Pular para o conteúdo principal

Core Banking API (0.40.0)

Download OpenAPI specification:Download

API Support: [email protected] License: Proprietary

Core Banking API

Administrative API for core banking operations. This API provides endpoints for partner institutions to manage accounts, balances, authentication, invoices, fee rules, and credit bankarization applications.

🔐 Authentication

All endpoints require OAuth2 Bearer Token authentication.

How to Get a Token

  1. Use the Authentication endpoint below - Click on POST /auth/token and use "Try it out"
  2. Enter your credentials:
    • client_id: Your OAuth2 client ID
    • client_secret: Your OAuth2 client secret
    • grant_type: client_credentials
  3. Copy the access_token from the response
  4. Click the "Authorize" button (🔒 icon at the top right)
  5. Paste the token in the "Value" field (without "Bearer " prefix)
  6. Click "Authorize" and then "Close"

Now all your requests will automatically include the token!

Alternative: Manual Token Usage

If you prefer to test manually, add this header to your requests:

Authorization: Bearer <your-access-token>

Development Mode

All endpoints require authentication. Make sure to obtain a valid token before making requests.

Security

Protected endpoints require mTLS plus an OAuth2 bearer token. Bankarization operations also require the scopes declared on each operation. Identity comes only from the token; public x-* identity headers are discarded.

Authentication

OAuth2 authentication endpoints for obtaining access tokens

Get authentication token

Obtain an access token using OAuth2 client credentials flow. The token can be used to authenticate subsequent API requests.

Authorizations:
bearerAuth
Request Body schema: application/json
required
client_id
required
string non-empty

Client identifier for OAuth2 authentication

client_secret
required
string non-empty

Client secret for OAuth2 authentication

grant_type
required
string
Value: "client_credentials"

OAuth2 grant type - must be client_credentials

Responses

Request samples

Content type
application/json
{
  • "client_id": "string",
  • "client_secret": "string",
  • "grant_type": "client_credentials"
}

Response samples

Content type
application/json
{
  • "access_token": "string",
  • "token_type": "Bearer",
  • "expires_in": 0
}

Account

Account management and information retrieval

List accounts

List accounts with pagination and filtering support. Use baasId to restrict the result to accounts linked to a BaaS partner. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
query Parameters
baasId
string <uuid>

BaaS identifier

page
integer > 0
Default: 1

Page number (starts at 1)

perPage
integer ( 0 .. 100 ]
Default: 10

Number of records per page (max 100)

filter
string

Generic text search filter

sortBy
string
Default: "createdAt"

Field to sort by (default: createdAt)

sortOrder
string
Default: "desc"
Enum: "asc" "desc" "ASC" "DESC"

Sort order (asc or desc, default: desc)

Responses

Response samples

Content type
application/json
{
  • "meta": {
    },
  • "data": [
    ]
}

Get account by ID

Retrieve detailed information about a specific account by ID. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
path Parameters
id
required
number > 0

Account unique identifier

Responses

Response samples

Content type
application/json
{
  • "id": "string",
  • "number": "string",
  • "type": "string",
  • "baasId": "2e4ca0ac-4c94-47cc-bb48-ebd98f366530",
  • "status": "INACTIVE",
  • "person": {
    },
  • "createdAt": "string",
  • "updatedAt": "string",
  • "closedAt": "string"
}

Create Accounts API OAuth2 credential

Creates an OAuth2 credential for the Accounts API (BancoDigitalAPI) by provisioning a client in Keycloak and persisting metadata in the database.

Authorizations:
bearerAuth
path Parameters
id
required
number > 0

Account ID

Request Body schema: application/json
required
description
required
string non-empty

Credential description

scopes
required
Array of strings non-empty
Items Enum: "pix.write" "pix.create" "pix.read" "account.read" "webhook.read" "webhook.write" "transactions.read" "billets.write" "billets.create" "billets.read" "infractions.write" "infractions.read"

Scopes to grant to this credential

allowedIps
required
Array of strings non-empty [ items^(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\... ]

List of allowed IPs/CIDR ranges (required)

Responses

Request samples

Content type
application/json
{
  • "description": "string",
  • "scopes": [
    ],
  • "allowedIps": [
    ]
}

Response samples

Content type
application/json
{
  • "clientId": "string",
  • "clientSecret": "string",
  • "id": 0,
  • "description": "string",
  • "allowedIps": [
    ]
}

Create PIX Manager credential

Creates a credential in PIX Manager API for a specific account. All data is automatically retrieved from the account.

