: checkout Retorna métricas agregadas dos links e pedidos pertencentes à conta autenticada.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/report", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/report');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/checkout/report",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/products
Credenciais
Escopo: checkout Produto: checkout Lista produtos ativos e arquivados do catálogo da conta.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/products", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/products');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/checkout/products",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/products
Credenciais
Escopo: checkout Produto: checkout Cria um produto no catálogo. Meios que exigem identificação de produto externo só podem ser usados quando provider_product_id for informado.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/products", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"name": "Plano mensal",
"price": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/products');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"name": "Plano mensal",
"price": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"name": "Plano mensal",
"price": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/checkout/products",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"name": "Plano mensal",
"price": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
/api/v1/checkout/products/{productId}
Credenciais
Escopo: checkout Produto: checkout Retorna o produto do catálogo pertencente à conta autenticada.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/products/SUBSTITUA_PELO_PRODUCT_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/products/SUBSTITUA_PELO_PRODUCT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/checkout/products/SUBSTITUA_PELO_PRODUCT_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/products/{productId}
Credenciais
Escopo: checkout Produto: checkout Atualiza uma versão do produto. Envie version retornado na leitura para impedir sobrescrita concorrente.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/products/SUBSTITUA_PELO_PRODUCT_ID", {
method: 'PUT',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"name": "Plano mensal atualizado",
"price": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/products/SUBSTITUA_PELO_PRODUCT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'PUT',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"name": "Plano mensal atualizado",
"price": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"name": "Plano mensal atualizado",
"price": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
''')
response = requests.request(
'PUT',
"https://sandbox-api.example.invalid/api/v1/checkout/products/SUBSTITUA_PELO_PRODUCT_ID",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"name": "Plano mensal atualizado",
"price": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
/api/v1/checkout/products/{productId}
Credenciais
Escopo: checkout Produto: checkout Arquiva o produto e os links ativos associados. A ação exige Idempotency-Key e não aceita corpo.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/products/SUBSTITUA_PELO_PRODUCT_ID", {
method: 'DELETE',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/products/SUBSTITUA_PELO_PRODUCT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'DELETE',
"https://sandbox-api.example.invalid/api/v1/checkout/products/SUBSTITUA_PELO_PRODUCT_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/links
Credenciais
Escopo: checkout Produto: checkout Lista links de pagamento, estado e métricas da conta autenticada.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/links", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/links');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/checkout/links",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/links
Credenciais
Escopo: checkout Produto: checkout Cria um link avulso ou associado a produto. O payment_path retornado deve ser combinado com seu domínio VexusPay.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/links", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"title": "Pagamento de serviço",
"amount": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/links');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"title": "Pagamento de serviço",
"amount": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"title": "Pagamento de serviço",
"amount": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/checkout/links",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"title": "Pagamento de serviço",
"amount": "49.90",
"currency": "BRL",
"payment_methods": [
"PIX"
]
}
/api/v1/checkout/links/{linkId}
Credenciais
Escopo: checkout Produto: checkout Retorna a configuração e o payment_path do link pertencente à conta autenticada.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/links/{linkId}
Credenciais
Escopo: checkout Produto: checkout Atualiza uma versão do link. Envie version retornado na leitura para impedir sobrescrita concorrente.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID", {
method: 'PUT',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"title": "Pagamento de serviço atualizado",
"amount": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'PUT',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"title": "Pagamento de serviço atualizado",
"amount": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"title": "Pagamento de serviço atualizado",
"amount": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
''')
response = requests.request(
'PUT',
"https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"title": "Pagamento de serviço atualizado",
"amount": "59.90",
"currency": "BRL",
"payment_methods": [
"PIX"
],
"version": 1
}
/api/v1/checkout/links/{linkId}/archive
Credenciais
Escopo: checkout Produto: checkout Arquiva o link e impede novos pagamentos. Exige Idempotency-Key e não aceita corpo.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID/archive", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID/archive');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID/archive",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/checkout/links/{linkId}/cancel
Credenciais
Escopo: checkout Produto: checkout Cancela o link com motivo auditável e impede novos pagamentos. Exige Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID/cancel", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"reason": "Solicitação de cancelamento do cliente"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID/cancel');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"reason": "Solicitação de cancelamento do cliente"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"reason": "Solicitação de cancelamento do cliente"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/checkout/links/SUBSTITUA_PELO_LINK_ID/cancel",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"reason": "Solicitação de cancelamento do cliente"
}
Catálogo, carteiras, saldos, depósitos, saques, swaps, transferências internas e conversões conforme capacidade consultada.

/api/v1/crypto/networks
Credenciais
Escopo: cashin Produto: crypto Lista BSC e TRON com manutenção e capacidades de depósito, saque e swap.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/networks", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/networks');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/networks",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/assets
Credenciais
Escopo: cashin Produto: crypto Lista os ativos por rede, casas decimais e capacidades efetivamente habilitadas.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/assets", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/assets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/assets",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/swap-pairs
Credenciais
Escopo: cashin Produto: crypto Lista pares same-chain e o cross-chain USDT TRC-20 ↔ USDT BEP-20 disponíveis.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/swap-pairs", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/swap-pairs');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/swap-pairs",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/wallets
Credenciais
Escopo: cashin Produto: crypto Lista somente as carteiras da conta ou do contexto de custódia autenticado.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/wallets", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/wallets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/wallets",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/wallets
Credenciais
Escopo: cashin Produto: crypto Cria ou reutiliza idempotentemente a carteira HD BSC ou TRON da conta. Tokens da mesma rede usam o mesmo endereço.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/wallets", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"network": "BSC"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/wallets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"network": "BSC"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"network": "BSC"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/crypto/wallets",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"network": "BSC"
}
/api/v1/crypto/wallets/{walletId}
Credenciais
Escopo: cashin Produto: crypto Retorna uma carteira Vexus pertencente à conta autenticada.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/wallets/SUBSTITUA_PELO_WALLET_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/wallets/SUBSTITUA_PELO_WALLET_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/wallets/SUBSTITUA_PELO_WALLET_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/wallets/{walletId}/balances
