# Pluggy Docs > Developer documentation for the Pluggy API Links below point at the markdown source. Drop the .md for the rendered page. The full text of every page is at /llms-full.txt. OpenAPI: /openapi/pluggy-api.json, /openapi/status-api.json, /openapi/enrichment-api.json MCP server: https://mcp.pluggy.ai/mcp ## integrations - [Slack Integration](https://docs.pluggy.ai/en/docs/integrations/slack.md): Add Pluggy's hosted docs bot to your Slack workspace — ask questions and get answers from the live documentation. No setup, no self-hosting. ## Getting Started - [Overview](https://docs.pluggy.ai/en/docs/overview.md): What Pluggy is, the three objects the whole API is built on, and the two ways to build your first integration. - [Quick Start](https://docs.pluggy.ai/en/docs/quickstart.md): Create your first item and read its transactions — with an agent connected to the live docs, or by hand. - [Authentication](https://docs.pluggy.ai/en/docs/authentication.md): Learn how to authenticate with the Pluggy API. - [Glossary](https://docs.pluggy.ai/en/docs/get-started/glossary.md): Before you start working with our API there are some important concepts that you need to know. - [FAQ](https://docs.pluggy.ai/en/docs/get-started/faq.md): The questions we are asked most often about items, connectors, environments and updates. ## Guides - [Sandbox](https://docs.pluggy.ai/en/docs/guides/sandbox.md): Test your integration with Pluggy's sandbox environment. ## Pluggy Connect Widget - [Introduction](https://docs.pluggy.ai/en/docs/connect-widget/introduction.md): Pluggy Connect is a drop-in widget that helps you quickly get started with Pluggy, allowing your users to connect their accounts within your app directly to the Pluggy API. - [Authentication](https://docs.pluggy.ai/en/docs/connect-widget/authentication.md): When connecting to Pluggy from a client-side application (i.e. Connect Widget), a Connect Token is required. This token provides limited access scoped to the generated Item resource data. - [Environments and Configurations](https://docs.pluggy.ai/en/docs/connect-widget/environments.md): Learn about the available environments and configuration options for the Pluggy Connect widget, including sandbox testing and production setup. - [Updating an Item](https://docs.pluggy.ai/en/docs/connect-widget/updating-item.md): Learn how to update an existing Item using the Pluggy Connect widget instead of creating a new connection from scratch. - [Customization](https://docs.pluggy.ai/en/docs/connect-widget/customization.md): From the Dashboard, it is possible to customize certain visual aspects of Pluggy Connect so that you can provide your users with a more tailored, branded experience. - [OAuth Support Guide](https://docs.pluggy.ai/en/docs/connect-widget/oauth-support.md): By following these guidelines, you can ensure a smooth OAuth integration experience for your users across various platforms and devices. ## Connections - [Item](https://docs.pluggy.ai/en/docs/connections/item.md): An Item is the representation of a connection with a specific Connector of an Institution and serves as the entry point to access the set of products recovered from the user who gave consent to collect their data. - [Item lifecycle](https://docs.pluggy.ai/en/docs/connections/item-lifecycle.md): Understand the different statuses and execution states an Item goes through during creation, update, and synchronization with financial institutions. - [Errors & Validations](https://docs.pluggy.ai/en/docs/connections/errors-validations.md): Learn about the different statuses and errors you could face using Pluggy's API. - [Warnings & Status Codes](https://docs.pluggy.ai/en/docs/connections/warnings-status-codes.md): Understanding warning codes and their meanings when retrieving data from Pluggy connectors. - [Consents and expiration](https://docs.pluggy.ai/en/docs/connections/consents.md): The first time an Item connects, a Consent is created with an expiration date. The Consent shows which financial products an item is authorized to recover for a given period. - [Connectors coverage](https://docs.pluggy.ai/en/docs/connections/connectors-coverage.md): Here you will find all the connectors available in Pluggy listed by type of connector, detailing which products are supported in each case. - [Credit Cards coverage](https://docs.pluggy.ai/en/docs/connections/credit-cards-coverage.md): Here you will find the coverage we have for each connector regarding Credit Card product. - [Accounts coverage](https://docs.pluggy.ai/en/docs/connections/accounts-coverage.md): Here