Authorizations:
bearerAuth
path Parameters
id
required
number > 0

Account ID

Responses

Response samples

Content type
application/json
{
  • "clientId": "string",
  • "clientSecret": "string",
  • "pixKey": "string",
  • "pixKeyCreated": true
}

Update PIX Manager credential

Updates a credential in PIX Manager API for a specific account. All data is automatically retrieved from the account.

Authorizations:
bearerAuth
path Parameters
id
required
number > 0

Account ID

Responses

Response samples

Content type
application/json
{
  • "message": "string"
}

Delete PIX Manager credential

Deletes a credential from PIX Manager API for a specific account.

Authorizations:
bearerAuth
path Parameters
id
required
number > 0

Account ID

clientId
required
string non-empty

Client ID to be deleted

Responses

Response samples

Content type
application/json
{
  • "message": "string"
}

BaaS

BaaS partner listing, including the main bucket account of each partner

List BaaS partners

List BaaS partners configured for the institution. Each item includes the main bucket account used by the partner. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
query Parameters
page
integer > 0
Default: 1

Page number (starts at 1)

perPage
integer ( 0 .. 100 ]
Default: 10

Number of records per page (max 100)

filter
string

Generic text search filter

sortBy
string
Default: "createdAt"

Field to sort by (default: createdAt)

sortOrder
string
Default: "desc"
Enum: "asc" "desc" "ASC" "DESC"

Sort order (asc or desc, default: desc)

Responses

Response samples

Content type
application/json
{
  • "meta": {
    },
  • "data": [
    ]
}

Fee Rules

Automatic debit fee rules for BaaS credentials (tenant is the baas_id of the token)

List automatic debit fee rules

Lists fee rules of the authenticated BaaS partner. filter matches the rule name (case-insensitive). Account filtering is done via ACCOUNT_NUMBER requirements on each rule. Requires fee-rules.read. ACCOUNT credentials receive 403.

Authorizations:
oauth2bearerAuth
query Parameters
page
integer > 0
Default: 1

Page number (starts at 1)

perPage
integer ( 0 .. 100 ]
Default: 10

Number of records per page (max 100)

filter
string

Case-insensitive search by fee rule name

sortBy
string
Default: "createdAt"

Field to sort by (default: createdAt)

sortOrder
string
Default: "desc"
Enum: "asc" "desc" "ASC" "DESC"

Sort order (asc or desc, default: desc)

Responses

Response samples

Content type
application/json
{
  • "meta": {
    },
  • "data": [
    ]
}

Create automatic debit fee rule

Creates a fee rule for the authenticated BaaS partner. weight is assigned as max(existing)+1. Requires fee-rules.write.

Authorizations:
oauth2bearerAuth
Request Body schema: application/json
required
name
required
string non-empty

Fee rule name

percent
required
number

Percentage fee

fixedAmount
number
Default: 0

Fixed amount

minAmount
required
number

Minimum fee amount

maxAmount
required
number

Maximum fee amount

Array of objects
Default: []

Rule requirements

effectiveDate
string or null <date-time>

Optional effective date

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "percent": 0,
  • "fixedAmount": 0,
  • "minAmount": 0,
  • "maxAmount": 0,
  • "requirements": [ ],
  • "effectiveDate": "2019-08-24T14:15:22Z"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "baasId": "2e4ca0ac-4c94-47cc-bb48-ebd98f366530",
  • "name": "string",
  • "percent": 0,
  • "fixedAmount": 0,
  • "minAmount": 0,
  • "maxAmount": 0,
  • "weight": 0,
  • "effectiveDate": "2019-08-24T14:15:22Z",
  • "requirements": [
    ],
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Get automatic debit fee rule

Returns a fee rule owned by the authenticated BaaS partner. Requires fee-rules.read.

Authorizations:
oauth2bearerAuth
path Parameters
id
required
string <uuid>

Fee rule identifier

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "baasId": "2e4ca0ac-4c94-47cc-bb48-ebd98f366530",
  • "name": "string",
  • "percent": 0,
  • "fixedAmount": 0,
  • "minAmount": 0,
  • "maxAmount": 0,
  • "weight": 0,
  • "effectiveDate": "2019-08-24T14:15:22Z",
  • "requirements": [
    ],
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Update automatic debit fee rule

Updates amounts, name and weight. requirements and effectiveDate are not mutable (portal parity). Duplicate weight for the same BaaS returns 409. Requires fee-rules.write.

