Confirm PIX key OTP

Second step of registering an `email` or `phone` PIX key. Send the `challengeId` returned by `POST .../pix/keys` (`202 pending_verification`) together with the 6-digit code the holder received. On success the key is registered at the partner and the response is the same `201` as a direct registration. Wrong code returns `code_invalid`; after too many attempts the challenge is locked (`challenge_locked`) and a new registration is required.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Path parameters

accountIdstringRequired
Account identifier.

Headers

X-Tenant-IdstringRequired
Tenant context used for authorization and routing.
Idempotency-KeystringOptional

Optional client-generated idempotency token (recommended for safe retries).

X-Request-TimestampstringRequired

Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).

X-Content-SHA256stringRequired

Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.

X-Request-SignaturestringRequired

Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.

Request

This endpoint expects an object.
challengeIdstringRequired
codestringRequired

6-digit OTP. Never logged.

Response

Pix key registered after OTP confirmation.
keyTypestring
keyTypeIdinteger
pixKeystring
createddatetime

Errors

400
Bad Request Error
404
Not Found Error
422
Unprocessable Entity Error
500
Internal Server Error
503
Service Unavailable Error