> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.api.corpx.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.api.corpx.com/_mcp/server.

# Get a MED dispute

GET https://client.api.corpx.com/v1/accounts/{accountId}/pix/med/{id}

Everything from the list plus the timeline visible to the account holder (`events`), the messages exchanged with the review (`messages`), the attachments with signed `downloadUrl` (`evidences`), the steps CorpX already executed in the return (`steps`) and the `can*` flags saying what is enabled right now. In `info_requested`, `infoRequest` carries the review's question and its deadline.

Reference: https://docs.api.corpx.com/ib/referencia/pix-med/get-pix-med

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Request

### Path parameters

- `accountId` (string, required) — Account identifier.
- `id` (string, required) — The `medId`.

### Headers

- `X-Tenant-Id` (string, required) — Tenant context used for authorization and routing.
- `X-Request-Timestamp` (string, required) — Unix seconds. Required on the signed host; tolerance is 300s either way (`403 request_timestamp_skew`).
- `X-Content-SHA256` (string, required) — Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns `400 body_hash_mismatch`.
- `X-Request-Signature` (string, required) — Detached JWS (`<protected>..<signature>`, ES256 or PS256) over `METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256`.

## Response

### 200

Dispute detail.

- `medId` (string, required) — Infraction report id. Same value as `data.medId` in the webhooks.
- `accountId` (string, required)
- `tenantId` (string, required)
- `endToEndId` (string, required) — E2E of the disputed PIX.
- `amount` (double, required) — Disputed amount. Amount in BRL. Max 2 decimal places (e.g., 150.75 for R$150,75).
- `answered` (boolean, required) — Whether the holder's response was recorded for this dispute.
- `updatedAt` (datetime, required)
- `reviewStatus` (enum, required) — Stage of CorpX's review. `awaiting_defense` → `pending_review` (→ `info_requested` → `pending_review`) → `in_execution` → `refunded` | `awaiting_funds`, or `refused`.
  - Allowed values: `awaiting_defense`, `pending_review`, `info_requested`, `in_execution`, `awaiting_funds`, `refunded`, `refused`
- `canUpload` (boolean, required)
- `canAnswer` (boolean, required)
- `canMessage` (boolean, required)
- `canSubmit` (boolean, required)
- `events` (list of PixMedEvent, required) — Timeline visible to the account holder; `message` texts are in Portuguese.
- `messages` (list of PixMedMessage, required)
- `evidences` (list of PixMedEvidence, required)
- `steps` (list of PixMedDetailStepsItems, required) — Return steps CorpX already executed, in text. Appears from `in_execution` on.
- `transactionId` (string, optional) — Our statement entry for the disputed PIX, when it exists on the platform. Empty for credits that predate the account here.
- `reasonCode` (string, optional) — Reason reported by the scheme, passed through raw.
- `claimMessage` (string, optional) — Free-text details from the claimant, when present.
- `claimantBank` (string, optional) — Claimant's bank. The scheme does not disclose the claimant's name or tax id to the receiving party.
- `openedAt` (datetime, optional)
- `clientAnswerDeadline` (datetime, optional) — `openedAt` + 48h. Nothing is auto-rejected on expiry: the dispute stays alive, the client just loses the chance to state their case.
- `answeredAt` (datetime, optional)
- `answerResult` (enum, optional)
  - Allowed values: `AGREE`, `DISAGREE`
- `answer` (string, optional) — The justification sent with the response.
- `closedAt` (datetime, optional) — Set when a webhook reported the dispute as closed.
- `infoDueAt` (datetime, optional, nullable) — Deadline of the pending clarification, in `info_requested`.
- `lockStatus` (enum, optional) — Balance hold for the dispute. Absent for disputes that predate the automatic hold.
  - Allowed values: `pending`, `locked`, `failed`, `unlocked`
- `lockedAmount` (double, optional) — Amount currently held, in BRL. `0` when nothing is held.
- `refundedTotal` (double, optional) — Sum of completed returns, in BRL.
- `remaining` (double, optional) — Disputed amount minus `refundedTotal`.
- `refundPartial` (boolean, optional) — `true` when the dispute closed with a partial return.
- `infoRequest` (PixMedDetailInfoRequest, optional, nullable) — The review's question, present in `info_requested`.