Authorizations:
oauth2bearerAuth
path Parameters
id
required
string <uuid>

Fee rule identifier

Request Body schema: application/json
required
name
string non-empty
weight
integer > 0
percent
required
number
fixedAmount
number
Default: 0
minAmount
required
number
maxAmount
required
number

Responses

Request samples

Content type
application/json
{
  • "name": "string",
  • "weight": 0,
  • "percent": 0,
  • "fixedAmount": 0,
  • "minAmount": 0,
  • "maxAmount": 0
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "baasId": "2e4ca0ac-4c94-47cc-bb48-ebd98f366530",
  • "name": "string",
  • "percent": 0,
  • "fixedAmount": 0,
  • "minAmount": 0,
  • "maxAmount": 0,
  • "weight": 0,
  • "effectiveDate": "2019-08-24T14:15:22Z",
  • "requirements": [
    ],
  • "createdAt": "2019-08-24T14:15:22Z",
  • "updatedAt": "2019-08-24T14:15:22Z"
}

Delete automatic debit fee rule

Hard-deletes a fee rule owned by the authenticated BaaS partner. Requires fee-rules.write.

Authorizations:
oauth2bearerAuth
path Parameters
id
required
string <uuid>

Fee rule identifier

Responses

Response samples

Content type
application/problem+json
{
  • "type": "string",
  • "title": "string",
  • "status": 0,
  • "detail": "string",
  • "instance": "string",
  • "requestId": "string"
}

Balance

Account balance queries and operations

Get account balance

Retrieve the current balance of a specific account by account ID. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
path Parameters
id
required
number > 0

Account unique identifier

Responses

Response samples

Content type
application/json
{
  • "accountId": "string",
  • "balance": {
    },
  • "currency": "string",
  • "lastUpdated": "string"
}

Invoices

Pix, boleto and hybrid (PIX_BOLETO) invoices for ACCOUNT and BaaS credentials bound to an account

Create invoice

Creates an invoice for a customer of the account. Payment method can be PIX (QR available immediately), BOLETO (local barcode immediately; invoice stays in REGISTERING until PCR confirmation) or PIX_BOLETO (hybrid). Idempotency-Key is required. Requires invoices.write.

Authorizations:
oauth2bearerAuth
path Parameters
accountId
required
integer > 0

Account unique identifier

header Parameters
Idempotency-Key
required
string [ 1 .. 160 ] characters

Idempotency key scoped by the credential (1–160 characters). Replay with the same payload returns the original invoice; a different payload returns 409.

Request Body schema: application/json
required
customerId
required
integer > 0

Invoice customer identifier

paymentMethod
string
Default: "PIX"
Enum: "PIX" "BOLETO" "PIX_BOLETO"

Payment method for the invoice

pixKey
string non-empty

Pix key for receiving (required when method includes PIX)

dueDate
required
string^\d{4}-\d{2}-\d{2}$

Invoice due date (YYYY-MM-DD)

daysToPay
integer >= 0
Default: 0

Days accepted after due date

amount
required
number > 0

Invoice amount

type
required
string
Enum: "IMMEDIATE" "SCHEDULED"

Invoice type (immediate or scheduled)

description
string <= 255 characters
emailTo
string <email> <= 255 characters
sendEmail
boolean
Default: false
object
object
object

Responses

Request samples

Content type
application/json
{
  • "customerId": 0,
  • "paymentMethod": "PIX",
  • "pixKey": "string",
  • "dueDate": "string",
  • "daysToPay": 0,
  • "amount": 0,
  • "type": "IMMEDIATE",
  • "description": "string",
  • "emailTo": "[email protected]",
  • "sendEmail": false,
  • "interest": {
    },
  • "lateFee": {
    },
  • "discount": {
    }
}

Response samples

Content type
application/json
{
  • "id": 0,
  • "txId": "string",
  • "brCode": "string",
  • "status": "string",
  • "type": "string",
  • "paymentMethod": "string",
  • "boletoBarcode": "string",
  • "boletoDigitableLine": "string",
  • "amount": 0,
  • "dueDate": "2019-08-24T14:15:22Z",
  • "description": "string"
}

List invoices

Lists invoices of the account with pagination. Requires invoices.read.

Authorizations:
oauth2bearerAuth
path Parameters
accountId
required
integer > 0

Account unique identifier

query Parameters
page
integer > 0
Default: 1

Page number (default 1)

perPage
integer ( 0 .. 100 ]
Default: 20

Items per page (default 20, max 100)

filter
string <= 255 characters

Search by invoice description or payer name

Responses

Response samples

Content type
application/json
{
  • "meta": {
    },
  • "data": [
    ]
}

Get invoice

Retrieves a single invoice of the account. Requires invoices.read.