you will find the coverage we have for each connector regarding Account product. - [Payment data coverage](https://docs.pluggy.ai/en/docs/connections/paymentdata-coverage.md): Here you will find the data coverage we have for each connector regarding Payment Data product. - [Investments coverage](https://docs.pluggy.ai/en/docs/connections/investments-coverage.md): Here you will find the coverage we have for each connector regarding Investments product. - [Investment Transactions coverage](https://docs.pluggy.ai/en/docs/connections/investment-transactions-coverage.md): Here you will find the coverage we have for each connector regarding Investment Transactions product. - [Loans coverage](https://docs.pluggy.ai/en/docs/connections/loans-coverage.md): Here you will find the coverage we have for each connector regarding the Loans product. - [Identity coverage](https://docs.pluggy.ai/en/docs/connections/identity-coverage.md): Here you will find the coverage we have for each connector regarding Identity product. - [Reporting Issues](https://docs.pluggy.ai/en/docs/connections/reporting-issues.md): This guide explains how to understand issues that users may have and how to report them to Pluggy's support team. - [Open Finance vs Direct: field differences](https://docs.pluggy.ai/en/docs/connections/open-finance-vs-direct-fields.md): Which API fields you get only from Open Finance connections, and which only from Direct ones. ## Open Finance - [Open Finance Connectors](https://docs.pluggy.ai/en/docs/open-finance/overview.md): Pluggy supports obtaining data from the Brazilian Open Finance Network with Open Finance Connectors, following the same data model as standard connectors. - [Open Finance Institutions Coverage](https://docs.pluggy.ai/en/docs/open-finance/institutions-coverage.md): All institutions available via Open Finance, their contexts (Personal, Business, Investments) and the products each connector exposes. - [Creating an Item](https://docs.pluggy.ai/en/docs/open-finance/creating-item.md): How to create your first Open Finance Regulated connection, step by step through Pluggy's Connect Widget or through API. - [Considerations & FAQ](https://docs.pluggy.ai/en/docs/open-finance/considerations-faq.md): Things to keep in mind when integrating Open Finance Regulated data that can be different from Direct Connections. - [Payment Data Open Finance Coverage](https://docs.pluggy.ai/en/docs/open-finance/payment-data.md): Coverage details for CPF/CNPJ counterpart data availability in Open Finance transaction payment data, by connector and operation type. - [Investments Open Finance Coverage](https://docs.pluggy.ai/en/docs/open-finance/investments.md): Coverage table for investment subtypes supported by each Open Finance institution connector. - [Operational Rate Limits](https://docs.pluggy.ai/en/docs/open-finance/rate-limits.md): Open Finance operational limits imposed by the Brazilian Open Finance Network on data fetching per product, institution, and CPF/CNPJ, plus the network's response time and timeout requirements. - [SCR — Credit Information System](https://docs.pluggy.ai/en/docs/open-finance/scr.md): Query Bacen's Sistema de Informações de Crédito for the document behind a connected Open Finance item, and read the payload the Banco Central returns. ## Products - [Account](https://docs.pluggy.ai/en/docs/products/accounts.md): The account product is the list of bank accounts such as Checking or Savings Account and Credit Card, that were available in the selected connector. - [Real Time Balance](https://docs.pluggy.ai/en/docs/products/real-time-balance.md): The real-time balance endpoint fetches the account balance directly from the financial institution without triggering a full item sync. - [Credit Card Bills](https://docs.pluggy.ai/en/docs/products/credit-card-bills.md): The Bill entity is recovered from institutions that support this product. It represents a bill (fatura) associated with an account of type Credit, specifically the subtype CREDIT_CARD. - [Transaction](https://docs.pluggy.ai/en/docs/products/transactions.md): Retrieve up to 12 months of transaction data. Transactions data of the accounts provide insights into the user's financial behavior. - [Transaction Categorization](https://docs.pluggy.ai/en/docs/products/transaction-categorization.md): Transaction categorization is a feature where we classify your Transactions into useful categories (Restaurants, Gas Stations, Income, etc.) using our categorizer AI