Credenciais
Escopo: cashin Produto: crypto Retorna saldos ledger, disponível, reservado, pendente e on-chain em strings inteiras de unidade mínima.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/wallets/SUBSTITUA_PELO_WALLET_ID/balances", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/wallets/SUBSTITUA_PELO_WALLET_ID/balances');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/wallets/SUBSTITUA_PELO_WALLET_ID/balances",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/wallets/{walletId}/transactions
Credenciais
Escopo: cashin Produto: crypto Lista depósitos e saques recentes da carteira.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/wallets/SUBSTITUA_PELO_WALLET_ID/transactions", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/wallets/SUBSTITUA_PELO_WALLET_ID/transactions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/wallets/SUBSTITUA_PELO_WALLET_ID/transactions",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/deposits
Credenciais
Escopo: cashin Produto: crypto Lista somente depósitos vinculados às carteiras da conta ou do contexto de custódia autenticado.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/deposits", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/deposits');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/deposits",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/deposits/{depositId}
Credenciais
Escopo: cashin Produto: crypto Retorna confirmações e estado do depósito; CREDITED ou 200 não substituem a verificação de estado terminal.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/deposits/SUBSTITUA_PELO_DEPOSIT_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/deposits/SUBSTITUA_PELO_DEPOSIT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/deposits/SUBSTITUA_PELO_DEPOSIT_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/withdrawals/quote
Credenciais
Escopo: cashout Produto: crypto Cria cotação autoritativa com taxas, valor líquido, total debitado e validade em *_units. Em GROSS, o valor informado é o teto e as taxas são descontadas dele. Não movimenta saldo.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/withdrawals/quote", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"network": "BSC",
"asset": "USDT_BSC",
"destination_address": "SUBSTITUA_PELO_ENDERECO_BSC",
"amount_units": "1000000",
"amount_mode": "GROSS"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/withdrawals/quote');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"network": "BSC",
"asset": "USDT_BSC",
"destination_address": "SUBSTITUA_PELO_ENDERECO_BSC",
"amount_units": "1000000",
"amount_mode": "GROSS"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"network": "BSC",
"asset": "USDT_BSC",
"destination_address": "SUBSTITUA_PELO_ENDERECO_BSC",
"amount_units": "1000000",
"amount_mode": "GROSS"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/crypto/withdrawals/quote",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"network": "BSC",
"asset": "USDT_BSC",
"destination_address": "SUBSTITUA_PELO_ENDERECO_BSC",
"amount_units": "1000000",
"amount_mode": "GROSS"
}
/api/v1/crypto/withdrawals
Credenciais
Escopo: cashout Produto: crypto Reserva e agenda o saque pelo quote_id. A resposta 202 não confirma blockchain; acompanhe até estado terminal.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/withdrawals", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"quote_id": "00000000-0000-4000-8000-000000000002"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/withdrawals');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"quote_id": "00000000-0000-4000-8000-000000000002"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"quote_id": "00000000-0000-4000-8000-000000000002"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/crypto/withdrawals",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"quote_id": "00000000-0000-4000-8000-000000000002"
}
/api/v1/crypto/withdrawals/{withdrawalId}
Credenciais
Escopo: cashout Produto: crypto Retorna estado, TXID e custo real de rede quando disponíveis.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/withdrawals/SUBSTITUA_PELO_WITHDRAWAL_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/withdrawals/SUBSTITUA_PELO_WITHDRAWAL_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/withdrawals/SUBSTITUA_PELO_WITHDRAWAL_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/swaps/quote
Credenciais
Escopo: cashout Produto: crypto Cria cotação autoritativa same-chain ou USDT cross-chain usando somente pares publicados.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/swaps/quote", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"asset_in": "USDT_TRC20",
"asset_out": "USDT_BSC",
"amount_in_units": "1000000",
"slippage_bps": 50
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/swaps/quote');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"asset_in": "USDT_TRC20",
"asset_out": "USDT_BSC",
"amount_in_units": "1000000",
"slippage_bps": 50
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"asset_in": "USDT_TRC20",
"asset_out": "USDT_BSC",
"amount_in_units": "1000000",
"slippage_bps": 50
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/crypto/swaps/quote",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"asset_in": "USDT_TRC20",
"asset_out": "USDT_BSC",
"amount_in_units": "1000000",
"slippage_bps": 50
}
/api/v1/crypto/swaps
Credenciais
Escopo: cashout Produto: crypto Reserva e agenda o swap pelo quote_id. A resposta 202 não confirma liquidação.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/swaps", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"quote_id": "00000000-0000-4000-8000-000000000003"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/swaps');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"quote_id": "00000000-0000-4000-8000-000000000003"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"quote_id": "00000000-0000-4000-8000-000000000003"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/crypto/swaps",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"quote_id": "00000000-0000-4000-8000-000000000003"
}
/api/v1/crypto/swaps/{swapId}
Credenciais
Escopo: cashout Produto: crypto Retorna valores realizados, hashes e estado conciliado do swap.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/swaps/SUBSTITUA_PELO_SWAP_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/swaps/SUBSTITUA_PELO_SWAP_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/swaps/SUBSTITUA_PELO_SWAP_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/internal-transfers
Credenciais
Escopo: cashout Produto: crypto Liquida entre dois usuários VexusPay no ledger Vexus. Não cria transação blockchain nem TXID. Envie exatamente um destinatário: recipient_custody_subject é o modo recomendado para White Label e precisa identificar um subject ACTIVE já existente na mesma White Label; esta rota não cria usuário automaticamente. recipient_external_user_id permanece apenas para compatibilidade.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/internal-transfers", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"recipient_custody_subject": "usuario_00000002",
"network": "TRON",
"asset": "USDT_TRC20",
"amount_units": "1000000"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/internal-transfers');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"recipient_custody_subject": "usuario_00000002",
"network": "TRON",
"asset": "USDT_TRC20",
"amount_units": "1000000"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"recipient_custody_subject": "usuario_00000002",
"network": "TRON",
"asset": "USDT_TRC20",
"amount_units": "1000000"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/crypto/internal-transfers",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"recipient_custody_subject": "usuario_00000002",
"network": "TRON",
"asset": "USDT_TRC20",
"amount_units": "1000000"
}
/api/v1/crypto/conversions/capabilities
Credenciais
Escopo: cashin Produto: crypto Retorna as direções, ativos, redes e controles operacionais disponíveis sem criar operação.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/conversions/capabilities", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/conversions/capabilities');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/conversions/capabilities",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/conversions/markets
Credenciais
Escopo: cashin Produto: crypto Preços indicativos do parceiro; não são cotações executáveis.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/conversions/markets", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/conversions/markets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/conversions/markets",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/conversions
Credenciais
Escopo: cashin Produto: crypto Lista endereços externos do parceiro pertencentes à conta.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/conversions", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/conversions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/conversions",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/conversions/deposit-address
Credenciais
Escopo: cashin Produto: crypto MAINTENANCE Rota reservada para o fluxo cripto para BRL. Novas vendas estão em manutenção; não a utilize até capabilities informar disponibilidade.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/conversions/deposit-address", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"asset": "USDT",
