See what protects the credential and the webhooks, and which third-party data the API masks in responses.
Credential
| Control | How it works |
|---|---|
| Account | The credential operates only its own account. No route takes accountId. |
| Secret | The client_secret appears once, at creation. PayZu stores only its hash. |
| Last use | PayZu records the last use of each credential. |
Scopes, IP list, rotation and revocation: Authentication.
A wrong secret and a nonexistent client_id get the same response, 401 with TOKEN_INVALID.
Webhook secrets
Every webhook arrives signed. The secret depends on where it goes:
| Secret | Starts with | Signs what goes to | How to get and change it |
|---|---|---|---|
| Endpoint | whsec_ | The registered endpoint | Comes only in the POST /transactions/webhooks response. To change it, generate another one in the dashboard, with the PIN. The previous one stops working right away. |
| Callback | cbsec_ | The callbackUrl given in the operation | Comes once, in POST /transactions/callback-secret. POST /transactions/callback-secret/rotate generates another one, and the previous one stops working right away. |
The signature comes in X-Payzu-Signature: it is the HMAC-SHA256 of <X-Payzu-Timestamp>.<raw body>. The timestamp is in milliseconds and changes on each attempt. How to check it: Webhooks.
An operation with callbackUrl on an account without a callback secret is refused with 412 and CALLBACK_SECRET_MISSING.
Third-party data in responses
| Data | How it appears |
|---|---|
| Destination key of a withdrawal and of a Pix copy-and-paste payment, in the lookup, in the list and in the statement | Masked when it is a CPF, email or phone number. CNPJ and random keys appear in full. |
| Document of the payer of a Pix received without a charge | CPF masked or CNPJ formatted. |
| Holder in the recipient lookup | Full name, masked CPF and only the last four digits of the account. |
ipAddress sent in the charge | Does not come back in any response or webhook. |
| Resource from another account | 404, the same as for a resource that does not exist. |