Authorizations:
oauth2bearerAuth
path Parameters
accountId
required
integer > 0

Account unique identifier

invoiceId
required
integer > 0

Invoice unique identifier

Responses

Response samples

Content type
application/json
{
  • "id": 0,
  • "txId": "string",
  • "brCode": "string",
  • "status": "string",
  • "type": "string",
  • "paymentMethod": "string",
  • "boletoBarcode": "string",
  • "boletoDigitableLine": "string",
  • "amount": 0,
  • "dueDate": "2019-08-24T14:15:22Z",
  • "description": "string"
}

Cancel invoice

Cancels an invoice. For boleto invoices the title is also settled at the clearing house. REGISTERING invoices cannot be cancelled until PCR confirmation (422). Requires invoices.write.

Authorizations:
oauth2bearerAuth
path Parameters
accountId
required
integer > 0

Account unique identifier

invoiceId
required
integer > 0

Invoice unique identifier

Responses

Response samples

Content type
application/json
{
  • "success": true
}

Emit draft invoice

Emits a DRAFT invoice, generating the Pix charge and/or registering the boleto. Boleto emission is idempotent. Requires invoices.write.

Authorizations:
oauth2bearerAuth
path Parameters
accountId
required
integer > 0

Account unique identifier

invoiceId
required
integer > 0

Invoice unique identifier

Responses

Response samples

Content type
application/json
{
  • "id": 0,
  • "txId": "string",
  • "brCode": "string",
  • "status": "string",
  • "type": "string",
  • "paymentMethod": "string",
  • "boletoBarcode": "string",
  • "boletoDigitableLine": "string",
  • "amount": 0,
  • "dueDate": "2019-08-24T14:15:22Z",
  • "description": "string"
}

Credit Bankarization

Credit bankarization for BaaS partners (assignment in the body) and ACCOUNT credentials (assignee is the authenticated account)

List bankarization credit products

Lists ready bankarization products published for the authenticated BaaS partner or ACCOUNT assignee. Requires credit.products.read.

Authorizations:
oauth2bearerAuth

Responses

Response samples

Content type
application/json
{
  • "data": [
    ]
}

Get a bankarization credit product

Returns public operation constraints and rate ranges. BaaS partners also receive public assignees. Requires credit.products.read.

Authorizations:
oauth2bearerAuth
path Parameters
productId
required
integer >= 1

Responses

Response samples

Content type
application/json
{
  • "id": 1,
  • "name": "string",
  • "description": "string",
  • "personType": "NATURAL_PERSON",
  • "creditType": "string",
  • "minTerm": 1,
  • "maxTerm": 1,
  • "minAmount": "string",
  • "maxAmount": "string",
  • "maxGracePeriodDays": 0,
  • "allowedPeriods": [
    ],
  • "amortizationOptions": [
    ],
  • "parameters": [
    ],
  • "interestRatesRequired": true,
  • "ratePolicies": [
    ],
  • "assignees": [
    ]
}

List bankarization applications for the authenticated account

Lists applications of the ACCOUNT API channel for the authenticated account. BaaS credentials receive 403. Requires credit.bankarization.applications.read.

Authorizations:
oauth2bearerAuth
query Parameters
page
integer >= 1
Default: 1
limit
integer [ 1 .. 100 ]
Default: 25

Responses

Response samples

Content type
application/json
{
  • "data": [
    ],
  • "meta": {
    }
}

Create a bankarization application

Creates an asynchronous bankarization application. Idempotency-Key is required. BaaS partners send assignment; ACCOUNT credentials omit it and act as assignee of the bound account. Requires credit.bankarization.applications.write.

Authorizations:
oauth2bearerAuth
header Parameters
Idempotency-Key
required
string [ 1 .. 160 ] characters

Idempotency key scoped by the credential (1–160 characters)

Request Body schema: application/json
required
One of
externalRequestId
string [ 1 .. 160 ] characters
creditProductId
required
integer >= 1
required
object (BankarizationDebtor)
object (BankarizationRepresentative)
required
object (BankarizationOperation)
required
object (BankarizationAssignment)

Responses

Request samples

Content type
application/json
Example
{
  • "externalRequestId": "string",
  • "creditProductId": 1,
  • "debtor": {
    },
  • "representative": {},
  • "operation": {
    },
  • "assignment": {
    }
}

Response samples

Content type
application/json
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "externalRequestId": "string",
  • "status": "RECEIVED",
  • "nextAction": "INTERNAL_CREDIT_FLOW",
  • "error": {
    },
  • "expiresAt": "2019-08-24T14:15:22Z",
  • "retryAt": "2019-08-24T14:15:22Z",
  • "pricing": {
    },
  • "links": {
    }
}

Get a bankarization application

Returns the current public status of an application owned by the authenticated credential. Requires credit.bankarization.applications.read.

