> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fastpaybrasil.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create document upload token

> Emite um **token escopado de upload** para enviar documentos da subconta
diretamente ao endpoint `POST /v1/document-uploads` (ex.: do navegador),
sem expor a chave de API.

Opcionalmente, informe `legalRepresentativeId` (um `id` retornado em
`legalRepresentatives` na criação da subconta, ou na listagem de
representantes) para vincular os **documentos de pessoa**
(`responsible_document_front`, `responsible_document_back`,
`selfie_with_document`) àquele sócio. Omitido, os documentos vinculam ao
**representante legal** (comportamento anterior).

O token expira em **300 segundos** (5 minutos).



## OpenAPI

````yaml /api-reference/openapi.yaml post /v1/submerchants/{merchantId}/document/upload-token
openapi: 3.0.0
info:
  title: FastPay API
  version: 1.0.0
  description: >-
    API for creating and managing payment charges.


    ## Authentication


    This API uses **Basic Authentication** for direct API access, such as
    creating charges.

    Use your API key as the username and an empty string as password.

    The header should be formatted as:


    `Authorization: Basic {base64(apiKey:)}`.


    For example:


    ```

    Authorization: Basic YWxleG91dG9uOiIi

    ```


    ## Webhooks


    FastPay sends webhooks to notify your application about charge status
    changes in real-time.

    Webhooks are sent via HTTP POST requests to your configured webhook
    endpoints.


    ### Webhook Events


    The following webhook events are available for charges:


    - `charge.created` - Sent when a new charge is created

    - `charge.pending` - Sent when a charge is pending payment

    - `charge.paid` - Sent when a charge is successfully paid

    - `charge.updated` - Sent when a charge is updated


    ### Webhook Payload Structure


    All webhook payloads follow this structure:


    ```json

    {
      "id": "webhook_event_id",
      "event": "charge.paid",
      "data": {
        // Complete charge object
      }
    }

    ```


    ### Webhook Delivery


    - Webhooks are sent via HTTP POST requests

    - Content-Type: `application/json`

    - Retry logic is implemented for failed deliveries

    - Webhook events are stored in the database for audit purposes

    - Delivery logs are maintained for debugging and monitoring


    ### Webhook Security


    - Webhooks are sent to pre-configured endpoints

    - Endpoints can be enabled/disabled per merchant

    - Event filtering is supported (only receive specific events)

    - Failed deliveries are retried with exponential backoff
servers:
  - url: https://api-global.fastpaybrasil.com
    description: Produção e Sandbox (diferenciados pela API key)
security: []
paths:
  /v1/submerchants/{merchantId}/document/upload-token:
    post:
      tags:
        - FastConnect
      summary: Create document upload token
      description: |-
        Emite um **token escopado de upload** para enviar documentos da subconta
        diretamente ao endpoint `POST /v1/document-uploads` (ex.: do navegador),
        sem expor a chave de API.

        Opcionalmente, informe `legalRepresentativeId` (um `id` retornado em
        `legalRepresentatives` na criação da subconta, ou na listagem de
        representantes) para vincular os **documentos de pessoa**
        (`responsible_document_front`, `responsible_document_back`,
        `selfie_with_document`) àquele sócio. Omitido, os documentos vinculam ao
        **representante legal** (comportamento anterior).

        O token expira em **300 segundos** (5 minutos).
      parameters:
        - name: merchantId
          in: path
          required: true
          description: Id da subconta.
          schema:
            type: string
            example: 2vorkDcXyvzifL63YX09S9VqcnI
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                legalRepresentativeId:
                  type: string
                  description: >-
                    Sócio ao qual os documentos de pessoa serão vinculados. Deve
                    pertencer à subconta (senão `404`). Omitido, vincula ao
                    representante legal.
                  example: 2vorkEbbbCccDddEeeFffGggHhh
      responses:
        '201':
          description: Token emitido
          content:
            application/json:
              schema:
                type: object
                properties:
                  token:
                    type: string
                    description: >-
                      Token de upload (use como Bearer no POST
                      /v1/document-uploads)
                    example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
                  expiresIn:
                    type: integer
                    description: Validade do token em segundos
                    example: 300
        '401':
          description: Unauthorized - invalid credentials
          content:
            application/json:
              schema:
                type: object
                properties:
                  statusCode:
                    type: integer
                    example: 401
                  message:
                    type: string
                    example: Unauthorized
        '404':
          description: Representante legal não encontrado (não pertence à subconta)
          content:
            application/json:
              schema:
                type: object
                properties:
                  statusCode:
                    type: integer
                    example: 404
                  message:
                    type: string
                    example: Representante legal não encontrado
      security:
        - basic: []
components:
  securitySchemes:
    basic:
      type: http
      scheme: basic
      description: |-
        HTTP Basic authentication. Use your secret key as the
        username and an empty string as password. The API key
        should be base64 encoded in the format 'username:' when
        sending the Authorization header.

````