Lookup internal transfer recipient by document
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
CPF (11 digits) or CNPJ (14 digits) of the recipient.
Headers
Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).
Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.
Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.
Response
Recipient found. Returns a privacy-preserving preview plus branch and account number.
Holder name with privacy mask: first name in full, remaining surnames reduced to first letter + ”***”.
Same value as maskedName. Kept so existing parsers of this field keep working.
Fully masked document shape. CPF → ***.***.***-**,
CNPJ → ***.***.***/****-**. Digits are never returned in the body.
Settlement-bank branch of the first matching account.
Settlement-bank account number of the first matching account.