engine. - [Investment](https://docs.pluggy.ai/en/docs/products/investments.md): The Investment entity is recovered from not only Brokers (XP, Clear) but also from retail and business Bank institutions. - [Investment's Transactions](https://docs.pluggy.ai/en/docs/products/investment-transactions.md): Each investment contains a list of transactions corresponding to Applications or Withdrawals. The transaction schema contains a set of details of that operation. - [Loan](https://docs.pluggy.ai/en/docs/products/loans.md): The Loan entity is recovered from institutions that support this product. It represents a loan contracted by the user, including data like contract number, taxes, interest rates, warranties, installments, etc. - [Identity](https://docs.pluggy.ai/en/docs/products/identity.md): The Identity entity is recovered from institutions that support this product, accessing details of personal information related to the owner of the connection's account. - [Credit Card Installments](https://docs.pluggy.ai/en/docs/products/credit-card-installments.md): How Pluggy captures, synchronizes, and delivers credit card installment purchases via API, including institution-specific behaviors, Open Finance rate limits, and webhook best practices. ## Intelligence APIs - [Connection Insights](https://docs.pluggy.ai/en/docs/intelligence/connection-insights.md): Based on connected accounts you can recover user's insights, book of variables, income analysis & recurring patterns. - [Transaction Enrichment](https://docs.pluggy.ai/en/docs/intelligence/transaction-enrichment.md): If you need to enhance your own data, we offer different solutions engine as an API for you to use. - [Recurring Payments Analysis](https://docs.pluggy.ai/en/docs/intelligence/recurring-payments.md): We offer a Recurring Payments API that allows you to identify a user's repeating expenses and repeating incomes, useful for financial profiling. ## Payments - [Payments Overview](https://docs.pluggy.ai/en/docs/payments/overview.md): With Pluggy Payments, you can easily create payment links to bill your customers and automatically track their payments, leveraging secure OAuth integrations with institutions using the Open Finance Payment Initiation infrastructure. - [Payment Intent Lifecycle and Errors](https://docs.pluggy.ai/en/docs/payments/intent-lifecycle.md): Here you can find the possible statuses of a Payment Intent and the error codes that may occur when attempting to process a payment. - [Scheduled Payments (Pix Agendado)](https://docs.pluggy.ai/en/docs/payments/scheduled-payments.md): With our payment initiation functionality, you can schedule payments to occur in the future (also called PIX RECORRENTE) using different scheduling modes. - [Scheduled Payment Webhooks](https://docs.pluggy.ai/en/docs/payments/scheduled-webhooks.md): Learn about the webhook flow and payloads for scheduled payments, including error codes that may occur during payment processing. - [FAQ](https://docs.pluggy.ai/en/docs/payments/scheduled-faq.md): The purpose of this page is to answer common questions about Scheduled Payments. - [PIX Automatico](https://docs.pluggy.ai/en/docs/payments/pix-automatico.md): Introduction to Pix Automático with Pluggy - your gateway to seamless, automated recurring payments in Brazil. - [Getting Started](https://docs.pluggy.ai/en/docs/payments/pix-getting-started.md): Integrating with Pluggy's payment gateway for Pix Automático - learn how to create your first payment request, handle authorization, schedule payments, and manage retries. - [Automatic PIX Scheduler (Beta)](https://docs.pluggy.ai/en/docs/payments/pix-scheduler.md): The Automatic PIX Scheduler automates recurring payment scheduling without manual intervention, respecting the allowed D+2 to D+10 scheduling window. - [Automatic retries (Beta)](https://docs.pluggy.ai/en/docs/payments/pix-retries.md): When an Automatic Pix Payment fails, Pluggy can automatically handle retries for you - no extra API calls, no polling, no cron jobs on your side. - [FAQ](https://docs.pluggy.ai/en/docs/payments/pix-faq.md): Common questions related to how Pix Automatico works, including payment requests, first payments, scheduling, cancellation, and retries. - [Coverage](https://docs.pluggy.ai/en/docs/payments/coverage.md): Here you will understand how to keep track of which Institutions support each type of payment. ## Smart Transfers - [Introduction](https://docs.pluggy.ai/en/docs/smart-transfers/introduction.md): Pluggy's Smart Transfers API makes payments instant, easy, and secure. Here we describe in a simple