DEPRECATED — do not use for new integrations. This signature uses your API key as the hashing secret and does not cover the full request body or a timestamp. It will be removed in the future. Register a webhook with a
secret using the Webhook Setup API and migrate to the HMAC-SHA256 signature.When it is used
This scheme is used when no webhook is registered for the event, so the webhook is delivered to thenotification_url of the transaction. It is also still used by flows that were not migrated to the HMAC-SHA256 signature, such as Automatic PIX authorization and schedule webhooks.
The signature is a SHA256 hash (hexadecimal) of a concatenation of transaction fields and your API key, sent as a Bearer token.
Legacy Headers
Legacy webhooks do not include the
x-webhook-wp-type and x-webhook-wp-timestamp headers.
Payin Webhook Signature
For a Payin webhook, you need to concatenate the following fields in the exact order:{id}: The unique identifier of the transaction{key}: A specific key associated with the transaction. In the case of Payin creation, the value used for key is thehashfield returned in the response{amount}: The amount involved in the transaction{api_key}: Your API key used for authentication
Payout Webhook Signature
For a Payout webhook, the following fields should be concatenated:{invoice}: The invoice number of the payout transaction{currency}: The currency used in the payout{amount}: The amount of the payout{api_key}: Your API key used for authentication
Automatic PIX Webhook Signature
For Automatic PIX authorization and schedule webhooks, the following fields should be concatenated:{merchant_id}: Merchant ID of the user that created the authorization{contract_id}: Contract ID of the authorization{api_key}: API Key of the user that created the authorization
Signature Verification
To verify the webhook’s authenticity:- Concatenate the required fields (depending on whether the webhook is for a Payin, Payout, or Automatic PIX)
- Generate a SHA256 hash of the concatenated string
- Compare the generated hash with the token provided in the signature header (without the
Bearerprefix)
Examples
Payin
For a Payin webhook with the following data:{id}= 123456{key}= ABCD{amount}= 10.00{api_key}= FF9876543210
123456ABCD10.00FF9876543210
To verify the authenticity of the webhook, generate the SHA256 hash of this string and compare it with the x-webhook-wp-signature header.
Payout
For a Payout webhook with the following data:{invoice}= WE00000001{currency}= BRL{amount}= 5.00{api_key}= FF99775566ffddhh
WE00000001BRL5.00FF99775566ffddhh
To verify the authenticity of the webhook, generate the SHA256 hash of this string and compare it with the x-webhook-wp-signature header.
Automatic PIX
For an Automatic PIX webhook with the following data:{merchant_id}= 467{contract_id}= A001{api_key}= FF99775566ffddhh
467A001FF99775566ffddhh
To verify the authenticity of the webhook, generate the SHA256 hash of this string and compare it with the x-webhook-wp-signature header.
