PayZuDocs

See what protects the credential and the webhooks, and which third-party data the API masks in responses.

Credential

ControlHow it works
AccountThe credential operates only its own account. No route takes accountId.
SecretThe client_secret appears once, at creation. PayZu stores only its hash.
Last usePayZu records the last use of each credential.

Scopes, IP list, rotation and revocation: Authentication.

A wrong secret and a nonexistent client_id get the same response, 401 with TOKEN_INVALID.

Webhook secrets

Every webhook arrives signed. The secret depends on where it goes:

SecretStarts withSigns what goes toHow to get and change it
Endpointwhsec_The registered endpointComes only in the POST /transactions/webhooks response. To change it, generate another one in the dashboard, with the PIN. The previous one stops working right away.
Callbackcbsec_The callbackUrl given in the operationComes once, in POST /transactions/callback-secret. POST /transactions/callback-secret/rotate generates another one, and the previous one stops working right away.

The signature comes in X-Payzu-Signature: it is the HMAC-SHA256 of <X-Payzu-Timestamp>.<raw body>. The timestamp is in milliseconds and changes on each attempt. How to check it: Webhooks.

An operation with callbackUrl on an account without a callback secret is refused with 412 and CALLBACK_SECRET_MISSING.

Third-party data in responses

DataHow it appears
Destination key of a withdrawal and of a Pix copy-and-paste payment, in the lookup, in the list and in the statementMasked when it is a CPF, email or phone number. CNPJ and random keys appear in full.
Document of the payer of a Pix received without a chargeCPF masked or CNPJ formatted.
Holder in the recipient lookupFull name, masked CPF and only the last four digits of the account.
ipAddress sent in the chargeDoes not come back in any response or webhook.
Resource from another account404, the same as for a resource that does not exist.

On this page