way how you can implement it. - [Creating a preauthorization](https://docs.pluggy.ai/en/docs/smart-transfers/preauthorization.md): In this section, you will learn how to create a preauthorization to do payments without user interaction. - [Creating a payment](https://docs.pluggy.ai/en/docs/smart-transfers/creating-payment.md): In this section, you will learn how to create a payment associated with a Smart Transfer Preauthorization. - [Smart Transfers Sandbox](https://docs.pluggy.ai/en/docs/smart-transfers/sandbox.md): The easiest way to try the Smart Transfers product is by using the sandbox connector. ## Developer Tools - [Basic concepts](https://docs.pluggy.ai/en/docs/developer-tools/basic-concepts.md): Security protocols, API conventions, environment, request identifiers, and pagination used by the Pluggy API. - [Run in Postman](https://docs.pluggy.ai/en/docs/developer-tools/postman.md): Access Pluggy's Postman Collection to test all available API endpoints using your CLIENT_ID and CLIENT_SECRET. - [Connect an account](https://docs.pluggy.ai/en/docs/developer-tools/connect-account.md): Learn how to connect the Pluggy API with a financial institution, including connectors with and without verification codes. - [Tutorials](https://docs.pluggy.ai/en/docs/developer-tools/tutorials.md): Get step-by-step guides on how to successfully connect your account with specific financial institutions. - [Server-Side SDKs](https://docs.pluggy.ai/en/docs/developer-tools/server-sdks.md): Pluggy offers client libraries for Node.js, .NET, and Java to simplify API integration. - [No-Code integrations](https://docs.pluggy.ai/en/docs/developer-tools/no-code.md): Here is a list of integrations that don't require any development to start running Pluggy. - [Bubble](https://docs.pluggy.ai/en/docs/developer-tools/bubble.md): Step-by-step guide to integrating Pluggy Connect in a Bubble application. - [Errors Codes](https://docs.pluggy.ai/en/docs/developer-tools/error-codes.md): The following errors describe in general what you will get for the different endpoints available in Pluggy API. - [Rate limits](https://docs.pluggy.ai/en/docs/developer-tools/rate-limits.md): Pluggy's API implements a rate limiter to maximize its stability when dealing with large bursts of incoming requests. - [Status Page API](https://docs.pluggy.ai/en/docs/developer-tools/status-page-api.md): Programmatically consume Pluggy's public status page — connector health, incidents and infrastructure components. - [Webhook](https://docs.pluggy.ai/en/docs/developer-tools/webhooks-ref.md): Learn about the webhooks sent by Pluggy to create a reactive integration to data and payment changes. - [Configure & Troubleshoot](https://docs.pluggy.ai/en/docs/developer-tools/webhook-troubleshoot.md): View, create and edit webhooks from Dashboard, visualize which webhooks were sent, their payloads and retry them to sync collected data. - [MCP Server](https://docs.pluggy.ai/en/docs/developer-tools/mcp.md): Connect any AI agent — Claude, ChatGPT/Codex, Cursor, VS Code, Windsurf, Gemini — to Pluggy's live documentation, API reference, changelog, recipes, and curated Q&A through the hosted, no-auth MCP server. - [Agent Skills](https://docs.pluggy.ai/en/docs/developer-tools/ai-skills.md): Official Pluggy skills for AI coding agents like Claude Code, Cursor, and GitHub Copilot — install with one command so your agent builds and reviews integrations following Pluggy's documented patterns. ## Integration Checklist - [Creating a use case from scratch](https://docs.pluggy.ai/en/docs/integration-checklist/use-case.md): This article is a step by step guide to build a simple example app that integrates with Pluggy. - [Pluggy's Integration Checklist](https://docs.pluggy.ai/en/docs/integration-checklist/overview.md): Follow these steps to ensure your Application is fully integrated with Pluggy API. - [Get your API keys](https://docs.pluggy.ai/en/docs/integration-checklist/api-keys.md): Get to know Dashboard. Create your first Application and obtain your access keys. - [Create your first Item](https://docs.pluggy.ai/en/docs/integration-checklist/first-item.md): Get to know our Demo application. Get to know Pluggy Connect and our Sandbox environment. - [Use our SDKs to Authenticate](https://docs.pluggy.ai/en/docs/integration-checklist/sdk-auth.md): Using your Application CLIENT_ID and CLIENT_SECRET credentials, set up authentication with Pluggy API. - [Setup PluggyConnect Widget on your app](https://docs.pluggy.ai/en/docs/integration-checklist/setup-widget.md): The