"network": "TRX"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/conversions/deposit-address');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"asset": "USDT",
"network": "TRX"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"asset": "USDT",
"network": "TRX"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/crypto/conversions/deposit-address",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"asset": "USDT",
"network": "TRX"
}
/api/v1/crypto/conversion-operations
Credenciais
Escopo: cashout Produto: crypto Lista operações de conversão pertencentes ao contexto autenticado, inclusive estados históricos.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/conversion-operations", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/conversion-operations');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/conversion-operations",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/crypto/conversions/quote
Credenciais
Escopo: cashout Produto: crypto Cria uma cotação executável FIAT_TO_CRYPTO somente quando capabilities liberar o ativo e a rede. O destino externo é obrigatório. CRYPTO_TO_FIAT está em manutenção e não faz parte deste request nesta versão.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/conversions/quote", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"direction": "FIAT_TO_CRYPTO",
"asset": "USDT",
"network": "TRX",
"brl_amount_minor": "10000",
"destination_address": "SUBSTITUA_PELO_ENDERECO_TRC20"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/conversions/quote');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"direction": "FIAT_TO_CRYPTO",
"asset": "USDT",
"network": "TRX",
"brl_amount_minor": "10000",
"destination_address": "SUBSTITUA_PELO_ENDERECO_TRC20"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"direction": "FIAT_TO_CRYPTO",
"asset": "USDT",
"network": "TRX",
"brl_amount_minor": "10000",
"destination_address": "SUBSTITUA_PELO_ENDERECO_TRC20"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/crypto/conversions/quote",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"direction": "FIAT_TO_CRYPTO",
"asset": "USDT",
"network": "TRX",
"brl_amount_minor": "10000",
"destination_address": "SUBSTITUA_PELO_ENDERECO_TRC20"
}
/api/v1/crypto/conversions/{conversionId}/confirm
Credenciais
Escopo: cashout Produto: crypto Confirma uma cotação FIAT_TO_CRYPTO ainda válida. A resposta 202 indica apenas admissão e exige acompanhamento até estado terminal.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/conversions/SUBSTITUA_PELO_CONVERSION_ID/confirm", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/conversions/SUBSTITUA_PELO_CONVERSION_ID/confirm');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/crypto/conversions/SUBSTITUA_PELO_CONVERSION_ID/confirm",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/crypto/conversions/{conversionId}
Credenciais
Escopo: cashout Produto: crypto Consulta o estado auditável da conversão.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/crypto/conversions/SUBSTITUA_PELO_CONVERSION_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/crypto/conversions/SUBSTITUA_PELO_CONVERSION_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/crypto/conversions/SUBSTITUA_PELO_CONVERSION_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
Cobrança direta por cartão tokenizado, além de capacidades, emissão, consulta, recarga, transações, controle, visualização segura e webhook OTP de cartões virtuais para contas autorizadas.

/api/v1/cards/products
Credenciais
Escopo: cards.read Produto: virtual.cards Retorna o catálogo técnico de tipos de cartão reconhecidos pela VexusPay; a presença de um produto não autoriza emissão. Consulte /api/v1/cards/capabilities imediatamente antes da ação e só emita quando actions.issue=true. O catálogo é dinâmico e códigos técnicos do emissor não são expostos.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/products", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/products');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/cards/products",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards/rates
Credenciais
Escopo: cards.read Produto: virtual.cards Retorna as taxas comerciais efetivas da conta para emissão, recarga e processamento, com origem GLOBAL, PLAN ou USER. As taxas são dinâmicas: consulte antes de iniciar uma operação. A taxa do emissor é informada somente quando a emissão ou recarga for confirmada.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/rates", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/rates');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/cards/rates",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards/capabilities
Somente produção Credenciais
Escopo: cards.read Produto: virtual.cards PUBLISHED_PRODUCTION_ONLY Retorna as ações efetivamente disponíveis para a conta neste momento e informa se X-Vexus-External-User-Id é obrigatório. Consulte imediatamente antes de exibir ou iniciar uma ação; não prometa emissão, recarga ou controle quando a ação correspondente estiver false. O pool de liquidação não possui consulta pública separada e sua indisponibilidade mantém a emissão bloqueada.
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/capabilities", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/capabilities');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/cards/capabilities",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards
Credenciais
Escopo: cards.read Produto: virtual.cards Lista somente os cartões do usuário externo informado quando external_user_header_required=true, com saldo, status, bandeira e últimos quatro dígitos. Não retorna PAN, CVV nem OTP.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'X-Vexus-External-User-Id: witevexus:user:1001',
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'X-Vexus-External-User-Id': 'witevexus:user:1001',
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/cards",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards
Credenciais
Escopo: cards.write Produto: virtual.cards Emite um cartão VexusPay somente quando products e capabilities liberarem a ação. A emissão é financeira e exige Idempotency-Key. O cartão pré-pago em USD é financiado pela tesouraria compartilhada do emissor, abastecida em USDT; não existe débito ou conversão automática da carteira Vexus Crypto do usuário final nem operação atômica cripto para cartão. A White Label deve reservar e debitar seu próprio ledger separadamente. O intervalo técnico atual é de USD 10.00 a USD 1000000.00, sem substituir os limites de risco próprios da White Label. Quando exigido, external_user_id no corpo deve coincidir com X-Vexus-External-User-Id. Não repita com uma nova chave após resposta ambígua.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"product_code": "vexus_international",
"amount": "10.00",
"name_on_card": "CLIENTE EXEMPLO",
"external_user_id": "witevexus:user:1001"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"product_code": "vexus_international",
"amount": "10.00",
"name_on_card": "CLIENTE EXEMPLO",
"external_user_id": "witevexus:user:1001"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"product_code": "vexus_international",
"amount": "10.00",
"name_on_card": "CLIENTE EXEMPLO",
"external_user_id": "witevexus:user:1001"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/cards",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"product_code": "vexus_international",
"amount": "10.00",
"name_on_card": "CLIENTE EXEMPLO",
"external_user_id": "witevexus:user:1001"
}
/api/v1/cards/{cardId}
Credenciais
Escopo: cards.read Produto: virtual.cards Sincroniza saldo e status atuais para o usuário externo autenticado. Não retorna PAN, CVV nem OTP.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'X-Vexus-External-User-Id: witevexus:user:1001',
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'X-Vexus-External-User-Id': 'witevexus:user:1001',
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards/{cardId}
Credenciais
Escopo: cards.write Produto: virtual.cards Cancela permanentemente um cartão somente quando capabilities.actions.cancel=true. A ação pode devolver saldo conforme regras do cartão e exige Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID", {
method: 'DELETE',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'DELETE',
"https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/cards/{cardId}/fund
Credenciais
Escopo: cards.write Produto: virtual.cards Adiciona saldo somente quando capabilities.actions.fund=true. A recarga pré-paga em USD usa a tesouraria compartilhada do emissor, abastecida em USDT, e não debita nem converte automaticamente a carteira Vexus Crypto do usuário final. A White Label deve reservar e debitar seu próprio ledger separadamente. Exige Idempotency-Key, aceita atualmente de USD 10.00 a USD 1000000.00 e retorna as taxas confirmadas.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/fund", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": "10.00"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/fund');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": "10.00"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": "10.00"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/fund",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": "10.00"
}
/api/v1/cards/{cardId}/freeze
Credenciais
