Skip to navigation

List the features enabled for the tenant

Returns every product feature of the tenant in X-Tenant-Id and whether it is enabled. The list is complete: a feature that is not contracted comes back with enabled: false, so “not contracted” and “unknown feature” never look the same.

The state is the one the API checks on each operation. When a feature is off here, the operation it gates answers 403 feature_disabled. Call this before offering a feature to your customer, and cache the result for a few minutes at most.

Read-only. Features are turned on and off by CorpX under your contract. Any credential of the tenant can call this route, whatever its scopes.

FeatureWhat it unlocks
accreditationSelf-service account opening (POST /v1/accreditations/pf and /pj)
account_portabilityAuthorization journey for a holder who already has an account at the settlement bank
kyc_artifactsKYC evidence download of your accreditations, including the holder selfie
tenant_user_invitesTenant managers invite viewer users of the tenant
pix_key_email_phoneE-mail and phone PIX keys. On by default
boleto_chargeBoleto Charge: issue boletos of the account itself
identity_verificationStandalone CPF identity checks
pin_hosted_resetTransaction PIN reset on the CorpX page instead of the API
pix_batchBatch PIX (/v1/accounts/{accountId}/pix/batches)

A feature being on does not grant scopes: each operation still needs the scope listed on it. New features can appear in this list; treat an unknown key as not relevant to you.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Headers

X-Tenant-IdstringRequired
Tenant context used for authorization and routing.
X-Request-TimestampstringRequired

Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).

X-Content-SHA256stringRequired

Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.

X-Request-SignaturestringRequired

Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.

Response

Every feature of the tenant, enabled or not.
tenantIdstring
itemslist of objects

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
500
Internal Server Error