Authorizations:
oauth2bearerAuth
path Parameters
requestId
required
string <uuid>

Bankarization request identifier

Responses

Response samples

Content type
application/json
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "externalRequestId": "string",
  • "status": "RECEIVED",
  • "nextAction": "INTERNAL_CREDIT_FLOW",
  • "error": {
    },
  • "expiresAt": "2019-08-24T14:15:22Z",
  • "retryAt": "2019-08-24T14:15:22Z",
  • "pricing": {
    },
  • "links": {
    }
}

Cancel a bankarization application

Idempotent cancellation before Loan creation. Requires credit.bankarization.applications.write.

Authorizations:
oauth2bearerAuth
path Parameters
requestId
required
string <uuid>

Bankarization request identifier

Responses

Response samples

Content type
application/json
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "externalRequestId": "string",
  • "status": "RECEIVED",
  • "nextAction": "INTERNAL_CREDIT_FLOW",
  • "error": {
    },
  • "expiresAt": "2019-08-24T14:15:22Z",
  • "retryAt": "2019-08-24T14:15:22Z",
  • "pricing": {
    },
  • "links": {
    }
}

Resend a bankarization registration invitation

Idempotently resends the customer registration invitation. Does not expose invitation secrets and does not extend expiration. Requires credit.bankarization.applications.write.

Authorizations:
oauth2bearerAuth
path Parameters
requestId
required
string <uuid>

Bankarization request identifier

header Parameters
Idempotency-Key
required
string [ 1 .. 160 ] characters

Idempotency key scoped by the credential (1–160 characters)

Responses

Response samples

Content type
application/json
{
  • "requestId": "d385ab22-0f51-4b97-9ecd-b8ff3fd4fcb6",
  • "externalRequestId": "string",
  • "status": "RECEIVED",
  • "nextAction": "INTERNAL_CREDIT_FLOW",
  • "error": {
    },
  • "expiresAt": "2019-08-24T14:15:22Z",
  • "retryAt": "2019-08-24T14:15:22Z",
  • "pricing": {
    },
  • "links": {
    }
}

PIX Keys

List PIX keys for account

Retrieve all PIX keys registered in DICT (Diretório de Identificadores de Contas Transacionais) for a specific account. This endpoint queries the Brazilian Central Bank PIX directory to list all keys associated with the account. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
path Parameters
id
required
number > 0

Account unique identifier

Responses

Response samples

Content type
application/json
[
  • {
    }
]

People

List people

List people with pagination and filtering support. Use baasId to restrict the result to a BaaS partner. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
query Parameters
baasId
string <uuid>

BaaS identifier

page
integer > 0
Default: 1

Page number (starts at 1)

perPage
integer ( 0 .. 100 ]
Default: 10

Number of records per page (max 100)

filter
string

Generic text search filter

sortBy
string
Default: "createdAt"

Field to sort by (default: createdAt)

sortOrder
string
Default: "desc"
Enum: "asc" "desc" "ASC" "DESC"

Sort order (asc or desc, default: desc)

Responses

Response samples

Content type
application/json
{
  • "meta": {
    },
  • "data": [
    ]
}

Get person by ID

Retrieve detailed information about a specific person by ID. This endpoint provides person data including name, document, type, contact information, and status. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
path Parameters
id
required
number > 0

Person unique identifier

Responses

Response samples

Content type
application/json
{
  • "id": "string",
  • "name": "string",
  • "tradeName": "string",
  • "document": "string",
  • "type": "string",
  • "birthDate": "string",
  • "email": "string",
  • "baasId": "2e4ca0ac-4c94-47cc-bb48-ebd98f366530",
  • "status": "INACTIVE",
  • "createdAt": "string",
  • "updatedAt": "string",
  • "ownedAccountIds": [
    ],
  • "permittedAccountIds": [
    ]
}

Onboarding

List onboardings

List onboardings with pagination and filtering support.

Authorizations:
bearerAuth
query Parameters
page
integer > 0
Default: 1

Page number (starts at 1)

perPage
integer ( 0 .. 100 ]
Default: 10

Number of records per page (max 100)

filter
string

Generic text search filter

sortBy
string
Default: "createdAt"

Field to sort by (default: createdAt)

sortOrder
string
Default: "desc"
Enum: "asc" "desc" "ASC" "DESC"

Sort order (asc or desc, default: desc)

showIncomplete
boolean
Default: false

Responses

Response samples

Content type
application/json
{
  • "meta": {
    },
  • "data": [
    ]
}

Create onboarding

Create a new onboarding request. Returns the complete created resource.

