Skip to content

/meds/list ​

Background ​

/meds/list is the MED infraction report list endpoint for partners. It uses cursor-based pagination and returns PIX MED infraction reports of all sub-merchants under the partner account, with filtering by creation time range, sub-merchant, MED status, and infraction report status.

Results are sorted by MED ID (the platform case number) in descending order, newest created first. Each MED belongs to exactly one sub-merchant, identified by the merchant number subMerchantNo, so records can be routed to the corresponding sub-merchant.

Endpoint ​

ItemValue
MethodGET
Path/meds/list
Content-Typeapplication/json
PurposeQuery the MED infraction report list

Authentication ​

Use ES256 request signing and include all five required headers: X-Merchant-Id, X-Timestamp, X-Nonce, Digest, and Authorization. Set X-Merchant-Id to the partner's top-level merchant number and keyId to the key version, v1 by default. The signature is a DER-encoded ECDSA signature encoded with standard Base64. See Request Signing.

Generate the timestamp, nonce, digest, and signature placeholders for each actual request. The canonical string includes the actual path and raw query; sign again when pagination or filter parameters change.

Request Fields ​

FieldLocationTypeRequiredDescription
limitQueryintNoRecords per page; minimum 1, maximum 100; defaults to 5 when omitted.
idQuerystringNoMED ID at the cursor position for pagination, maximum length 64 characters.
directionQuerystringNoPagination direction: next (next page) or previous (previous page), default next.
subMerchantNoQuerystringNoFilters by sub-merchant number, max length 64 characters; omit to return MEDs of all sub-merchants under the partner.
filterStartTimeQuerystringNoFilter start time of MED creation, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ); can be used alone, and forms a closed interval (inclusive of both ends) when provided together with filterEndTime.
filterEndTimeQuerystringNoFilter end time of MED creation, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ); can be used alone, and forms a closed interval (inclusive of both ends) when provided together with filterStartTime.
statusQuerystringNoFilter by MED status; see the status enum below.
infractionReportStatusQuerystringNoFilter by infraction report status; see the infractionReportStatus enum below.

status MED Status Enum ​

ValueDescription
WAITINGPending: the case is waiting to be handled by the partner (upload evidence files and submit the analysis)
EVIDENCE_REQUIREDAdditional evidence required: the platform has returned the partner's dispute submission; the partner can supplement files and resubmit the analysis
UNDER_REVIEWUnder platform review: the partner has submitted an analysis verdict (or the platform has submitted on their behalf); the platform is reviewing until the review result
ACCEPTED_BY_USERPartner has agreed to the refund: reserved status, not produced in the current flow (may exist in historical data)
REJECTED_BY_USERPartner has disputed: reserved status, not produced in the current flow (may exist in historical data)
ACCEPTED_BY_PSPReview result upheld: the platform's review result is that the MED is upheld and the refund is executed
REJECTED_BY_PSPReview result not upheld: the platform's review result is that the MED is not upheld
CANCELLED_BY_USERUser cancelled: the paying user / complaint initiator withdrew this MED application
CANCELLED_BY_PSPPlatform cancelled: the platform cancelled or terminated this MED processing
CLOSEDClosed: closed after fund processing (deduction or return) is complete; terminal state

infractionReportStatus Infraction Report Status Enum ​

ValueDescription
RECEIVEDThe report has been received
ANALYZEDThe report analysis is complete
CANCELLEDThe report has been cancelled

Filtering Rules ​

  1. Time range validation: filterStartTime and filterEndTime can each be used alone; when both are provided, filterStartTime must be less than or equal to filterEndTime, and the filtering interval is closed, inclusive of both ends.
  2. Time format: Time parameters are ISO 8601 UTC time strings (yyyy-MM-ddTHH:mm:ssZ), accurate to the second and must carry the Z suffix; timezone offset notation is not accepted.

Pagination Behavior ​

  • Cursor-based pagination is more efficient and consistent than offset-based pagination when the underlying dataset changes.
  • First request: Omit the id and direction parameters.
  • Next page: Use the full URL provided in the next field of the response.
  • Previous page: Use the full URL provided in the previous field of the response.

