Learn how to receive Brazil Core Services decode QR Code notifications.
Decode QR Code notifications
The notifications will be delivered to the notification_url sent in the account creation request.
Until dLocal receives a 200 status code confirmation on these notifications, it will retry once an hour for 7 days.
Signature Notifications
An HMAC signature is calculated using a request's key-value pairs and a secret key, which is known only to you and dLocal. By verifying this signature, you'll confirm that the notification was not modified during transmission.
dLocal will be signing each POST notification using the same method described on the Security section (HMAC-SHA256 hash function) but in header Signature without prefix V2-HMAC-SHA256, Signature:
Sample signature header: "Signature":"aa293f32c1bad5279dff8dbf3d0f8ba0dfe492f9f3e952792f11d16624a16010"
Simply take the Signature HTTP header from the notification, and compare it with the one generated by you using your X-Login and secretKey, and the X-Date and Request body of the notification received. If the signature generated by you matched the one received on the Signature HTTP header, then it is safe to assume that this is a valid message from dLocal.
Request Fields
| Field | Description |
|---|---|
payment_id | Identifier of the payment in dLocal. |
endtoend_id | End-to-End (E2E) identifier of the Pix transaction. The field name is exactly endtoend_id in the payload. |
qr_code_created_at | Date and time when the QR Code was created. This value comes from creation_date. |
amount | Payment amount, sent as a JSON number. |
decode_timestamp | Date and time of the latest update. This value comes from last_updated_date. |
Example request
{
"payment_id": "pay-001",
"endtoend_id": "E00000000202607150000000000000001",
"qr_code_created_at": "2026-09-01T10:00:00Z",
"amount": 99.99,
"decode_timestamp": "2026-09-01T10:05:00Z"
}