Authorizations:
bearerAuth
Request Body schema: application/json
required
accountType
required
string
Enum: "NATURAL_PERSON" "LEGAL_PERSON" "SALARY_ACCOUNT"
companyName
string
companyTradeName
string
companyDocument
string
companyEmail
string <email>
companyPhone
string >= 8 characters
personName
required
string non-empty
personTradeName
string
personDocument
required
string non-empty
personEmail
required
string <email>
personPhone
required
string >= 8 characters
addrZipCode
required
string >= 8 characters
addrAddress
required
string non-empty
addrNumber
required
string non-empty
addrComplement
string
addrDistrict
required
string non-empty
baasId
string <uuid>
deviceId
string <uuid>
accountPassword
required
string non-empty
accountMasterPassword
required
string non-empty
onlyPerson
boolean
Default: false
isPep
boolean
Default: false

Responses

Request samples

Content type
application/json
{
  • "accountType": "NATURAL_PERSON",
  • "companyName": "string",
  • "companyTradeName": "string",
  • "companyDocument": "string",
  • "companyEmail": "[email protected]",
  • "companyPhone": "stringst",
  • "personName": "string",
  • "personTradeName": "string",
  • "personDocument": "string",
  • "personEmail": "[email protected]",
  • "personPhone": "stringst",
  • "addrZipCode": "stringst",
  • "addrAddress": "string",
  • "addrNumber": "string",
  • "addrComplement": "string",
  • "addrDistrict": "string",
  • "baasId": "2e4ca0ac-4c94-47cc-bb48-ebd98f366530",
  • "deviceId": "4de4adb9-21ee-47e3-aeb4-8cf8ed6c109a",
  • "accountPassword": "string",
  • "accountMasterPassword": "string",
  • "onlyPerson": false,
  • "isPep": false
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "accountType": "NATURAL_PERSON",
  • "status": "PENDING",
  • "company": {
    },
  • "person": {
    },
  • "address": {
    },
  • "baasId": "2e4ca0ac-4c94-47cc-bb48-ebd98f366530",
  • "deviceId": "4de4adb9-21ee-47e3-aeb4-8cf8ed6c109a",
  • "observation": "string",
  • "isPep": true,
  • "createdAt": "string",
  • "updatedAt": "string"
}

Get onboarding by ID

Retrieve detailed information about a specific onboarding by ID.

Authorizations:
bearerAuth
path Parameters
id
required
string <uuid>

Onboarding unique identifier

Responses

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "accountType": "NATURAL_PERSON",
  • "status": "PENDING",
  • "company": {
    },
  • "person": {
    },
  • "address": {
    },
  • "baasId": "2e4ca0ac-4c94-47cc-bb48-ebd98f366530",
  • "deviceId": "4de4adb9-21ee-47e3-aeb4-8cf8ed6c109a",
  • "observation": "string",
  • "isPep": true,
  • "createdAt": "string",
  • "updatedAt": "string"
}

Update onboarding

Update an existing onboarding request. Returns the complete updated resource.

Authorizations:
bearerAuth
path Parameters
id
required
string <uuid>

Onboarding unique identifier

Request Body schema: application/json
accountType
string
Enum: "NATURAL_PERSON" "LEGAL_PERSON" "SALARY_ACCOUNT"
companyName
string
companyTradeName
string
companyDocument
string
companyEmail
string <email>
companyPhone
string >= 8 characters
personName
string non-empty
personTradeName
string
personDocument
string non-empty
personEmail
string <email>
personPhone
string >= 8 characters
addrZipCode
string >= 8 characters
addrAddress
string non-empty
addrNumber
string non-empty
addrComplement
string
addrDistrict
string non-empty
baasId
string <uuid>
deviceId
string <uuid>
accountPassword
string non-empty
accountMasterPassword
string non-empty
onlyPerson
boolean
Default: false
isPep
boolean
Default: false

