/meds/list Endpoint
Background
/meds/list is the MED infraction report list endpoint for merchants. It uses cursor-based pagination and returns the merchant's own PIX MED infraction reports, with filtering by MED creation time range, MED status, and infraction report status.
Results are sorted by MED ID (the platform case number) in descending order, newest first.
Endpoint
| Item | Value |
|---|---|
| Method | GET |
| Path | /meds/list |
| Content-Type | application/json |
| Purpose | Query the MED infraction report list |
Authentication
Use ES256 request signing and include all five required headers: X-Merchant-Id, X-Timestamp, X-Nonce, Digest, and Authorization. Set X-Merchant-Id to the merchant number and keyId to the key version, v1 by default. The signature is the DER-encoded ECDSA signature encoded with standard Base64. See Request Signing.
Generate the timestamp, nonce, digest, and signature placeholders for each actual request. The canonical string includes the actual path and raw query; sign again when pagination or filter parameters change.
Request Fields
| Field | Location | Type | Required | Description |
|---|---|---|---|---|
limit | Query | int | No | Records per page; minimum 1, maximum 100; defaults to 5 when omitted. |
id | Query | string | No | MED ID at the cursor position for pagination, maximum length 64 characters. |
direction | Query | string | No | Pagination direction: next (next page) or previous (previous page), default next. |
filterStartTime | Query | string | No | Filter start time of MED creation, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ); can be used alone, and forms a closed interval (inclusive of both ends) when provided together with filterEndTime. |
filterEndTime | Query | string | No | Filter end time of MED creation, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ); can be used alone, and forms a closed interval (inclusive of both ends) when provided together with filterStartTime. |
status | Query | string | No | Filter by MED status; see the status enum below. |
infractionReportStatus | Query | string | No | Filter by infraction report status; see the infractionReportStatus enum below. |
status MED Status Enum
| Value | Description |
|---|---|
WAITING | Pending: the case is waiting to be handled by the merchant (upload evidence files and submit the analysis) |
EVIDENCE_REQUIRED | Additional evidence required: the platform has returned the merchant's dispute submission; the merchant can resubmit the analysis after uploading the additional files |
UNDER_REVIEW | Under platform review: the merchant has submitted an analysis verdict (or the platform has submitted on their behalf); the platform is reviewing until the review result |
ACCEPTED_BY_USER | Merchant has accepted the refund: reserved status, not produced in the current flow (may exist in historical data) |
REJECTED_BY_USER | Merchant has disputed: reserved status, not produced in the current flow (may exist in historical data) |
ACCEPTED_BY_PSP | Review result upheld: the platform's review result is that the MED is upheld and the refund is executed |
REJECTED_BY_PSP | Review result not upheld: the platform's review result is that the MED is not upheld |
CANCELLED_BY_USER | Cancelled by user: the paying user / complainant withdraws the MED request |
CANCELLED_BY_PSP | Cancelled by platform: the platform cancels or terminates the MED processing |
CLOSED | Closed: closed after fund processing (deduction or return) is complete; terminal state |
infractionReportStatus Infraction Report Status Enum
| Value | Description |
|---|---|
RECEIVED | The report has been received |
ANALYZED | The report analysis is complete |
CANCELLED | The report has been cancelled |
Filtering Rules
- Time range validation:
filterStartTimeandfilterEndTimecan each be used alone; when both are provided,filterStartTimemust be less than or equal tofilterEndTime, and the filtering interval is a closed interval, inclusive of both ends. - Time format: Time parameters are ISO 8601 UTC time strings (
yyyy-MM-ddTHH:mm:ssZ), accurate to the second and must carry theZsuffix; timezone offsets are not accepted.
Pagination Behavior
- Cursor-based pagination is more efficient and consistent than offset-based pagination when the underlying dataset changes.
- First request: Omit the
idanddirectionparameters. - Next page: Use the full URL provided in the
nextfield of the response. - Previous page: Use the full URL provided in the
previousfield of the response.
