> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://en.docs.api.corpx.com/ib/referencia/auth/list-tenant-features/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://en.docs.api.corpx.com/_mcp/server. # List the features enabled for the tenant GET https://client.api.corpx.com/v1/tenant/features Returns every product feature of the tenant in `X-Tenant-Id` and whether it is enabled. The list is complete: a feature that is not contracted comes back with `enabled: false`, so "not contracted" and "unknown feature" never look the same. The state is the one the API checks on each operation. When a feature is off here, the operation it gates answers `403 feature_disabled`. Call this before offering a feature to your customer, and cache the result for a few minutes at most. Read-only. Features are turned on and off by CorpX under your contract. Any credential of the tenant can call this route, whatever its scopes. | Feature | What it unlocks | | ----------------------- | ------------------------------------------------------------------------------------ | | `accreditation` | Self-service account opening (`POST /v1/accreditations/pf` and `/pj`) | | `account_portability` | Authorization journey for a holder who already has an account at the settlement bank | | `kyc_artifacts` | KYC evidence download of your accreditations, including the holder selfie | | `tenant_user_invites` | Tenant managers invite `viewer` users of the tenant | | `pix_key_email_phone` | E-mail and phone PIX keys. On by default | | `boleto_charge` | Boleto Charge: issue boletos of the account itself | | `identity_verification` | Standalone CPF identity checks | | `pin_hosted_reset` | Transaction PIN reset on the CorpX page instead of the API | | `pix_batch` | Batch PIX (`/v1/accounts/{accountId}/pix/batches`) | A feature being on does not grant scopes: each operation still needs the scope listed on it. New features can appear in this list; treat an unknown key as not relevant to you. Reference: https://en.docs.api.corpx.com/ib/referencia/auth/list-tenant-features ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. ## Request ### Headers - `X-Tenant-Id` (string, required) — Tenant context used for authorization and routing. - `X-Request-Timestamp` (string, required) — Unix seconds. Required on the signed host; tolerance is 300s either way (`403 request_timestamp_skew`). - `X-Content-SHA256` (string, required) — Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns `400 body_hash_mismatch`. - `X-Request-Signature` (string, required) — Detached JWS (`..`, ES256 or PS256) over `METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256`. ## Response ### 200 Every feature of the tenant, enabled or not. - `tenantId` (string, required) - `items` (list of TenantFeature, required) ## Errors ### 400 Bad Request Error `X-Tenant-Id` missing. - `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values. - `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change. - `docs` (string, optional) — Link to this code in the public error catalogue. - `requestId` (string, optional) — Gateway request id. Quote it when contacting support. - `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context. - `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only. ### 401 Unauthorized Error Authentication failed or token missing. - `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values. - `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change. - `docs` (string, optional) — Link to this code in the public error catalogue. - `requestId` (string, optional) — Gateway request id. Quote it when contacting support. - `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context. - `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only. ### 403 Forbidden Error The token is not bound to the tenant in `X-Tenant-Id`. - `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values. - `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change. - `docs` (string, optional) — Link to this code in the public error catalogue. - `requestId` (string, optional) — Gateway request id. Quote it when contacting support. - `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context. - `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only. ### 500 Internal Server Error Unexpected server error. - `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values. - `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change. - `docs` (string, optional) — Link to this code in the public error catalogue. - `requestId` (string, optional) — Gateway request id. Quote it when contacting support. - `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context. - `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only. ## Types ### TenantFeature - `feature` (string, required) — Feature key. New keys can be added; ignore the ones you do not use. - `enabled` (boolean, required) — `false` means not contracted: the gated operation answers `403 feature_disabled`. ### ErrorResponsePartner Raw error from the settlement bank, when the failure came from it. Diagnostic only. - `code` (string, optional) - `message` (string, optional) - `field` (string, optional) — Field the partner pointed at, when any. ## Examples **Response** ```json { "tenantId": "tn_7f3a9c", "items": [ { "feature": "accreditation", "enabled": true }, { "feature": "boleto_charge", "enabled": false }, { "feature": "pix_batch", "enabled": true } ] } ``` **SDK Code** ```python Auth_listTenantFeatures_example import requests url = "https://client.api.corpx.com/v1/tenant/features" headers = { "X-Content-SHA256": "X-Content-SHA256", "X-Request-Signature": "X-Request-Signature", "X-Request-Timestamp": "X-Request-Timestamp", "X-Tenant-Id": "X-Tenant-Id", "Authorization": "Bearer " } response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript Auth_listTenantFeatures_example const url = 'https://client.api.corpx.com/v1/tenant/features'; const options = { method: 'GET', headers: { 'X-Content-SHA256': 'X-Content-SHA256', 'X-Request-Signature': 'X-Request-Signature', 'X-Request-Timestamp': 'X-Request-Timestamp', 'X-Tenant-Id': 'X-Tenant-Id', Authorization: 'Bearer ' } }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Auth_listTenantFeatures_example package main import ( "fmt" "net/http" "io" ) func main() { url := "https://client.api.corpx.com/v1/tenant/features" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("X-Content-SHA256", "X-Content-SHA256") req.Header.Add("X-Request-Signature", "X-Request-Signature") req.Header.Add("X-Request-Timestamp", "X-Request-Timestamp") req.Header.Add("X-Tenant-Id", "X-Tenant-Id") req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Auth_listTenantFeatures_example require 'uri' require 'net/http' url = URI("https://client.api.corpx.com/v1/tenant/features") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["X-Content-SHA256"] = 'X-Content-SHA256' request["X-Request-Signature"] = 'X-Request-Signature' request["X-Request-Timestamp"] = 'X-Request-Timestamp' request["X-Tenant-Id"] = 'X-Tenant-Id' request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java Auth_listTenantFeatures_example import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://client.api.corpx.com/v1/tenant/features") .header("X-Content-SHA256", "X-Content-SHA256") .header("X-Request-Signature", "X-Request-Signature") .header("X-Request-Timestamp", "X-Request-Timestamp") .header("X-Tenant-Id", "X-Tenant-Id") .header("Authorization", "Bearer ") .asString(); ``` ```php Auth_listTenantFeatures_example request('GET', 'https://client.api.corpx.com/v1/tenant/features', [ 'headers' => [ 'Authorization' => 'Bearer ', 'X-Content-SHA256' => 'X-Content-SHA256', 'X-Request-Signature' => 'X-Request-Signature', 'X-Request-Timestamp' => 'X-Request-Timestamp', 'X-Tenant-Id' => 'X-Tenant-Id', ], ]); echo $response->getBody(); ``` ```csharp Auth_listTenantFeatures_example using RestSharp; var client = new RestClient("https://client.api.corpx.com/v1/tenant/features"); var request = new RestRequest(Method.GET); request.AddHeader("X-Content-SHA256", "X-Content-SHA256"); request.AddHeader("X-Request-Signature", "X-Request-Signature"); request.AddHeader("X-Request-Timestamp", "X-Request-Timestamp"); request.AddHeader("X-Tenant-Id", "X-Tenant-Id"); request.AddHeader("Authorization", "Bearer "); IRestResponse response = client.Execute(request); ``` ```swift Auth_listTenantFeatures_example import Foundation let headers = [ "X-Content-SHA256": "X-Content-SHA256", "X-Request-Signature": "X-Request-Signature", "X-Request-Timestamp": "X-Request-Timestamp", "X-Tenant-Id": "X-Tenant-Id", "Authorization": "Bearer " ] let request = NSMutableURLRequest(url: NSURL(string: "https://client.api.corpx.com/v1/tenant/features")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```