Responses

Request samples

Content type
application/json
{
  • "accountType": "NATURAL_PERSON",
  • "companyName": "string",
  • "companyTradeName": "string",
  • "companyDocument": "string",
  • "companyEmail": "[email protected]",
  • "companyPhone": "stringst",
  • "personName": "string",
  • "personTradeName": "string",
  • "personDocument": "string",
  • "personEmail": "[email protected]",
  • "personPhone": "stringst",
  • "addrZipCode": "stringst",
  • "addrAddress": "string",
  • "addrNumber": "string",
  • "addrComplement": "string",
  • "addrDistrict": "string",
  • "baasId": "2e4ca0ac-4c94-47cc-bb48-ebd98f366530",
  • "deviceId": "4de4adb9-21ee-47e3-aeb4-8cf8ed6c109a",
  • "accountPassword": "string",
  • "accountMasterPassword": "string",
  • "onlyPerson": false,
  • "isPep": false
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "accountType": "NATURAL_PERSON",
  • "status": "PENDING",
  • "company": {
    },
  • "person": {
    },
  • "address": {
    },
  • "baasId": "2e4ca0ac-4c94-47cc-bb48-ebd98f366530",
  • "deviceId": "4de4adb9-21ee-47e3-aeb4-8cf8ed6c109a",
  • "observation": "string",
  • "isPep": true,
  • "createdAt": "string",
  • "updatedAt": "string"
}

Approve onboarding

Approve an onboarding request and optionally create an account.

Authorizations:
bearerAuth
path Parameters
id
required
string <uuid>

Onboarding unique identifier

Request Body schema: application/json
createAccount
boolean
Default: true
planId
integer > 0
observation
string
forceAccept
boolean
Default: false

Responses

Request samples

Content type
application/json
{
  • "createAccount": true,
  • "planId": 0,
  • "observation": "string",
  • "forceAccept": false
}

Response samples

Content type
application/json
{
  • "personId": 0,
  • "accountId": 0
}

Reject onboarding

Reject an onboarding request.

Authorizations:
bearerAuth
path Parameters
id
required
string <uuid>

Onboarding unique identifier

Request Body schema: application/json
observation
string

Responses

Request samples

Content type
application/json
{
  • "observation": "string"
}

Response samples

Content type
application/json
{
  • "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  • "status": "PENDING",
  • "createdAt": "string",
  • "updatedAt": "string"
}

Get onboarding images

Get signed URLs for onboarding document images.

Authorizations:
bearerAuth
path Parameters
id
required
string <uuid>

Onboarding unique identifier

Responses

Response samples

Content type
application/json
[]

Upload onboarding image

Upload onboarding document image (front/back/selfie). Multipart is processed in banking-api and sent as FormData to Atlas.

Authorizations:
bearerAuth
path Parameters
id
required
string <uuid>

Onboarding unique identifier

Request Body schema: multipart/form-data
required
type
required
string
Enum: "FRONT" "BACK" "SELFIE"

Image type: FRONT, BACK, or SELFIE

file
any

Image file (multipart/form-data)

Responses

Response samples

Content type
application/json
{}

Transaction

Get transaction by ID

Retrieve detailed information about a specific transaction by ID. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
path Parameters
id
required
number > 0

Transaction unique identifier

Responses

Response samples

Content type
application/json
{
  • "id": "string",
  • "amount": "string",
  • "type": "string",
  • "creditDebitType": "string",
  • "paymentType": "string",
  • "payer": {
    },
  • "payee": {
    },
  • "additionalInformation": "string",
  • "status": 0,
  • "reason": "string",
  • "reference": "string",
  • "relatedAccountId": "string",
  • "actionTag": "string",
  • "createdAt": "string",
  • "updatedAt": "string"
}

List transactions

List transactions with pagination and filtering support. Use baasId or accountId to restrict the result to a BaaS partner or account, and startDate/endDate to filter by creation period. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
query Parameters
baasId
string <uuid>

BaaS identifier

accountId
integer > 0

Account identifier

startDate
required
string

Required start of creation period. Must be provided with endDate and the range cannot exceed 30 days

endDate
required
string

Required end of creation period. Must be provided with startDate and the range cannot exceed 30 days

page
integer > 0
Default: 1

Page number (starts at 1)

perPage
integer ( 0 .. 100 ]
Default: 10

Number of records per page (max 100)

filter
string

Generic text search filter

sortBy
string
Default: "createdAt"

Field to sort by (default: createdAt)

sortOrder
string
Default: "desc"
Enum: "asc" "desc" "ASC" "DESC"

Sort order (asc or desc, default: desc)

Responses

Response samples

Content type
application/json
{
  • "meta": {
    },
  • "data": [
    ]
}

Movement

Get movement by ID

Retrieve detailed information about a specific movement by ID. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
path Parameters
id
required
number > 0

Movement unique identifier

Responses

Response samples

Content type
application/json
{
  • "id": 0,
  • "accountId": 0,
  • "transactionId": 0,
  • "amount": "string",
  • "type": "CREDIT",
  • "description": "string",
  • "isRefund": true,
  • "createdAt": "string",
  • "updatedAt": "string"
}

