# Security (/en/docs/conta-digital/security)

<QuickLinks>
  <QuickLink href="/docs/conta-digital/authentication" title="Authentication" />

  <QuickLink href="/docs/conta-digital/webhooks#signature" title="Webhook signature" />
</QuickLinks>

## Credential [#credential]

| Control  | How it works                                                               |
| -------- | -------------------------------------------------------------------------- |
| Account  | The credential operates only its own account. No route takes `accountId`.  |
| Secret   | The `client_secret` appears once, at creation. PayZu stores only its hash. |
| Last use | PayZu records the last use of each credential.                             |

Scopes, IP list, rotation and revocation: [Authentication](/docs/conta-digital/authentication).

A wrong secret and a nonexistent `client_id` get the same response, `401` with `TOKEN_INVALID`.

## Webhook secrets [#webhook-secrets]

Every webhook arrives signed. The secret depends on where it goes:

| Secret   | Starts with | Signs what goes to                       | How to get and change it                                                                                                                                                |
| -------- | ----------- | ---------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Endpoint | `whsec_`    | The registered endpoint                  | Comes only in the `POST /transactions/webhooks` response. To change it, generate another one in the dashboard, with the PIN. The previous one stops working right away. |
| Callback | `cbsec_`    | The `callbackUrl` given in the operation | Comes once, in `POST /transactions/callback-secret`. `POST /transactions/callback-secret/rotate` generates another one, and the previous one stops working right away.  |

The signature comes in `X-Payzu-Signature`: it is the HMAC-SHA256 of `<X-Payzu-Timestamp>.<raw body>`. The timestamp is in milliseconds and changes on each attempt. How to check it: [Webhooks](/docs/conta-digital/webhooks#signature).

An operation with `callbackUrl` on an account without a callback secret is refused with `412` and `CALLBACK_SECRET_MISSING`.

## Third-party data in responses [#third-party-data-in-responses]

| Data                                                                                                                 | How it appears                                                                       |
| -------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
| Destination key of a withdrawal and of a Pix copy-and-paste payment, in the lookup, in the list and in the statement | Masked when it is a CPF, email or phone number. CNPJ and random keys appear in full. |
| Document of the payer of a Pix received without a charge                                                             | CPF masked or CNPJ formatted.                                                        |
| Holder in the recipient lookup                                                                                       | Full name, masked CPF and only the last four digits of the account.                  |
| `ipAddress` sent in the charge                                                                                       | Does not come back in any response or webhook.                                       |
| Resource from another account                                                                                        | `404`, the same as for a resource that does not exist.                               |