Escopo: cards.write Produto: virtual.cards Suspende temporariamente um cartão ativo somente quando capabilities.actions.freeze=true. Exige Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/freeze", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/freeze');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/freeze",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/cards/{cardId}/unfreeze
Credenciais
Escopo: cards.write Produto: virtual.cards Reativa um cartão congelado somente quando capabilities.actions.unfreeze=true. Exige Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/unfreeze", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/unfreeze');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/unfreeze",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/cards/{cardId}/transactions
Credenciais
Escopo: cards.read Produto: virtual.cards Retorna um snapshot de transações e saldo para exibição e conciliação auxiliar. O contrato do emissor não define identificador estável, paginação, webhook ou correlação completa do ciclo de autorização, captura, estorno, reembolso e chargeback; não use esta resposta como fonte contábil. Códigos OTP, PAN e CVV nunca são retornados.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/transactions", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/transactions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'X-Vexus-External-User-Id: witevexus:user:1001',
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'X-Vexus-External-User-Id': 'witevexus:user:1001',
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/transactions",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards/{cardId}/display-sessions
Credenciais
Escopo: cards.write Produto: virtual.cards Cria uma URL HTTPS de uso único, válida por 120 segundos, para exibir PAN e CVV diretamente no navegador do usuário. O backend da integração nunca recebe esses dados. Abra display_url diretamente em um iframe cuja origem coincida exatamente com allowed_origin; recarregar ou reutilizar a URL falha. Não faça proxy, fetch, captura, persistência ou log da URL. Quando exigido, X-Vexus-External-User-Id identifica o titular e external_user_id no corpo, se enviado, deve coincidir. Uma nova visualização exige nova Idempotency-Key; a recuperação não reexibe display_url e, após a expiração, crie outra sessão com outra chave.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/display-sessions", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
},
body: JSON.stringify({
"allowed_origin": "https://witevexus.fun",
"external_user_id": "witevexus:user:1001"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/display-sessions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'X-Vexus-External-User-Id: witevexus:user:1001',
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"allowed_origin": "https://witevexus.fun",
"external_user_id": "witevexus:user:1001"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"allowed_origin": "https://witevexus.fun",
"external_user_id": "witevexus:user:1001"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/cards/SUBSTITUA_PELO_CARD_ID/display-sessions",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"allowed_origin": "https://witevexus.fun",
"external_user_id": "witevexus:user:1001"
}
/api/v1/cards/webhooks
Credenciais
Escopo: cards.read Produto: virtual.cards Lista somente os endpoints exclusivos da conta inscritos apenas em virtual_card.otp.received. Endpoints mistos de outros produtos não são administráveis pelo escopo de cartões. O segredo nunca é retornado.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/webhooks", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/webhooks');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/cards/webhooks",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/cards/webhooks
Credenciais
Escopo: cards.write Produto: virtual.cards Cria um endpoint HTTPS para receber o único evento público de cartão, virtual_card.otp.received. O signing_secret aparece somente nesta resposta; armazene-o no cofre do backend. O evento usa createdAt em RFC 3339 UTC e assinatura HMAC sobre o corpo bruto. Exige Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/cards/webhooks", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"label": "OTP produção",
"url": "https://api.exemplo.com/webhooks/vexus"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/cards/webhooks');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"label": "OTP produção",
"url": "https://api.exemplo.com/webhooks/vexus"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"label": "OTP produção",
"url": "https://api.exemplo.com/webhooks/vexus"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/cards/webhooks",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"label": "OTP produção",
"url": "https://api.exemplo.com/webhooks/vexus"
}
/api/v1/cards/webhooks/{webhookId}/rotate-secret
Somente produção Credenciais
Escopo: cards.write Produto: virtual.cards PUBLISHED_PRODUCTION_ONLY Revoga imediatamente o segredo anterior, sem janela de sobreposição, e retorna o novo signing_secret uma única vez. Atualize o receptor de forma coordenada. Envie um objeto JSON vazio e Idempotency-Key. A recuperação posterior não reexibe o segredo.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/rotate-secret", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/rotate-secret');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/rotate-secret",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/cards/webhooks/{webhookId}/activate
Somente produção Credenciais
Escopo: cards.write Produto: virtual.cards PUBLISHED_PRODUCTION_ONLY Reativa novas entregas de virtual_card.otp.received para um endpoint da conta. Envie um objeto JSON vazio e Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/activate", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/activate');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/activate",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/cards/webhooks/{webhookId}/deactivate
Somente produção Credenciais
Escopo: cards.write Produto: virtual.cards PUBLISHED_PRODUCTION_ONLY Pausa novas entregas de virtual_card.otp.received sem apagar o histórico. Envie um objeto JSON vazio e Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/cards/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/deactivate", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/cards/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/deactivate');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/cards/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/deactivate",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
Consulta autorizada de saldo, limites financeiros efetivos, taxas e recuperação idempotente de operações.
/api/v1/account/limits
Credenciais
Escopo: account.read Produto: account Retorna os limites financeiros efetivos da conta em BRL: agregado, PIX de entrada e saída, boleto e transferência interna. O campo source informa se a regra vem da política GLOBAL ou de uma personalização USER.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/account/limits", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/account/limits');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/account/limits",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/account/fees
Credenciais
Escopo: account.read Produto: account Retorna taxas comerciais efetivas para PIX, boleto, cartão, cartão virtual, transferência interna e regras por ativo/rede cripto. Em cripto, a cotação da operação é autoritativa para custos de rede, taxa de serviço, valor líquido e débito total.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/account/fees", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/account/fees');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/account/fees",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/account/operations/by-idempotency/{idempotencyKey}
Somente produção Credenciais
Escopo: account.read Produto: DYNAMIC_FROM_ORIGINAL_OPERATION PUBLISHED_PRODUCTION_ONLY Recupera de forma sanitizada o estado da intenção criada pela mesma credencial de produção. Exige account.read e valida dinamicamente, na conta proprietária da credencial, o produto e os entitlements da operação original; o custody subject delimita somente a propriedade do recurso e não possui contrato independente. Use após timeout, queda de conexão ou OPERATION_STATUS_AMBIGUOUS. Em cripto, PENDING recente ainda está em curso e, depois de 60 segundos, é promovido de forma conservadora para AMBIGUOUS com reconciliation_required=true. Ao receber ACCEPTED, pare o polling desta rota: wallet.create, withdrawal.quote, swap.quote, conversion.address e conversion.quote encerram a própria intenção com terminal=true; withdrawal.execute e swap.execute devem ser acompanhados pelo GET do resource_id até o lifecycle terminal. Persista o conversionId antes de POST /conversions/{conversionId}/confirm, pois a recuperação da confirmação pode retornar ACCEPTED sem resource_id; use o GET da conversão original. ACCEPTED nunca comprova liquidação nem autoriza uma nova intenção financeira. Codifique o segmento da chave conforme RFC 3986; por exemplo, `:` vira `%3A`. Para cripto, repita o contexto X-Vexus-Custody-Subject ou CENTRAL; para cartão da WiteVexus, repita X-Vexus-External-User-Id. A recuperação de display e webhook não reexibe display_url nem signing_secret. Se a criação de webhook for confirmada sem que o segredo tenha sido recebido, rotacione-o antes do uso; rotação ambígua permanece REVIEW e exige reconciliação. O replay do POST original com método, URL, corpo e chave idênticos conserva a resposta por 24 horas; depois que display_url expirar, crie outra sessão com outra chave.