List movements

List movements with pagination and filtering support. Use baasId or accountId to restrict the result to a BaaS partner or account, and startDate/endDate to filter by creation period. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
query Parameters
baasId
string <uuid>

BaaS identifier

accountId
integer > 0

Account identifier

startDate
required
string

Required start of creation period. Must be provided with endDate and the range cannot exceed 30 days

endDate
required
string

Required end of creation period. Must be provided with startDate and the range cannot exceed 30 days

page
integer > 0
Default: 1

Page number (starts at 1)

perPage
integer ( 0 .. 100 ]
Default: 10

Number of records per page (max 100)

filter
string

Generic text search filter

sortBy
string
Default: "createdAt"

Field to sort by (default: createdAt)

sortOrder
string
Default: "desc"
Enum: "asc" "desc" "ASC" "DESC"

Sort order (asc or desc, default: desc)

Responses

Response samples

Content type
application/json
{
  • "meta": {
    },
  • "data": [
    ]
}

Infraction

Get infraction by ID

Retrieve detailed information about a specific infraction by ID. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
path Parameters
id
required
string <uuid>

Infraction unique identifier

Responses

Response samples

Content type
application/json
{
  • "id": "string",
  • "transactionId": 0,
  • "accountId": 0,
  • "type": "string",
  • "reportedBy": "string",
  • "reportDetails": "string",
  • "status": "string",
  • "debitParticipant": 0,
  • "creditParticipant": 0,
  • "analysisResult": "string",
  • "relatedId": "string",
  • "analysisDetails": "string",
  • "internalAnalysis": "string",
  • "payerName": "string",
  • "payerDocument": "string",
  • "msgEndToEndId": "string",
  • "fraudType": "string",
  • "creationTime": "string",
  • "createdAt": "string",
  • "updatedAt": "string"
}

List infractions

List infractions with pagination and filtering support. Use baasId or accountId to restrict the result to a BaaS partner or account, and startDate/endDate to filter by creation period. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
query Parameters
baasId
string <uuid>

BaaS identifier

accountId
integer > 0

Account identifier

startDate
required
string

Required start of creation period. Must be provided with endDate and the range cannot exceed 30 days

endDate
required
string

Required end of creation period. Must be provided with startDate and the range cannot exceed 30 days

page
integer > 0
Default: 1

Page number (starts at 1)

perPage
integer ( 0 .. 100 ]
Default: 10

Number of records per page (max 100)

filter
string

Generic text search filter

sortBy
string
Default: "createdAt"

Field to sort by (default: createdAt)

sortOrder
string
Default: "desc"
Enum: "asc" "desc" "ASC" "DESC"

Sort order (asc or desc, default: desc)

Responses

Response samples

Content type
application/json
{
  • "meta": {
    },
  • "data": [
    ]
}

Refund

List refunds

List refunds with pagination and filtering support. Use baasId or accountId to restrict the result to a BaaS partner or account, and startDate/endDate to filter by creation period. This is an administrative API that requires institution authentication only.

Authorizations:
bearerAuth
query Parameters
baasId
string <uuid>

BaaS identifier

accountId
integer > 0

Account identifier

startDate
string

Start of creation period

endDate
string

End of creation period

page
integer > 0
Default: 1

Page number (starts at 1)

perPage
integer ( 0 .. 100 ]
Default: 10

Number of records per page (max 100)

filter
string

Generic text search filter

sortBy
string
Default: "createdAt"

Field to sort by (default: createdAt)

sortOrder
string
Default: "desc"
Enum: "asc" "desc" "ASC" "DESC"

Sort order (asc or desc, default: desc)

Responses

Response samples

Content type
application/json
{
  • "meta": {
    },
  • "data": [
    ]
}

Retrieve a specific refund

Get refund by ID

Authorizations:
bearerAuth
path Parameters
id
required
string <uuid>

Refund ID

Responses

Response samples

Content type
application/json
{
  • "id": "string",
  • "transactionId": 0,
  • "accountId": 0,
  • "refundReason": "string",
  • "refundDetails": "string",
  • "amount": "string",
  • "status": "string",
  • "refundEndToEndId": "string",
  • "refundAttempts": 0,
  • "requestingParticipant": 0,
  • "contestedParticipant": 0,
  • "analysisResult": "string",
  • "analysisDetails": "string",
  • "refundRejectionReason": "string",
  • "relatedId": "string",
  • "relatedInfractionId": "string",
  • "creationTime": "string",
  • "createdAt": "string",
  • "updatedAt": "string"
}