> ## Documentation Index
> Fetch the complete documentation index at: https://docs.safefypay.com.br/llms.txt
> Use this file to discover all available pages before exploring further.

# Changelog

> Changes that affect your Safefy integration, with dates and what to do

Changes that need some action from integrators. The most recent come first.

<Update label="2026-09-29" description="Webhooks: signature with your account secret">
  ## New webhook signature (action required by 2026-10-29)

  Callbacks sent to the `callbackUrl` of charges and payouts now carry two new headers:

  * `X-Safefy-Timestamp`: send time, in Unix seconds.
  * `X-Safefy-Signature-V2`: `t={timestamp},v1={HMAC-SHA256(secret, "{timestamp}.{body}")}`.

  The secret is **unique to your account**. Get it in **Dashboard → Webhooks → Show secret** ("Mostrar segredo").

  **Why it changed:** the legacy signature (`X-Safefy-Signature`) used the payment or payout ID as the key, and the
  payer knows that ID. With the account secret, only Safefy can sign a valid callback. The timestamp in the signature
  blocks replays of old callbacks.

  **What to do:**

  1. Get the secret from the dashboard and store it on your server.
  2. Validate `X-Safefy-Signature-V2` over the raw request body.
  3. Reject callbacks with an invalid signature or older than 5 minutes.
  4. When in doubt, confirm the status through the API before releasing the order.

  **Deadline:** the legacy `X-Safefy-Signature` header stops being sent on **2026-10-29**. Until then both are sent.

  Step by step and examples in Node.js, Python, PHP and C#: [Webhooks → Signature](/en/webhooks#signature).
</Update>

<Update label="2026-09-29" description="Dashboard: production API credentials need a code">
  ## Creating a production API credential asks for an e-mail code

  When you create a **Production** API credential in the dashboard, Safefy e-mails a code to the account and the
  credential is only created after you confirm it. **Sandbox** credentials are still created right away.

  API calls with existing credentials do not change.
</Update>
