1. Guides
Pix2DePix API
  • ⚡ Quickstart
  • Guides
    • 🔑 Authentication
    • 🔄 Possible Statuses
    • 🔀 Synchronous requests & safe retries
    • ⚠️ Errors & the response envelope
    • 🧯 Troubleshooting
    • ✅ Best Practices
    • 🚀 Features
      • ⏱️ QR Delay
    • 🛡️ Security & Limits
      • 🚦 API Limits
      • 🧱 Firewall
      • 🪲 Bug Bounty
    • 🧭 Networks
      • 🌐 Networks and payout addresses
      • 💧 Liquid network guide
      • 📚 Arkade network guide
      • ✨ Spark network guide
  • API Endpoints
    • Ping
      GET
    • Deposit (PIX ➔ DePix)
      POST
    • Deposit Status
      GET
    • Deposits
      GET
    • User Info
      GET
    • Withdraw
      POST
    • Withdraw Status
      GET
  • Webhooks
    • 🪝 Webhooks
    • Deposit Webhook
    • Withdraw Webhook
    • MED Webhook
  • Reference
    • 📖 Glossary
    • 📝 Changelog
  • Schemas
    • JWTClaims
    • ErrorObj
    • PingObj
    • ErrorResponse
    • DepositObj
    • PingResponse
    • DepositResponse
    • DepositStatusObj
    • DepositStatusResponse
    • DepositWebhookBody
    • DepositsResponse
    • DepositStatus
    • UserInfoResponse
    • WithdrawStatusResponse
    • WithdrawStatusObj
    • WithdrawResponse
    • WithdrawObj
    • WithdrawStatus
    • WithdrawWebhookBody
    • MEDWebhookBody
    • RejectionReasons
  1. Guides

✅ Best Practices

JWT Token Best Security Practices#

The token generated in your Telegram for API access is your credential, and it allows operations to be performed on your behalf. You should take some measures to protect it. Here are some tips:
Rotate the token periodically: create a new one, switch your integration over, and let the old one expire.
Define only the necessary scope; do not grant access to unnecessary scopes.
Never store the token in publicly accessible locations.
Never share this token with third parties.
Never store this token in cloud services.
Avoid setting a very long validity period.
Never commit this token to version control systems (such as Git/GitHub).
Do not hard-code this token directly into programming code.
Creating a new token does not invalidate the old one, and a token cannot be invalidated from your side. Every token stays valid until the expiry date it was given at creation, which can be anywhere from 1 to 365 days — so that period is the only limit you control. If you suspect a token was compromised, contact us immediately in your Telegram channel so we can invalidate it.

API Usage and Security Guidelines#

When integrating with our API, it is crucial to adhere to the following best practices to ensure secure and reliable operation:

1. Authentication#

Ensure proper authentication of your end users before allowing access to our services. This step is essential to avoid exposing our API indirectly, such as through a proxy, and ensures that only legitimate users are accessing the API.

2. Anti-DDOS Measures#

Implement effective anti-DDOS mechanisms on your side, such as a hashcash or CAPTCHA system, to prevent malicious users from leveraging your service to launch denial-of-service attacks. These measures help protect both your infrastructure and ours.

3. Deposit API: Address Validation#

Our deposit API includes a feature that allows partners to specify an end-user's DePix address for greater flexibility. However, this functionality can be exploited by malicious actors if they gain unauthorized direct or indirect access to the API (e.g., through your site or service). They can generate QR codes for deposits with arbitrary addresses for their benefit.
To mitigate this risk:
Authenticate Users: Rigorously authenticate your users to ensure only legitimate access.
Monitor Usage: Implement monitoring to detect and address any suspicious or dishonest use of the deposit API.
By following these guidelines, you can help secure your integration and contribute to a safe API ecosystem.
Modified at 2026-09-17 15:07:08
Previous
🧯 Troubleshooting
Next
⏱️ QR Delay
Built with