Skip to main content
Changes that need some action from integrators. The most recent come first.
Webhooks: signature with your account secret

New webhook signature (action required by 2026-10-29)

Callbacks sent to the callbackUrl of charges and payouts now carry two new headers:
  • X-Safefy-Timestamp: send time, in Unix seconds.
  • X-Safefy-Signature-V2: t={timestamp},v1={HMAC-SHA256(secret, "{timestamp}.{body}")}.
The secret is unique to your account. Get it in Dashboard → Webhooks → Show secret (“Mostrar segredo”).Why it changed: the legacy signature (X-Safefy-Signature) used the payment or payout ID as the key, and the payer knows that ID. With the account secret, only Safefy can sign a valid callback. The timestamp in the signature blocks replays of old callbacks.What to do:
  1. Get the secret from the dashboard and store it on your server.
  2. Validate X-Safefy-Signature-V2 over the raw request body.
  3. Reject callbacks with an invalid signature or older than 5 minutes.
  4. When in doubt, confirm the status through the API before releasing the order.
Deadline: the legacy X-Safefy-Signature header stops being sent on 2026-10-29. Until then both are sent.Step by step and examples in Node.js, Python, PHP and C#: Webhooks → Signature.
Dashboard: production API credentials need a code

Creating a production API credential asks for an e-mail code

When you create a Production API credential in the dashboard, Safefy e-mails a code to the account and the credential is only created after you confirm it. Sandbox credentials are still created right away.API calls with existing credentials do not change.