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/operations/by-idempotency/SUBSTITUA_PELO_IDEMPOTENCY_KEY", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'X-Vexus-External-User-Id': 'witevexus:user:1001',
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/account/operations/by-idempotency/SUBSTITUA_PELO_IDEMPOTENCY_KEY');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'X-Vexus-External-User-Id: witevexus:user:1001',
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'X-Vexus-External-User-Id': 'witevexus:user:1001',
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/account/operations/by-idempotency/SUBSTITUA_PELO_IDEMPOTENCY_KEY",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/account/ted
Somente produção Credenciais
Escopo: account.read Produto: account PUBLISHED_PRODUCTION_ONLY Consulta agência, conta, dígito, instituição e titular da conta TED vinculada ao usuário nominal. A consulta é somente leitura e nunca expõe credenciais do provedor.
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/ted", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/account/ted');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/account/ted",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/account/balance
Somente produção Credenciais
Escopo: account.read Produto: account PUBLISHED_PRODUCTION_ONLY Consulta o saldo BRL da conta nominal no provedor bancário homologado. A resposta é somente leitura e é isolada pelo usuário autenticado.
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/balance", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/account/balance');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/account/balance",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/account/transactions
Somente produção Credenciais
Escopo: account.read Produto: account PUBLISHED_PRODUCTION_ONLY Consulta o extrato da conta nominal em um período de até 31 dias, com paginação. Depósitos, saídas e demais tipos retornados permanecem separados por titular.
const response = await fetch("https://api.nodexhub.com.br/api/v1/account/transactions", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/account/transactions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/account/transactions",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal
Somente produção Credenciais
Escopo: account.read Produto: account PUBLISHED_PRODUCTION_ONLY Retorna a conta nominal ativa e a chave Pix vinculada ao usuário autenticado. Credenciais do provedor nunca são expostas.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/ted
Somente produção Credenciais
Escopo: account.read Produto: account PUBLISHED_PRODUCTION_ONLY Consulta agência, conta, dígito e instituição da conta nominal.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/ted", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/ted');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal/ted",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/balance
Somente produção Credenciais
Escopo: account.read Produto: account PUBLISHED_PRODUCTION_ONLY Consulta o saldo BRL da conta nominal do usuário autenticado.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/balance", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/balance');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal/balance",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/transactions
Somente produção Credenciais
Escopo: account.read Produto: account PUBLISHED_PRODUCTION_ONLY Consulta depósitos, saídas e demais movimentações da conta nominal em até 31 dias.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/transactions", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/transactions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal/transactions",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/pix-key
Somente produção Credenciais
Escopo: account.read Produto: account PUBLISHED_PRODUCTION_ONLY Retorna a chave Pix nominal já provisionada.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/pix-key", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/pix-key');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal/pix-key",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/operations/{operationId}
Somente produção Credenciais
Escopo: account.read Produto: account PUBLISHED_PRODUCTION_ONLY Consulta o resultado idempotente de uma operação QR ou saída Pix nominal.
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/operations/SUBSTITUA_PELO_OPERATION_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/operations/SUBSTITUA_PELO_OPERATION_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/nominal/operations/SUBSTITUA_PELO_OPERATION_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/balance
Credenciais
Escopo: cashin Produto: pix.cash_in Consulta o saldo exposto pelo contrato da conta. Envie um objeto JSON vazio.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/balance", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/balance');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/balance",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/nominal/pix-key
Somente produção Credenciais
Escopo: pix.cash_in Produto: pix.cash_in PUBLISHED_PRODUCTION_ONLY Solicita uma conta virtual no provedor bancário homologado com chave aleatória, e-mail ou CNPJ. Exige Idempotency-Key e só funciona após a aprovação administrativa do pedido nominal.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/pix-key", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/pix-key');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/pix-key",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/qr/dynamic
Somente produção Credenciais
Escopo: pix.cash_in Produto: pix.cash_in PUBLISHED_PRODUCTION_ONLY Cria uma cobrança QR dinâmica na conta nominal. Exige Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/dynamic", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/qr/dynamic');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/qr/dynamic",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/qr/static
Somente produção Credenciais
Escopo: pix.cash_in Produto: pix.cash_in PUBLISHED_PRODUCTION_ONLY Cria um QR estático na conta nominal. Exige Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/static", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/qr/static');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/qr/static",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/qr/decode
Somente produção Credenciais
Escopo: pix.qr_pay Produto: pix.qr_pay PUBLISHED_PRODUCTION_ONLY Lê e valida um QR Pix no provedor bancário homologado sem executar pagamento.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/decode", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/qr/decode');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/qr/decode",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/qr/pay
Somente produção Credenciais
Escopo: pix.qr_pay Produto: pix.qr_pay PUBLISHED_PRODUCTION_ONLY Paga um QR Pix pela conta nominal. A operação é assíncrona e exige Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/qr/pay", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/qr/pay');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/qr/pay",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/nominal/pix-out
Somente produção Credenciais
Escopo: pix.cash_out Produto: pix.cash_out PUBLISHED_PRODUCTION_ONLY Envia Pix pela conta nominal. A confirmação é recebida por webhook e exige Idempotency-Key.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/nominal/pix-out", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/nominal/pix-out');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/nominal/pix-out",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
Contrato White Label da própria conta: plano, adicionais, taxas, cobrança e situação de acesso.
/api/v1/white-label
Credenciais
Escopo: account.read Produto: white_label Retorna, em uma única resposta, a situação do contrato, plano, adicionais, cobrança, taxas e produtos efetivamente habilitados. Esta consulta permanece acessível mesmo quando a mensalidade estiver vencida.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/white-label", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/white-label');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/white-label",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/plan
Credenciais
Escopo: account.read Produto: white_label Retorna o plano e os adicionais contratados pela conta autenticada.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/white-label/plan", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/white-label/plan');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/white-label/plan",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/fees
Credenciais
Escopo: account.read Produto: white_label Retorna as taxas comerciais do plano, incluindo PIX, boleto, cartão virtual e regras por ativo/rede cripto.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/white-label/fees", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/white-label/fees');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/white-label/fees",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/billing
Credenciais
Escopo: account.read Produto: white_label Retorna mensalidade, entrada, valor pendente, vencimento e situação de acesso. Não cria cobrança nem movimenta saldo.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/white-label/billing", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/white-label/billing');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/white-label/billing",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/status
Credenciais
Escopo: account.read Produto: white_label Retorna somente a situação do contrato e se operações financeiras pela API estão liberadas.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/white-label/status", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/white-label/status');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/white-label/status",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/nominal
Somente produção Credenciais
Escopo: account.read Produto: white_label Lista somente os pedidos da White Label titular. Documento aparece mascarado e os dados de identidade vêm da VexusPay central.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/white-label/nominal", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/white-label/nominal');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/white-label/nominal",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/nominal
Somente produção Credenciais
Escopo: account.read Produto: white_label Envia o pedido para análise administrativa. Nome, CPF ou CNPJ não são aceitos no corpo: a VexusPay usa exclusivamente o KYC já aprovado do titular.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/white-label/nominal", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"reason": "Conta operacional da minha marca para recebimentos PIX."