Request Examples
Example 1: Fetch the first page
GET /meds/list?limit=10 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Example 2: Filter by time range
GET /meds/list?filterStartTime=2026-01-01T00:00:00Z&filterEndTime=2026-01-31T23:59:59Z&limit=20 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Example 3: Filter by status
GET /meds/list?status=WAITING&limit=15 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Example 4: Navigate to the next page
GET /meds/list?limit=10&id=medc2874510938274639021&direction=next HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Example 5: Navigate to the previous page
GET /meds/list?limit=10&id=medc1029384756102938475&direction=previous HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Example 6: Combine complex filters
GET /meds/list?filterStartTime=2026-01-01T00:00:00Z&filterEndTime=2026-01-31T23:59:59Z&status=WAITING&infractionReportStatus=RECEIVED&limit=25 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Response Fields
The endpoint uses the standard status, msg, and data response envelope. Pagination cursors and the MED records are returned in data.
Each list item is a lightweight projection of Query MED Details and shares the same structure: list items contain the summary fields plus the transaction, payer (without the bank account), payee, and infractionReport groups; details, funds, analysis, and chargebacks are only returned by the detail endpoint.
Pagination Fields
| Field | Type | Returned | Description |
|---|---|---|---|
status | int | Yes | Response code |
msg | string | Yes | Response message corresponding to status. |
data | object | On success | Paginated result; may be omitted when signature or protocol parsing fails. |
data.next | string | Yes | Full URL for the next page of results; null when there are no more pages; maximum length 512 characters. |
data.previous | string | Yes | Full URL for the previous page of results; null when on the first page; maximum length 512 characters. |
data.results | array | Yes | List of MED records. |
Item Summary Fields (data.results[])
| Field | Type | Returned | Description |
|---|---|---|---|
data.results[].medId | string | Yes | Unique MED identifier, the platform case number (medc prefix + digits), maximum length 64 characters. |
data.results[].subMerchantNo | string | Yes | The sub-merchant number that the MED belongs to; always an empty string for direct merchants; can be ignored. |
data.results[].status | string | Yes | Current MED status; see the MED status enum above. |
data.results[].originSituationType | string | Yes | Situation type that triggered the MED; see Enums & Statuses in the MED API Overview. |
data.results[].amount | decimal | Yes | Transaction amount involved in the MED; up to 25 digits for the integer part and 4 digits for the decimal part; never negative. |
data.results[].analysisResult | string | No | Analysis result: ACCEPTED (accepted) or REJECTED (rejected); null when no analysis has been made yet. |
data.results[].dueTime | string | No | Evidence submission deadline, by which the evidence uploads and analysis submission must be completed, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ); null when not set. |
data.results[].createdAt | string | Yes | MED record creation time, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ). |
data.results[].updatedAt | string | Yes | MED record last update time, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ). |
Remaining Item Groups (data.results[])
| Field | Type | Returned | Description |
|---|---|---|---|
data.results[].transaction | object | Yes | The Pix transaction that triggered the MED; identical to data.transaction in the detail endpoint. |
data.results[].payer | object | Yes | Payer information (the party that sent the Pix); identical to data.payer in the detail endpoint, except bankAccount is not included. |
data.results[].payee | object | Yes | Payee information (the party that received the Pix); identical to data.payee in the detail endpoint, except bankAccount is not included. |
data.results[].infractionReport | object | Yes | Central bank infraction report information; identical to data.infractionReport in the detail endpoint. |
Response Example
{
"status": 200,
"msg": "sucesso",
"data": {
"next": "https://api.adopay.com.br/meds/list?id=medc2874510938274639021&direction=next&limit=5",
"previous": null,
"results": [
{
"medId": "medc2874510938274639021",
"subMerchantNo": "",
"status": "WAITING",
"originSituationType": "SCAM_FRAUD",
"amount": 1000.50,
"analysisResult": null,
"dueTime": "2026-01-31T23:59:59Z",
"createdAt": "2026-01-15T14:30:00Z",
"updatedAt": "2026-01-15T14:30:00Z",
"transaction": {
"e2eId": "E1234567820240115143000123",
"transactionDate": "2026-01-15T14:30:12Z",
"merchantOrderNo": "PIX20260816000001",
"platOrderNo": "P5nosqyWAQsQZNtYa5OW"
},
"payer": {
"name": "João Silva",
"document": "12345678901",
"email": "user@example.com",
"phone": "+5511999999999"
},
"payee": {
"name": "John Doe",
"document": "12345678000195"
},
"infractionReport": {
"id": "report-456",
"status": "RECEIVED",
"createdAt": "2026-01-15T14:30:00Z",
"creatorPsp": "12345678"
}
}
]
}
}Response Error Codes
Back to MED API Overview