Request Examples ​

Example 1: Fetch the first page

http
GET /meds/list?limit=10 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"

Example 2: Filter by time range

http
GET /meds/list?filterStartTime=2026-01-01T00:00:00Z&filterEndTime=2026-01-31T23:59:59Z&limit=20 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"

Example 3: Filter by sub-merchant and status

http
GET /meds/list?subMerchantNo=24922653000123&status=WAITING&limit=15 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"

Example 4: Navigate to the next page

http
GET /meds/list?limit=10&id=medc2874510938274639021&direction=next HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"

Example 5: Navigate to the previous page

http
GET /meds/list?limit=10&id=medc1029384756102938475&direction=previous HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"

Example 6: Combine complex filters

http
GET /meds/list?filterStartTime=2026-01-01T00:00:00Z&filterEndTime=2026-01-31T23:59:59Z&subMerchantNo=24922653000123&status=WAITING&infractionReportStatus=RECEIVED&limit=25 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"

Response Fields ​

The endpoint uses the standard status, msg, and data response envelope. Pagination cursors and the MED record list are returned in data.

Each list item is a lightweight projection of Query MED Details and shares the same structure: list items contain the summary fields plus the transaction, payer (without the bank account), payee, and infractionReport groups; details, funds, analysis, and chargebacks are only returned by the details endpoint.

Pagination Fields ​

FieldTypeAlways ReturnedDescription
statusintYesResponse code
msgstringYesCorresponds to status
dataobjectOn successPaginated result; may be omitted when the request fails at signature verification or protocol parsing.
data.nextstringYesFull URL for the next page of results; null when there are no more pages; maximum length 512 characters.
data.previousstringYesFull URL for the previous page of results; null when on the first page; maximum length 512 characters.
data.resultsarrayYesList of MED records.

Item Summary Fields (data.results[]) ​

FieldTypeAlways ReturnedDescription
data.results[].medIdstringYesUnique MED identifier, the platform case number (medc prefix + digits), maximum length 64 characters.
data.results[].subMerchantNostringYesSub-merchant number that owns the MED, maximum length 64 characters.
data.results[].statusstringYesCurrent MED status; see the MED status enum above.
data.results[].originSituationTypestringYesSituation type that triggered the MED; see Enums & Statuses in the MED API Overview.
data.results[].amountdecimalYesTransaction amount involved in the MED; up to 25 digits for the integer part and 4 digits for the decimal part; never negative.
data.results[].analysisResultstringNoAnalysis result: ACCEPTED (accepted) or REJECTED (rejected); null when no analysis has been made yet.
data.results[].dueTimestringNoEvidence submission deadline by which evidence upload and analysis submission must be completed, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ); null when not set.
data.results[].createdAtstringYesMED record creation time, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ).
data.results[].updatedAtstringYesMED record last update time, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ).

Item Groups (data.results[]) ​

FieldTypeAlways ReturnedDescription
data.results[].transactionobjectYesThe Pix transaction that triggered the MED; identical to data.transaction in the details endpoint.
data.results[].payerobjectYesPayer information (the party that sent the Pix); identical to data.payer in the details endpoint, except bankAccount is not included.
data.results[].payeeobjectYesPayee information (the party that received the Pix); identical to data.payee in the details endpoint, except bankAccount is not included.
data.results[].infractionReportobjectYesCentral bank infraction report information; identical to data.infractionReport in the details endpoint.

Response Example ​

json
{
  "status": 200,
  "msg": "sucesso",
  "data": {
    "next": "https://api.adopay.com.br/meds/list?id=medc2874510938274639021&direction=next&limit=5",
    "previous": null,
    "results": [
      {
        "medId": "medc2874510938274639021",
        "subMerchantNo": "24922653000123",
        "status": "WAITING",
        "originSituationType": "SCAM_FRAUD",
        "amount": 1000.50,
        "analysisResult": null,
        "dueTime": "2026-01-31T23:59:59Z",
        "createdAt": "2026-01-15T14:30:00Z",
        "updatedAt": "2026-01-15T14:30:00Z",
        "transaction": {
          "e2eId": "E1234567820240115143000123",
          "transactionDate": "2026-01-15T14:30:12Z",
          "merchantOrderNo": "PIX20260816000001",
          "platOrderNo": "P5nosqyWAQsQZNtYa5OW"
        },
        "payer": {
          "name": "João Silva",
          "document": "12345678901",
          "email": "user@example.com",
          "phone": "+5511999999999"
        },
        "payee": {
          "name": "John Doe",
          "document": "12345678000195"
        },
        "infractionReport": {
          "id": "report-456",
          "status": "RECEIVED",
          "createdAt": "2026-01-15T14:30:00Z",
          "creatorPsp": "12345678"
        }
      }
    ]
  }
}

Response Error Codes ​


Back to MED API Overview