/meds/list
Background
/meds/list is the MED infraction report list endpoint for partners. It uses cursor-based pagination and returns PIX MED infraction reports of all sub-merchants under the partner account, with filtering by creation time range, sub-merchant, MED status, and infraction report status.
Results are sorted by MED ID (the platform case number) in descending order, newest created first. Each MED belongs to exactly one sub-merchant, identified by the merchant number subMerchantNo, so records can be routed to the corresponding sub-merchant.
Endpoint
| Item | Value |
|---|---|
| Method | GET |
| Path | /meds/list |
| Content-Type | application/json |
| Purpose | Query the MED infraction report list |
Authentication
Use ES256 request signing and include all five required headers: X-Merchant-Id, X-Timestamp, X-Nonce, Digest, and Authorization. Set X-Merchant-Id to the partner's top-level merchant number and keyId to the key version, v1 by default. The signature is a DER-encoded ECDSA signature encoded with standard Base64. See Request Signing.
Generate the timestamp, nonce, digest, and signature placeholders for each actual request. The canonical string includes the actual path and raw query; sign again when pagination or filter parameters change.
Request Fields
| Field | Location | Type | Required | Description |
|---|---|---|---|---|
limit | Query | int | No | Records per page; minimum 1, maximum 100; defaults to 5 when omitted. |
id | Query | string | No | MED ID at the cursor position for pagination, maximum length 64 characters. |
direction | Query | string | No | Pagination direction: next (next page) or previous (previous page), default next. |
subMerchantNo | Query | string | No | Filters by sub-merchant number, max length 64 characters; omit to return MEDs of all sub-merchants under the partner. |
filterStartTime | Query | string | No | Filter start time of MED creation, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ); can be used alone, and forms a closed interval (inclusive of both ends) when provided together with filterEndTime. |
filterEndTime | Query | string | No | Filter end time of MED creation, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ); can be used alone, and forms a closed interval (inclusive of both ends) when provided together with filterStartTime. |
status | Query | string | No | Filter by MED status; see the status enum below. |
infractionReportStatus | Query | string | No | Filter by infraction report status; see the infractionReportStatus enum below. |
status MED Status Enum
| Value | Description |
|---|---|
WAITING | Pending: the case is waiting to be handled by the partner (upload evidence files and submit the analysis) |
EVIDENCE_REQUIRED | Additional evidence required: the platform has returned the partner's dispute submission; the partner can supplement files and resubmit the analysis |
UNDER_REVIEW | Under platform review: the partner has submitted an analysis verdict (or the platform has submitted on their behalf); the platform is reviewing until the review result |
ACCEPTED_BY_USER | Partner has agreed to the refund: reserved status, not produced in the current flow (may exist in historical data) |
REJECTED_BY_USER | Partner has disputed: reserved status, not produced in the current flow (may exist in historical data) |
ACCEPTED_BY_PSP | Review result upheld: the platform's review result is that the MED is upheld and the refund is executed |
REJECTED_BY_PSP | Review result not upheld: the platform's review result is that the MED is not upheld |
CANCELLED_BY_USER | User cancelled: the paying user / complaint initiator withdrew this MED application |
CANCELLED_BY_PSP | Platform cancelled: the platform cancelled or terminated this MED processing |
CLOSED | Closed: closed after fund processing (deduction or return) is complete; terminal state |
infractionReportStatus Infraction Report Status Enum
| Value | Description |
|---|---|
RECEIVED | The report has been received |
ANALYZED | The report analysis is complete |
CANCELLED | The report has been cancelled |
Filtering Rules
- Time range validation:
filterStartTimeandfilterEndTimecan each be used alone; when both are provided,filterStartTimemust be less than or equal tofilterEndTime, and the filtering interval is closed, inclusive of both ends. - Time format: Time parameters are ISO 8601 UTC time strings (
yyyy-MM-ddTHH:mm:ssZ), accurate to the second and must carry theZsuffix; timezone offset notation is not accepted.
Pagination Behavior
- Cursor-based pagination is more efficient and consistent than offset-based pagination when the underlying dataset changes.
- First request: Omit the
idanddirectionparameters. - Next page: Use the full URL provided in the
nextfield of the response. - Previous page: Use the full URL provided in the
previousfield of the response.