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/white-label/nominal');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"reason": "Conta operacional da minha marca para recebimentos PIX."
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"reason": "Conta operacional da minha marca para recebimentos PIX."
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/white-label/nominal",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"reason": "Conta operacional da minha marca para recebimentos PIX."
}
/api/v1/white-label/nominal/bind
Somente produção Credenciais
Escopo: account.read Produto: white_label Vincula o identificador do cliente na White Label à conta nominal Vexus já ativa. O identificador é isolado por White Label.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/white-label/nominal/bind", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"nominal_user_id": 1001,
"external_subject": "cliente:1001"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/white-label/nominal/bind');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"nominal_user_id": 1001,
"external_subject": "cliente:1001"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"nominal_user_id": 1001,
"external_subject": "cliente:1001"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/white-label/nominal/bind",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"nominal_user_id": 1001,
"external_subject": "cliente:1001"
}
/api/v1/white-label/nominal/{requestId}
Somente produção Credenciais
Escopo: account.read Produto: white_label Consulta um pedido pertencente à White Label titular, sem retornar documento completo nem credenciais da conta.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/white-label/nominal/SUBSTITUA_PELO_REQUEST_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/white-label/nominal/SUBSTITUA_PELO_REQUEST_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/white-label/nominal/SUBSTITUA_PELO_REQUEST_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/white-label/nominal/{requestId}
Somente produção Credenciais
Escopo: account.read Produto: white_label Cancela um pedido ainda pendente ou aprovado. Uma conta já provisionada não pode ser cancelada por esta rota.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/white-label/nominal/SUBSTITUA_PELO_REQUEST_ID", {
method: 'DELETE',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/white-label/nominal/SUBSTITUA_PELO_REQUEST_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'DELETE',
"https://sandbox-api.example.invalid/api/v1/white-label/nominal/SUBSTITUA_PELO_REQUEST_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
Central de tickets e webhooks assinados para qualquer conta ativa autenticada. Disponível somente em produção.
/api/v1/support/tickets
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Lista até os 100 tickets mais recentes da conta titular da credencial, ordenados pela última atualização. Não retorna tickets de outras contas nem o conteúdo das mensagens.
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/tickets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/support/tickets",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/support/tickets
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Abre um ticket na fila da VexusPay para a conta autenticada. Envie texto, até quatro attachment_ids previamente gerados, ou ambos; nunca envie HTML, bytes/base64 nem credenciais no JSON.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"category": "IMPLEMENTATION",
"subject": "Dúvida na integração PIX",
"message": "Precisamos validar o tratamento do retorno assíncrono da nossa integração.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/tickets');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"category": "IMPLEMENTATION",
"subject": "Dúvida na integração PIX",
"message": "Precisamos validar o tratamento do retorno assíncrono da nossa integração.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"category": "IMPLEMENTATION",
"subject": "Dúvida na integração PIX",
"message": "Precisamos validar o tratamento do retorno assíncrono da nossa integração.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/tickets",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"category": "IMPLEMENTATION",
"subject": "Dúvida na integração PIX",
"message": "Precisamos validar o tratamento do retorno assíncrono da nossa integração.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
/api/v1/support/tickets/{ticketId}
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Retorna o ticket e a conversa cronológica quando o ticket pertence à conta titular da credencial.
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets/SUBSTITUA_PELO_TICKET_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/tickets/SUBSTITUA_PELO_TICKET_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/support/tickets/SUBSTITUA_PELO_TICKET_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/support/tickets/{ticketId}/messages
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Adiciona texto, até quatro attachment_ids previamente gerados, ou ambos ao ticket da própria conta. Ao responder, o ticket volta para OPEN. Tickets CLOSED não aceitam novas mensagens.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets/SUBSTITUA_PELO_TICKET_ID/messages", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"message": "Aplicamos o ajuste e enviamos um novo correlation ID para análise.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/tickets/SUBSTITUA_PELO_TICKET_ID/messages');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"message": "Aplicamos o ajuste e enviamos um novo correlation ID para análise.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"message": "Aplicamos o ajuste e enviamos um novo correlation ID para análise.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/tickets/SUBSTITUA_PELO_TICKET_ID/messages",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"message": "Aplicamos o ajuste e enviamos um novo correlation ID para análise.",
"attachment_ids": [
"d6c53708-95f6-46f2-8bf7-2c4cdd4ccade"
]
}
/api/v1/support/tickets/{ticketId}/close
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Confirma o encerramento do ticket da própria conta. Envie um objeto JSON vazio e preserve a Idempotency-Key caso precise repetir a solicitação.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/tickets/SUBSTITUA_PELO_TICKET_ID/close", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/tickets/SUBSTITUA_PELO_TICKET_ID/close');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/tickets/SUBSTITUA_PELO_TICKET_ID/close",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/support/attachments
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Recebe uma única imagem no campo multipart file, valida o MIME real, normaliza o bitmap e retorna um attachment_id pendente. Aceita JPEG, PNG ou WebP de até 5 MiB; o ID expira em 24 horas se não for vinculado a uma mensagem.
Idempotency-Key.import crypto from 'node:crypto';
import { readFile } from 'node:fs/promises';
const idempotencyKey = crypto.randomUUID();
const image = await readFile('/caminho/para/evidencia.png');
const form = new FormData();
form.append('file', new Blob([image], { type: 'image/png' }), 'evidencia.png');
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/attachments", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
},
body: form,
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/attachments');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
],
CURLOPT_POSTFIELDS => ['file' => new CURLFile('/caminho/para/evidencia.png', 'image/png', 'evidencia.png')],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
}
image_file = open('/caminho/para/evidencia.png', 'rb')
files = {'file': ('evidencia.png', image_file, 'image/png')}
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/attachments",
headers=headers,
files=files,
timeout=30,
)
image_file.close()
response.raise_for_status()
print(response.json())
/api/v1/support/attachments/{attachmentId}
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Retorna o binário privado de uma imagem pertencente à conta. O download exige credenciais em cada chamada, usa Cache-Control: no-store e deve ser intermediado pelo backend da integração; nunca exponha o Client Secret ao navegador.
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/attachments/SUBSTITUA_PELO_ATTACHMENT_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
const imageBytes = Buffer.from(await response.arrayBuffer());
console.log(response.headers.get('content-type'), imageBytes.length);
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/attachments/SUBSTITUA_PELO_ATTACHMENT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
file_put_contents('/caminho/para/anexo-suporte', $response);
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/support/attachments/SUBSTITUA_PELO_ATTACHMENT_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
with open('./anexo-suporte', 'wb') as output:
output.write(response.content)
/api/v1/support/webhooks
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Lista os endpoints da própria conta inscritos em eventos de suporte. A URL é mascarada para a origem HTTPS e o segredo de assinatura nunca é reexibido.