## Errors

### 403 Forbidden Error

Caller has no role on this account's tenant.

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 404 Not Found Error

Dispute not found, or not on this account (`med_not_found`).

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 500 Internal Server Error

Unexpected server error.

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

## Types

### PixMedEvent

- `at` (datetime, required)
- `kind` (string, required) — `submitted`, `info_requested`, `decided`, `account_blocked`, `balance_unlocked`, `refund_sent`, `refund_completed`, `refund_failed`, `remainder_locked`, `account_unblocked`, `awaiting_funds`, `round_opened`, `closed`, `balance_locked`.
- `reviewStatus` (string, optional)
- `message` (string, optional)
- `round` (integer, optional, nullable)
- `step` (string, optional, nullable)

### PixMedMessage

- `messageId` (string, required)
- `authorKind` (enum, required)
  - Allowed values: `staff`, `holder`
- `body` (string, required)
- `createdAt` (datetime, required)
- `evidenceIds` (list of string, required)

### PixMedEvidence

- `evidenceId` (string, required)
- `filename` (string, required)
- `contentType` (string, required)
- `sizeBytes` (long, required)
- `uploadedAt` (datetime, required)
- `uploadedBy` (string, optional)
- `scanStatus` (enum, optional) — `PENDING` while the antivirus and sanitization run, `APPROVED` once cleared, `REJECTED` with a `scanReason`. Rejected files do not travel with the defense and get no `downloadUrl`.
  - Allowed values: `PENDING`, `APPROVED`, `REJECTED`, `UNKNOWN`
- `scanReason` (string, optional)
- `downloadUrl` (string, optional) — Short-lived signed URL, present only for cleared files.
- `messageId` (string, optional, nullable)

### PixMedDetailStepsItems

- `round` (integer, optional)
- `step` (string, optional)
- `label` (string, optional)
- `at` (datetime, optional)

### PixMedDetailInfoRequest

The review's question, present in `info_requested`.

- `message` (string, optional)
- `requestedAt` (datetime, optional)
- `dueAt` (datetime, optional, nullable)

### ErrorResponsePartner

Raw error from the settlement bank, when the failure came from it. Diagnostic only.

- `code` (string, optional)
- `message` (string, optional)
- `field` (string, optional) — Field the partner pointed at, when any.

## Examples

**Response**

```json
{
  "medId": "204cc938-da3d-4f04-baf3-0b2e6a2f1283",
  "accountId": "2e6b725b-84a0-400d-8740-22a5ba0f23e6",
  "tenantId": "tn_7f3a9c",
  "endToEndId": "E303062942026021812490000005QLMv",
  "amount": 1000,
  "answered": true,
  "updatedAt": "2026-02-20T14:02:31Z",
  "reviewStatus": "info_requested",
  "canUpload": true,
  "canAnswer": false,
  "canMessage": true,
  "canSubmit": true,
  "events": [
    {
      "at": "2026-02-19T14:02:31Z",
      "kind": "submitted",
      "reviewStatus": "pending_review",
      "message": "Defesa enviada",
      "round": null,
      "step": null
    },
    {
      "at": "2026-02-20T14:02:31Z",
      "kind": "info_requested",
      "reviewStatus": "info_requested",
      "message": "Esclarecimento solicitado",
      "round": null,
      "step": null
    }
  ],
  "messages": [
    {
      "messageId": "medmsg_01J9X",
      "authorKind": "staff",
      "body": "Envie o comprovante de entrega com o rastreio.",
      "createdAt": "2026-02-20T14:02:31Z",
      "evidenceIds": []
    }
  ],
  "evidences": [],
  "steps": [],
  "reasonCode": "unauthorized-transaction",
  "openedAt": "2026-02-18T19:34:14Z",
  "clientAnswerDeadline": "2026-02-20T19:34:14Z",
  "infoDueAt": "2026-02-21T14:02:31Z",
  "lockStatus": "locked",
  "lockedAmount": 1000,
  "refundedTotal": 0,
  "remaining": 1000,
  "refundPartial": false,
  "infoRequest": {
    "message": "Envie o comprovante de entrega com o rastreio.",
    "requestedAt": "2026-02-20T14:02:31Z",
    "dueAt": "2026-02-21T14:02:31Z"
  }
}
```