Request Examples
Example 1: Fetch the first page
GET /meds/list?limit=10 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Example 2: Filter by time range
GET /meds/list?filterStartTime=2026-01-01T00:00:00Z&filterEndTime=2026-01-31T23:59:59Z&limit=20 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Example 3: Filter by sub-merchant and status
GET /meds/list?subMerchantNo=24922653000123&status=WAITING&limit=15 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Example 4: Navigate to the next page
GET /meds/list?limit=10&id=medc2874510938274639021&direction=next HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Example 5: Navigate to the previous page
GET /meds/list?limit=10&id=medc1029384756102938475&direction=previous HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Example 6: Combine complex filters
GET /meds/list?filterStartTime=2026-01-01T00:00:00Z&filterEndTime=2026-01-31T23:59:59Z&subMerchantNo=24922653000123&status=WAITING&infractionReportStatus=RECEIVED&limit=25 HTTP/1.1
X-Merchant-Id: <MERCHANT_ID>
X-Timestamp: <UNIX_TIMESTAMP_SECONDS>
X-Nonce: <UNIQUE_NONCE>
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"Response Fields
The endpoint uses the standard status, msg, and data response envelope. Pagination cursors and the MED record list are returned in data.
Each list item is a lightweight projection of Query MED Details and shares the same structure: list items contain the summary fields plus the transaction, payer (without the bank account), payee, and infractionReport groups; details, funds, analysis, and chargebacks are only returned by the details endpoint.
Pagination Fields
| Field | Type | Always Returned | Description |
|---|---|---|---|
status | int | Yes | Response code |
msg | string | Yes | Corresponds to status |
data | object | On success | Paginated result; may be omitted when the request fails at signature verification or protocol parsing. |
data.next | string | Yes | Full URL for the next page of results; null when there are no more pages; maximum length 512 characters. |
data.previous | string | Yes | Full URL for the previous page of results; null when on the first page; maximum length 512 characters. |
data.results | array | Yes | List of MED records. |
Item Summary Fields (data.results[])
| Field | Type | Always Returned | Description |
|---|---|---|---|
data.results[].medId | string | Yes | Unique MED identifier, the platform case number (medc prefix + digits), maximum length 64 characters. |
data.results[].subMerchantNo | string | Yes | Sub-merchant number that owns the MED, maximum length 64 characters. |
data.results[].status | string | Yes | Current MED status; see the MED status enum above. |
data.results[].originSituationType | string | Yes | Situation type that triggered the MED; see Enums & Statuses in the MED API Overview. |
data.results[].amount | decimal | Yes | Transaction amount involved in the MED; up to 25 digits for the integer part and 4 digits for the decimal part; never negative. |
data.results[].analysisResult | string | No | Analysis result: ACCEPTED (accepted) or REJECTED (rejected); null when no analysis has been made yet. |
data.results[].dueTime | string | No | Evidence submission deadline by which evidence upload and analysis submission must be completed, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ); null when not set. |
data.results[].createdAt | string | Yes | MED record creation time, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ). |
data.results[].updatedAt | string | Yes | MED record last update time, ISO 8601 UTC time string (yyyy-MM-ddTHH:mm:ssZ). |
Item Groups (data.results[])
| Field | Type | Always Returned | Description |
|---|---|---|---|
data.results[].transaction | object | Yes | The Pix transaction that triggered the MED; identical to data.transaction in the details endpoint. |
data.results[].payer | object | Yes | Payer information (the party that sent the Pix); identical to data.payer in the details endpoint, except bankAccount is not included. |
data.results[].payee | object | Yes | Payee information (the party that received the Pix); identical to data.payee in the details endpoint, except bankAccount is not included. |
data.results[].infractionReport | object | Yes | Central bank infraction report information; identical to data.infractionReport in the details endpoint. |
Response Example
{
"status": 200,
"msg": "sucesso",
"data": {
"next": "https://api.adopay.com.br/meds/list?id=medc2874510938274639021&direction=next&limit=5",
"previous": null,
"results": [
{
"medId": "medc2874510938274639021",
"subMerchantNo": "24922653000123",
"status": "WAITING",
"originSituationType": "SCAM_FRAUD",
"amount": 1000.50,
"analysisResult": null,
"dueTime": "2026-01-31T23:59:59Z",
"createdAt": "2026-01-15T14:30:00Z",
"updatedAt": "2026-01-15T14:30:00Z",
"transaction": {
"e2eId": "E1234567820240115143000123",
"transactionDate": "2026-01-15T14:30:12Z",
"merchantOrderNo": "PIX20260816000001",
"platOrderNo": "P5nosqyWAQsQZNtYa5OW"
},
"payer": {
"name": "João Silva",
"document": "12345678901",
"email": "user@example.com",
"phone": "+5511999999999"
},
"payee": {
"name": "John Doe",
"document": "12345678000195"
},
"infractionReport": {
"id": "report-456",
"status": "RECEIVED",
"createdAt": "2026-01-15T14:30:00Z",
"creatorPsp": "12345678"
}
}
]
}
}Response Error Codes
Back to MED API Overview