Learn how to receive Brazil Core Services infraction notifications.
Infractions notifications
The notifications will be delivered to the notification_url sent in the account creation request.
Until dLocal receives a 200 status code confirmation on these notifications, it will retry once an hour for 7 days.
Signature Notifications
An HMAC signature is calculated using a request's key-value pairs and a secret key, which is known only to you and dLocal. By verifying this signature, you'll confirm that the notification was not modified during transmission.
dLocal will be signing each POST notification using the same method described on the Security section (HMAC-SHA256 hash function) but in header Signature without prefix V2-HMAC-SHA256, Signature:
Sample signature header: "Signature":"aa293f32c1bad5279dff8dbf3d0f8ba0dfe492f9f3e952792f11d16624a16010"
Simply take the Signature HTTP header from the notification, and compare it with the one generated by you using your X-Login and secretKey, and the X-Date and Request body of the notification received. If the signature generated by you matched the one received on the Signature HTTP header, then it is safe to assume that this is a valid message from dLocal.
Request Fields
| Body Field | Type | Description |
|---|---|---|
infraction.amount | String | Amount involved in the infraction. |
infraction.analysis_status | String | Analysis result. Can be PENDING, AGREED, or DISAGREED. |
infraction.creation_date | String | ISO8601 datetime when the infraction was created. |
infraction.details | String | Human-readable description of the infraction. |
infraction.infraction_id | String | Unique identifier of the infraction. |
infraction.due_date | String | ISO8601 datetime deadline for responding to the infraction. |
infraction.reason | String | Reason for the infraction. Can be FRAUD or OPERATIONAL_FLAW. |
infraction.status | String | Current status. Can be OPEN, ACKNOWLEDGED, CLOSED, or CANCELLED. |
transaction.value | String | Transaction amount. |
transaction.end_to_end_id | String | Unique end-to-end transaction identifier assigned by the Pix network. |
transaction.payment_id | String | dLocal payment identifier. |
transaction.payment_merchant_id | String | Merchant identifier associated with the payment. |
transaction.payer.account.account_number | String | Account number of the payer. |
transaction.payer.account.account_type | String | Type of account. Can be CACC (checking) or SVGS (savings). |
transaction.payer.account.branch | String | Bank branch number of the payer. |
transaction.payer.name | String | Full name of the payer. |
transaction.payer.psp.ispb | String | ISPB code that uniquely identifies the payer's PSP in the Brazilian payment system. |
transaction.payer.psp.name | String | Name of the payer's PSP. |
transaction.payer.tax_id | String | Tax identification number (CPF or CNPJ) of the payer. |
transaction.receiver.account.account_number | String | Account number of the receiver. |
transaction.receiver.account.account_type | String | Type of account. Can be CACC (checking) or SVGS (savings). |
transaction.receiver.account.branch | String | Bank branch number of the receiver. |
transaction.receiver.address_key | String | Pix key used to receive the payment (e.g. email, CPF, phone, or EVP). |
transaction.receiver.psp.ispb | String | ISPB code that uniquely identifies the receiver's PSP in the Brazilian payment system. |
transaction.receiver.psp.name | String | Name of the receiver's PSP. |
transaction.receiver.tax_id | String | Tax identification number (CPF or CNPJ) of the receiver. |
Example request
{
"infraction": {
"amount": "150.00",
"analysis_status": "PENDING",
"creation_date": "2026-08-24T12:00:00Z",
"details": "Suspected fraud reported by payer PSP",
"infraction_id": "INF-123456789",
"due_date": "2026-09-01T23:59:59Z",
"reason": "FRAUD",
"status": "OPEN"
},
"transaction": {
"value": "150.00",
"end_to_end_id": "E12345678202608241200000000001",
"payment_id": "PAY-987654321",
"payment_merchant_id": "MERCH-001",
"payer": {
"account": {
"account_number": "1234567",
"account_type": "CACC",
"branch": "0001"
},
"name": "John Doe",
"psp": {
"ispb": "12345678",
"name": "Payer Bank"
},
"tax_id": "12345678901"
},
"receiver": {
"account": {
"account_number": "7654321",
"account_type": "CACC",
"branch": "0001"
},
"address_key": "[email protected]",
"psp": {
"ispb": "87654321",
"name": "Receiver Bank"
},
"tax_id": "98765432100"
}
}
}