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/webhooks');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://api.nodexhub.com.br/api/v1/support/webhooks",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/support/webhooks
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Cria um endpoint HTTPS para receber eventos de suporte. O signing_secret aparece somente nesta resposta; armazene-o imediatamente em um cofre. Se events for omitido, os cinco eventos são assinados.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"label": "Suporte produção",
"url": "https://api.exemplo.com/webhooks/vexus/support",
"events": [
"support.message.created",
"support.ticket.status_changed",
"support.ticket.closed"
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/webhooks');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"label": "Suporte produção",
"url": "https://api.exemplo.com/webhooks/vexus/support",
"events": [
"support.message.created",
"support.ticket.status_changed",
"support.ticket.closed"
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"label": "Suporte produção",
"url": "https://api.exemplo.com/webhooks/vexus/support",
"events": [
"support.message.created",
"support.ticket.status_changed",
"support.ticket.closed"
]
}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/webhooks",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"label": "Suporte produção",
"url": "https://api.exemplo.com/webhooks/vexus/support",
"events": [
"support.message.created",
"support.ticket.status_changed",
"support.ticket.closed"
]
}
/api/v1/support/webhooks/{webhookId}/rotate-secret
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Invalida o segredo anterior e retorna o novo signing_secret uma única vez. Envie um objeto JSON vazio e atualize o receptor antes de depender de novas entregas.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/rotate-secret", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/rotate-secret');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/rotate-secret",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/support/webhooks/{webhookId}/activate
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Reativa um endpoint da própria conta e limpa o circuito de falhas. Envie um objeto JSON vazio.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/activate", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/activate');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/activate",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
/api/v1/support/webhooks/{webhookId}/deactivate
Somente produção Credenciais
Escopo: support.manage Produto: support Somente produção. Suspende novas entregas ao endpoint sem excluir o histórico. Envie um objeto JSON vazio.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://api.nodexhub.com.br/api/v1/support/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/deactivate", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://api.nodexhub.com.br/api/v1/support/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/deactivate');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://api.nodexhub.com.br/api/v1/support/webhooks/SUBSTITUA_PELO_WEBHOOK_ID/deactivate",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}
Regras, execução, consulta, cancelamento, devolução e relatório de Split Payment.

/api/v1/splits/rules
Credenciais
Escopo: split Produto: split Lista as regras pertencentes à conta autenticada.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/splits/rules", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/splits/rules');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/splits/rules",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/splits/rules
Credenciais
Escopo: split Produto: split Cria uma regra versionada por percentuais ou valores fixos.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/splits/rules", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"name": "Parceiros",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "conta-parceira",
"percentage": "20.00"
}
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/splits/rules');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"name": "Parceiros",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "conta-parceira",
"percentage": "20.00"
}
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"name": "Parceiros",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "conta-parceira",
"percentage": "20.00"
}
]
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/splits/rules",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"name": "Parceiros",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "conta-parceira",
"percentage": "20.00"
}
]
}
/api/v1/splits/rules/{ruleId}
Credenciais
Escopo: split Produto: split Arquiva a versão anterior e cria uma nova versão da regra.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/splits/rules/SUBSTITUA_PELO_RULE_ID", {
method: 'PUT',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"name": "Parceiros v2",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "conta-parceira",
"percentage": "25.00"
}
]
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/splits/rules/SUBSTITUA_PELO_RULE_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'PUT',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"name": "Parceiros v2",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "conta-parceira",
"percentage": "25.00"
}
]
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"name": "Parceiros v2",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "conta-parceira",
"percentage": "25.00"
}
]
}
''')
response = requests.request(
'PUT',
"https://sandbox-api.example.invalid/api/v1/splits/rules/SUBSTITUA_PELO_RULE_ID",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"name": "Parceiros v2",
"mode": "PERCENTAGE",
"currency": "BRL",
"participants": [
{
"handle": "conta-parceira",
"percentage": "25.00"
}
]
}
/api/v1/splits/rules/{ruleId}
Credenciais
Escopo: split Produto: split Arquiva a regra da conta. Esta operação não aceita corpo.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/splits/rules/SUBSTITUA_PELO_RULE_ID", {
method: 'DELETE',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/splits/rules/SUBSTITUA_PELO_RULE_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'DELETE',
"https://sandbox-api.example.invalid/api/v1/splits/rules/SUBSTITUA_PELO_RULE_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/splits
Credenciais
Escopo: split Produto: split Cria a operação financeira e suas alocações a partir de uma regra ativa. Requer uma rota de liquidação Split homologada para a conta; a gestão de regras continua disponível sem essa rota.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/splits", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"rule_id": "00000000-0000-4000-8000-000000000001",
"amount": 100,
"payer": {
"name": "Cliente de Exemplo",
"document": "52998224725",
"email": "cliente@example.com"
}
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/splits');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"rule_id": "00000000-0000-4000-8000-000000000001",
"amount": 100,
"payer": {
"name": "Cliente de Exemplo",
"document": "52998224725",
"email": "cliente@example.com"
}
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"rule_id": "00000000-0000-4000-8000-000000000001",
"amount": 100,
"payer": {
"name": "Cliente de Exemplo",
"document": "52998224725",
"email": "cliente@example.com"
}
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/splits",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"rule_id": "00000000-0000-4000-8000-000000000001",
"amount": 100,
"payer": {
"name": "Cliente de Exemplo",
"document": "52998224725",
"email": "cliente@example.com"
}
}
/api/v1/splits/{splitId}
Credenciais
Escopo: split Produto: split Retorna a operação e as alocações visíveis à conta proprietária.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/splits/SUBSTITUA_PELO_SPLIT_ID", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/splits/SUBSTITUA_PELO_SPLIT_ID');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/splits/SUBSTITUA_PELO_SPLIT_ID",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/splits/{splitId}/cancel
Credenciais
Escopo: split Produto: split Cancela um split somente quando o estado financeiro permitir. Não aceita corpo.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/splits/SUBSTITUA_PELO_SPLIT_ID/cancel", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/splits/SUBSTITUA_PELO_SPLIT_ID/cancel');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/splits/SUBSTITUA_PELO_SPLIT_ID/cancel",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/splits/{splitId}/refund
Credenciais
Escopo: split Produto: split Solicita devolução parcial ou total; uma resposta 202 indica processamento assíncrono.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/splits/SUBSTITUA_PELO_SPLIT_ID/refund", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": 25,
"comment": "Devolução parcial solicitada pelo cliente"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/splits/SUBSTITUA_PELO_SPLIT_ID/refund');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": 25,
"comment": "Devolução parcial solicitada pelo cliente"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": 25,
"comment": "Devolução parcial solicitada pelo cliente"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/splits/SUBSTITUA_PELO_SPLIT_ID/refund",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": 25,
"comment": "Devolução parcial solicitada pelo cliente"
}
/api/v1/splits/report
Credenciais
Escopo: split Produto: split Retorna itens da conta autenticada no intervalo UTC informado.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/splits/report", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/splits/report');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/splits/report",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
Controles extras exclusivos do Sandbox para simular estados sem movimentar valores reais.