**SDK Code**

```python Pix MED_getPixMed_example
import requests

url = "https://client.api.corpx.com/v1/accounts/accountId/pix/med/id"

headers = {
    "X-Content-SHA256": "X-Content-SHA256",
    "X-Request-Signature": "X-Request-Signature",
    "X-Request-Timestamp": "X-Request-Timestamp",
    "X-Tenant-Id": "X-Tenant-Id",
    "Authorization": "Bearer <token>"
}

response = requests.get(url, headers=headers)

print(response.json())
```

```javascript Pix MED_getPixMed_example
const url = 'https://client.api.corpx.com/v1/accounts/accountId/pix/med/id';
const options = {
  method: 'GET',
  headers: {
    'X-Content-SHA256': 'X-Content-SHA256',
    'X-Request-Signature': 'X-Request-Signature',
    'X-Request-Timestamp': 'X-Request-Timestamp',
    'X-Tenant-Id': 'X-Tenant-Id',
    Authorization: 'Bearer <token>'
  }
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Pix MED_getPixMed_example
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://client.api.corpx.com/v1/accounts/accountId/pix/med/id"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("X-Content-SHA256", "X-Content-SHA256")
	req.Header.Add("X-Request-Signature", "X-Request-Signature")
	req.Header.Add("X-Request-Timestamp", "X-Request-Timestamp")
	req.Header.Add("X-Tenant-Id", "X-Tenant-Id")
	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Pix MED_getPixMed_example
require 'uri'
require 'net/http'

url = URI("https://client.api.corpx.com/v1/accounts/accountId/pix/med/id")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["X-Content-SHA256"] = 'X-Content-SHA256'
request["X-Request-Signature"] = 'X-Request-Signature'
request["X-Request-Timestamp"] = 'X-Request-Timestamp'
request["X-Tenant-Id"] = 'X-Tenant-Id'
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java Pix MED_getPixMed_example
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://client.api.corpx.com/v1/accounts/accountId/pix/med/id")
  .header("X-Content-SHA256", "X-Content-SHA256")
  .header("X-Request-Signature", "X-Request-Signature")
  .header("X-Request-Timestamp", "X-Request-Timestamp")
  .header("X-Tenant-Id", "X-Tenant-Id")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php Pix MED_getPixMed_example
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://client.api.corpx.com/v1/accounts/accountId/pix/med/id', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'X-Content-SHA256' => 'X-Content-SHA256',
    'X-Request-Signature' => 'X-Request-Signature',
    'X-Request-Timestamp' => 'X-Request-Timestamp',
    'X-Tenant-Id' => 'X-Tenant-Id',
  ],
]);

echo $response->getBody();
```

```csharp Pix MED_getPixMed_example
using RestSharp;

var client = new RestClient("https://client.api.corpx.com/v1/accounts/accountId/pix/med/id");
var request = new RestRequest(Method.GET);
request.AddHeader("X-Content-SHA256", "X-Content-SHA256");
request.AddHeader("X-Request-Signature", "X-Request-Signature");
request.AddHeader("X-Request-Timestamp", "X-Request-Timestamp");
request.AddHeader("X-Tenant-Id", "X-Tenant-Id");
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift Pix MED_getPixMed_example
import Foundation

let headers = [
  "X-Content-SHA256": "X-Content-SHA256",
  "X-Request-Signature": "X-Request-Signature",
  "X-Request-Timestamp": "X-Request-Timestamp",
  "X-Tenant-Id": "X-Tenant-Id",
  "Authorization": "Bearer <token>"
]

let request = NSMutableURLRequest(url: NSURL(string: "https://client.api.corpx.com/v1/accounts/accountId/pix/med/id")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```