/api/v1/sandbox/workspace
Credenciais
Escopo: sandbox.manage Mostra apenas saldos e recursos fictícios da conta autenticada.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/workspace", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/workspace');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/sandbox/workspace",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/sandbox/faucet
Credenciais
Escopo: sandbox.manage Credita um ativo fictício no ledger isolado do Sandbox.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/faucet", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"asset": "USDT_BEP20",
"amount": "25.00"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/faucet');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"asset": "USDT_BEP20",
"amount": "25.00"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"asset": "USDT_BEP20",
"amount": "25.00"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/faucet",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"asset": "USDT_BEP20",
"amount": "25.00"
}
/api/v1/sandbox/reset
Credenciais
Escopo: sandbox.manage Apaga somente recursos Sandbox da conta e recria o saldo inicial fictício.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/reset", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"confirmation": "RESET_SANDBOX"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/reset');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"confirmation": "RESET_SANDBOX"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"confirmation": "RESET_SANDBOX"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/reset",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"confirmation": "RESET_SANDBOX"
}
/api/v1/sandbox/resources/{resourceType}/{resourceId}/actions
Credenciais
Escopo: sandbox.manage Aprova, falha, expira ou reverte uma operação pendente fictícia.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/resources/SUBSTITUA_PELO_RESOURCE_TYPE/SUBSTITUA_PELO_RESOURCE_ID/actions", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"action": "APPROVE"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/resources/SUBSTITUA_PELO_RESOURCE_TYPE/SUBSTITUA_PELO_RESOURCE_ID/actions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"action": "APPROVE"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"action": "APPROVE"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/resources/SUBSTITUA_PELO_RESOURCE_TYPE/SUBSTITUA_PELO_RESOURCE_ID/actions",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"action": "APPROVE"
}
/api/v1/sandbox/crypto/deposits
Credenciais
Escopo: sandbox.manage Cria um depósito fictício sem transmissão ou consulta blockchain. Use o wallet_id retornado pela criação/listagem de uma carteira Sandbox da própria conta.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/crypto/deposits", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"wallet_id": "00000000-0000-4000-8000-000000000003",
"amount": "10.00",
"confirmations": 0
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/crypto/deposits');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"wallet_id": "00000000-0000-4000-8000-000000000003",
"amount": "10.00",
"confirmations": 0
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"wallet_id": "00000000-0000-4000-8000-000000000003",
"amount": "10.00",
"confirmations": 0
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/crypto/deposits",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"wallet_id": "00000000-0000-4000-8000-000000000003",
"amount": "10.00",
"confirmations": 0
}
/api/v1/sandbox/cards/{cardId}/transactions
Credenciais
Escopo: sandbox.manage Simula aprovação, recusa, estorno ou refund de um cartão fictício.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/cards/SUBSTITUA_PELO_CARD_ID/transactions", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"amount": "12.50",
"currency": "USD",
"outcome": "APPROVED"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/cards/SUBSTITUA_PELO_CARD_ID/transactions');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"amount": "12.50",
"currency": "USD",
"outcome": "APPROVED"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"amount": "12.50",
"currency": "USD",
"outcome": "APPROVED"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/cards/SUBSTITUA_PELO_CARD_ID/transactions",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"amount": "12.50",
"currency": "USD",
"outcome": "APPROVED"
}
/api/v1/sandbox/cards/{cardId}/otp
Credenciais
Escopo: sandbox.manage Gera OTP fictício e o entrega apenas pelo pipeline de webhook Sandbox.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/cards/SUBSTITUA_PELO_CARD_ID/otp", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"wallet_type": "GOOGLE_PAY"
}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/cards/SUBSTITUA_PELO_CARD_ID/otp');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{
"wallet_type": "GOOGLE_PAY"
}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{
"wallet_type": "GOOGLE_PAY"
}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/cards/SUBSTITUA_PELO_CARD_ID/otp",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{
"wallet_type": "GOOGLE_PAY"
}
/api/v1/sandbox/webhook-deliveries
Credenciais
Escopo: sandbox.manage Lista entregas e tentativas do ambiente Sandbox.
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries", {
method: 'GET',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
},
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'GET',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
],
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
}
response = requests.request(
'GET',
"https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries",
headers=headers,
timeout=30,
)
response.raise_for_status()
print(response.json())
/api/v1/sandbox/webhook-deliveries/{deliveryId}/retry
Credenciais
Escopo: sandbox.manage Agenda novamente uma entrega Sandbox sem afetar webhooks de produção.
Idempotency-Key.import crypto from 'node:crypto';
const idempotencyKey = crypto.randomUUID();
const response = await fetch("https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries/SUBSTITUA_PELO_DELIVERY_ID/retry", {
method: 'POST',
headers: {
'Apikey': process.env.VEXUS_CLIENT_ID,
'X-Client-Secret': process.env.VEXUS_CLIENT_SECRET,
'Idempotency-Key': idempotencyKey,
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
});
if (!response.ok) throw new Error(`HTTP ${response.status}`);
console.log(await response.json());
$idempotencyKey = bin2hex(random_bytes(16));
$ch = curl_init('https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries/SUBSTITUA_PELO_DELIVERY_ID/retry');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'POST',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTPHEADER => [
'Apikey: ' . getenv('VEXUS_CLIENT_ID'),
'X-Client-Secret: ' . getenv('VEXUS_CLIENT_SECRET'),
'Idempotency-Key: ' . $idempotencyKey,
'Content-Type: application/json',
],
CURLOPT_POSTFIELDS => <<<'JSON'
{}
JSON,
]);
$response = curl_exec($ch);
$httpStatus = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($response === false) throw new RuntimeException(curl_error($ch));
curl_close($ch);
if ($httpStatus >= 400) throw new RuntimeException("HTTP {$httpStatus}");
var_dump(json_decode($response, true, 512, JSON_THROW_ON_ERROR));
import os
import requests
import json
import uuid
idempotency_key = str(uuid.uuid4())
headers = {
'Apikey': os.environ['VEXUS_CLIENT_ID'],
'X-Client-Secret': os.environ['VEXUS_CLIENT_SECRET'],
'Idempotency-Key': idempotency_key,
'Content-Type': 'application/json',
}
payload = json.loads(r'''
{}
''')
response = requests.request(
'POST',
"https://sandbox-api.example.invalid/api/v1/sandbox/webhook-deliveries/SUBSTITUA_PELO_DELIVERY_ID/retry",
headers=headers,
json=payload,
timeout=30,
)
response.raise_for_status()
print(response.json())
{}