Connect Widget is Pluggy's plug and play frontend solution that allows users to connect their financial accounts on a step by step flow. - [Data sync: Update an Item](https://docs.pluggy.ai/en/docs/integration-checklist/data-sync.md): After creating an Item, the next step is keeping it up to date. - [Setup Two-way sync with Webhooks](https://docs.pluggy.ai/en/docs/integration-checklist/webhooks-sync.md): Webhooks allow Pluggy to notify your application of events without requiring you to request updates, keeping you up to date with the latest changes. - [Consent management: Delete an Item](https://docs.pluggy.ai/en/docs/integration-checklist/consent-management.md): It's of utmost importance for your integration to allow your users to revoke the consent given when sharing their financial data. - [Subscribe to our Status Page](https://docs.pluggy.ai/en/docs/integration-checklist/status-page.md): Check out our public status page where we post any incident and outages, so you can keep awareness on any existing issues. ## Boleto - [Boleto Management API](https://docs.pluggy.ai/en/docs/boleto/management-api.md): Issue boletos, track their payment and receive a webhook the moment one is settled — through a single API that hides each bank's differences. - [Coverage](https://docs.pluggy.ai/en/docs/boleto/coverage.md): Which institutions the Boleto Management API can issue through today, which are being built, and how each one authorises a connection. ## Tutorials - [Caixa PF Tutorial (Mobile)](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/caixa-pf-mobile.md): Step-by-step guide to authorize your device and connect a Caixa Econômica Federal personal account using the Caixa mobile app. - [Caixa PF Tutorial (Web)](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/caixa-pf-web.md): Step-by-step guide to authorize your device and connect a Caixa Econômica Federal personal account using Internet Banking on the web. - [Caixa PJ Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/caixa-pj.md): Which credentials to use when connecting a Caixa Empresas business account: the same username and password used in Internet Banking. - [Banco Inter MEI Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/inter-mei.md): How to connect a Banco Inter MEI account by logging into the Inter app with your MEI account number and scanning the access QR code. - [Banco Inter Empresas Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/inter-pj.md): How to create an API integration in Banco Inter Empresas to obtain the Client ID, Client Secret, key, and certificate needed to connect with Pluggy. - [Sicredi Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/sicredi.md): Which credentials to use when connecting a Sicredi Empresas account: CNPJ, username, and password — the same ones used in the Sicredi app. - [Sicoob PJ Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/sicoob-pj.md): Which credentials to use when connecting a Sicoob Empresas account: cooperative number, access key, and password from Internet Banking. - [Santander PJ Secondary User Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/santander-pj-secondary-user.md): Step-by-step guide to create a secondary user in Santander Empresas so you can connect your business account with Pluggy. - [Santander PJ Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/santander-pj.md): Which credentials to use when connecting a Santander Empresas business account: branch, account, username and password — the same used in Internet Banking. - [Itaú PJ Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/itau-pj.md): Which credentials to use when connecting an Itaú Empresas business account: branch, account, password and CPF — the same used in Internet Banking. - [Itaú PJ Tutorial — User Without a Token](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/itau-pj-user-without-token.md): How to create an operator user without a token in Itaú Empresas: create an access profile, add an operator and validate it via the web. - [Banco do Brasil PJ Tutorial — Device Authorization](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/bb-pj-device-authorization.md): How to authorize a device in Banco do Brasil's Internet Banking so you can connect your Banco do Brasil Empresas account. - [Banco do Brasil PJ Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/bb-pj.md): Which credentials to use when connecting a Banco do Brasil Empresas business account: J key, J password and 8-digit password — plus best practices for a successful connection. - [Bradesco PJ Tutorial — Enable Mobile App Access](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/bradesco-pj-mobile-access.md): How to enable mobile app access for a Bradesco Empresas user through the Internet Banking administration section. - [Bradesco PJ Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/bradesco-pj.md): Which credentials to use when connecting a Bradesco Empresas business account: username, password and the security key generated in the Bradesco app. - [Bradesco PF Open Finance Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/bradesco-pf-of.md): Step-by-step guide to connect a Bradesco personal (PF) account via Open Finance, using the QR code validation in the Bradesco app. - [Efí Bank PJ Tutorial](https://docs.pluggy.ai/en/docs/developer-tools/tutorials/efi-pj.md): How to create an API application in Efí Bank Empresas to obtain the Client ID, Client Secret and certificate needed to connect with Pluggy. ## API Reference - [Authentication](https://docs.pluggy.ai/en/docs/reference/authentication.md): The two credentials the Pluggy API accepts, how each is issued, how long it lives and what it can reach. - [Basic Concepts](https://docs.pluggy.ai/en/docs/reference/basic-concepts.md): Base URL, transport, request and response conventions, and how paginated endpoints are read. - [Error Codes](https://docs.pluggy.ai/en/docs/reference/error-codes.md): The HTTP status codes the Pluggy API returns, what each means, and the shape of an error body. - [Rate Limits](https://docs.pluggy.ai/en/docs/reference/rate-limits.md): Per-endpoint request limits, the 429 response, and the headers that say when to retry. - [Webhook](https://docs.pluggy.ai/en/docs/reference/webhooks.md): Subscribing to events, the event list, the payload every notification carries, and the delivery and retry rules. - [Server-Side SDKs](https://docs.pluggy.ai/en/docs/reference/server-sdks.md): The official client libraries, how to install each, and the OpenAPI document to generate your own. ## API Reference: Status - [GET /api/status](https://docs.pluggy.ai/en/reference/status/status-snapshot): Retrieve status snapshot - [GET /api/connectors-incidents](https://docs.pluggy.ai/en/reference/status/status-connector-incidents): Retrieve active incidents by connector - [GET /api/summary](https://docs.pluggy.ai/en/reference/status/status-summary): Retrieve status summary ## API Reference: Enrichment - [POST /categorize](https://docs.pluggy.ai/en/reference/enrichment/categorize): Categorize - [POST /behavior-analysis](https://docs.pluggy.ai/en/reference/enrichment/behavior-analysis): Behavior Analysis - [POST /recurring-payments](https://docs.pluggy.ai/en/reference/enrichment/recurring-payments): Recurring Payments ## API Reference: Auth - [POST /auth](https://docs.pluggy.ai/en/reference/auth/auth-create): Create API Key - [POST /connect_token](https://docs.pluggy.ai/en/reference/auth/connect-token-create): Create Connect Token ## API Reference: Connector - [GET /connectors](https://docs.pluggy.ai/en/reference/connector/connectors-list): List - [GET /connectors/{id}](https://docs.pluggy.ai/en/reference/connector/connector-retrieve): Retrieve - [POST /connectors/{id}/validate](https://docs.pluggy.ai/en/reference/connector/connectors-validate): Validate ## API Reference: Items - [POST /items](https://docs.pluggy.ai/en/reference/items/items-create): Create - [GET /items/{id}](https://docs.pluggy.ai/en/reference/items/items-retrieve): Retrieve - [PATCH /items/{id}](https://docs.pluggy.ai/en/reference/items/items-update): Update - [DELETE /items/{id}](https://docs.pluggy.ai/en/reference/items/items-delete): Delete - [GET /items/{id}/resources](https://docs.pluggy.ai/en/reference/items/items-resources): Retrieve Item resources - [POST /items/{id}/mfa](https://docs.pluggy.ai/en/reference/items/items-send-mfa): Send MFA - [PATCH /items/{id}/disable-auto-sync](https://docs.pluggy.ai/en/reference/items/items-disable-autosync): Disable item auto sync - [GET /v2/items](https://docs.pluggy.ai/en/reference/items/items-list-by-cursor): List ## API Reference: SCR - [GET /items/{id}/scr](https://docs.pluggy.ai/en/reference/scr/items-retrieve-scr): Retrieve SCR ## API Reference: Consent - [GET /consents](https://docs.pluggy.ai/en/reference/consent/consents-list): List - [GET /consents/{id}](https://docs.pluggy.ai/en/reference/consent/consent-retrieve): Retrieve ## API Reference: Account - [GET /accounts](https://docs.pluggy.ai/en/reference/account/accounts-list): List - [GET /accounts/{id}](https://docs.pluggy.ai/en/reference/account/accounts-retrieve): Retrieve - [GET /accounts/{id}/statements](https://docs.pluggy.ai/en/reference/account/account-statements-list): List account statements - [GET /accounts/{id}/balance](https://docs.pluggy.ai/en/reference/account/account-balance-get): Get real-time balance ## API Reference: Transaction - [GET /transactions](https://docs.pluggy.ai/en/reference/transaction/transactions-list): List by Page (deprecated) - [GET /v2/transactions](https://docs.pluggy.ai/en/reference/transaction/transactions-list-by-cursor): List - [GET /transactions/{id}](https://docs.pluggy.ai/en/reference/transaction/transactions-retrieve): Retrieve - [PATCH /transactions/{id}](https://docs.pluggy.ai/en/reference/transaction/transactions-Update): Update ## API Reference: Investment - [GET /investments](https://docs.pluggy.ai/en/reference/investment/investments-list): List - [GET /investments/{id}](https://docs.pluggy.ai/en/reference/investment/investments-retrieve): Retrieve - [GET /investments/{id}/transactions](https://docs.pluggy.ai/en/reference/investment/investment-transactions-list): List investment transactions ## API Reference: Identity - [GET /identity](https://docs.pluggy.ai/en/reference/identity/identity-find-by-item): Find by item - [GET /identity/{id}](https://docs.pluggy.ai/en/reference/identity/identity-retrieve): Retrieve ## API Reference: Webhook - [GET /webhooks](https://docs.pluggy.ai/en/reference/webhook/webhooks-list): List - [POST /webhooks](https://docs.pluggy.ai/en/reference/webhook/webhooks-create): Create - [GET /webhooks/{id}](https://docs.pluggy.ai/en/reference/webhook/webhooks-retrieve): Retrieve - [PATCH /webhooks/{id}](https://docs.pluggy.ai/en/reference/webhook/webhooks-update): Update - [DELETE /webhooks/{id}](https://docs.pluggy.ai/en/reference/webhook/webhooks-delete): Delete ## API Reference: Category - [GET /categories](https://docs.pluggy.ai/en/reference/category/categories-list): List - [GET /categories/{id}](https://docs.pluggy.ai/en/reference/category/categories-retrieve): Retrieve - [GET /categories/rules](https://docs.pluggy.ai/en/reference/category/client-category-rules-list): List Category Rules - [POST /categories/rules](https://docs.pluggy.ai/en/reference/category/client-category-rules-create): Create Category Rule - [DELETE /categories/rules/{id}](https://docs.pluggy.ai/en/reference/category/client-category-rules-delete): Delete Category Rule ## API Reference: Loan - [GET /loans](https://docs.pluggy.ai/en/reference/loan/loans-list): List - [GET /loans/{id}](https://docs.pluggy.ai/en/reference/loan/loans-retrieve): Retrieve ## API Reference: Merchant - [GET /merchants](https://docs.pluggy.ai/en/reference/merchant/merchants-get-by-cnpj): Get merchants by CNPJ list ## API Reference: Bill - [GET /bills](https://docs.pluggy.ai/en/reference/bill/bills-list): List - [GET /bills/{id}](https://docs.pluggy.ai/en/reference/bill/bills-retrieve): Retrieve ## API Reference: Payment Customer - [GET /payments/customers](https://docs.pluggy.ai/en/reference/payment-customer/payment-customers-list): List - [POST /payments/customers](https://docs.pluggy.ai/en/reference/payment-customer/payment-customer-create): Create - [GET /payments/customers/{id}](https://docs.pluggy.ai/en/reference/payment-customer/payment-customer-retrieve): Retrieve - [PATCH /payments/customers/{id}](https://docs.pluggy.ai/en/reference/payment-customer/payment-customer-update): Update - [DELETE /payments/customers/{id}](https://docs.pluggy.ai/en/reference/payment-customer/payment-customer-delete): Delete ## API Reference: Payment Recipient - [GET /payments/recipients](https://docs.pluggy.ai/en/reference/payment-recipient/payment-recipients-list): List - [POST /payments/recipients](https://docs.pluggy.ai/en/reference/payment-recipient/payment-recipient-create): Create - [GET /payments/recipients/{id}](https://docs.pluggy.ai/en/reference/payment-recipient/payment-recipient-retrieve): Retrieve - [PATCH /payments/recipients/{id}](https://docs.pluggy.ai/en/reference/payment-recipient/payment-recipient-update): Update - [DELETE /payments/recipients/{id}](https://docs.pluggy.ai/en/reference/payment-recipient/payment-recipient-delete): Delete - [GET /payments/recipients/institutions](https://docs.pluggy.ai/en/reference/payment-recipient/payment-recipients-institution-list): List Institutions - [GET /payments/recipients/institutions/{id}](https://docs.pluggy.ai/en/reference/payment-recipient/payment-recipient-institutions-retrieve): Retrieve Institution ## API Reference: Payment Request - [GET /payments/requests](https://docs.pluggy.ai/en/reference/payment-request/payment-requests-list): List - [POST /payments/requests](https://docs.pluggy.ai/en/reference/payment-request/payment-request-create): Create - [POST /payments/requests/pix-qr](https://docs.pluggy.ai/en/reference/payment-request/payment-request-create-pix-qr): Create PIX QR payment request - [GET /payments/requests/{id}](https://docs.pluggy.ai/en/reference/payment-request/payment-request-retrieve): Retrieve - [PATCH /payments/requests/{id}](https://docs.pluggy.ai/en/reference/payment-request/payment-request-update): Update - [DELETE /payments/requests/{id}](https://docs.pluggy.ai/en/reference/payment-request/payment-request-delete): Delete ## API Reference: Automatic PIX - [POST /payments/requests/automatic-pix](https://docs.pluggy.ai/en/reference/automatic-pix/payment-request-create-automatic-pix): Create Automatic PIX payment request - [POST /payments/requests/{id}/automatic-pix/schedule](https://docs.pluggy.ai/en/reference/automatic-pix/payment-request-create-automatic-pix-schedule): Schedule Automatic PIX payment - [GET /payments/requests/{id}/automatic-pix/schedules](https://docs.pluggy.ai/en/reference/automatic-pix/payment-request-get-automatic-pix-schedules): List Automatic PIX scheduled payments - [GET /payments/requests/{requestId}/automatic-pix/schedules/{paymentId}](https://docs.pluggy.ai/en/reference/automatic-pix/payment-request-get-automatic-pix-schedule): Get an automatic PIX scheduled payment - [POST /payments/requests/{id}/automatic-pix/cancel](https://docs.pluggy.ai/en/reference/automatic-pix/payment-request-cancel-automatic-pix-consent): Cancel an automatic PIX consent - [POST /payments/requests/{id}/automatic-pix/schedules/{scheduleId}/cancel](https://docs.pluggy.ai/en/reference/automatic-pix/cancel-automatic-pix-schedule): Cancel an Automatic PIX schedule - [POST /payments/requests/{id}/automatic-pix/schedules/{scheduleId}/retry](https://docs.pluggy.ai/en/reference/automatic-pix/retry-automatic-pix-schedule): Retry an Automatic PIX schedule ## API Reference: Payment Schedule - [GET /payments/requests/{id}/schedules](https://docs.pluggy.ai/en/reference/payment-schedule/payment-schedules-list): List Schedules - [POST /payments/requests/{id}/schedules/cancel](https://docs.pluggy.ai/en/reference/payment-schedule/payment-schedules-cancel): Cancel Payment Schedule Authorization - [POST /payments/requests/{id}/schedules/{scheduleId}/cancel](https://docs.pluggy.ai/en/reference/payment-schedule/payment-schedules-cancel-specific): Cancel Payment Schedule ## API Reference: Payment Intent - [GET /payments/intents](https://docs.pluggy.ai/en/reference/payment-intent/payment-intents-list): List - [POST /payments/intents](https://docs.pluggy.ai/en/reference/payment-intent/payment-intent-create): Create - [GET /payments/intents/{id}](https://docs.pluggy.ai/en/reference/payment-intent/payment-intent-retrieve): Retrieve ## API Reference: Smart Transfer - [GET /smart-transfers/preauthorizations](https://docs.pluggy.ai/en/reference/smart-transfer/smart-tranfers-preauthorizations-list): List preauthorizations - [POST /smart-transfers/preauthorizations](https://docs.pluggy.ai/en/reference/smart-transfer/smart-transfer-preauthorization-create): Create preauthorization - [GET /smart-transfers/preauthorizations/{id}](https://docs.pluggy.ai/en/reference/smart-transfer/smart-transfer-preauthorization-retrieve): Retrieve preauthorization - [GET /smart-transfers/preauthorizations/{id}/payments](https://docs.pluggy.ai/en/reference/smart-transfer/smart-transfer-preauthorization-payments-list): List preauthorization payments - [POST /smart-transfers/payments](https://docs.pluggy.ai/en/reference/smart-transfer/smart-transfer-payment-create): Create payment - [GET /smart-transfers/payments/{id}](https://docs.pluggy.ai/en/reference/smart-transfer/smart-transfer-paymentretrieve): Retrieve payment ## API Reference: Boleto Management - [POST /boleto-connections](https://docs.pluggy.ai/en/reference/boleto-management/boleto-connection-create): Connect boleto credentials - [POST /boleto-connections/from-item](https://docs.pluggy.ai/en/reference/boleto-management/boleto-connection-create-from-item): Create boleto connection from Item - [POST /boletos](https://docs.pluggy.ai/en/reference/boleto-management/boleto-create): Issue Boleto - [POST /boletos/{id}/cancel](https://docs.pluggy.ai/en/reference/boleto-management/boleto-cancel): Cancel Boleto - [GET /boletos/{id}](https://docs.pluggy.ai/en/reference/boleto-management/boleto-get): Get Boleto ## Recipes - [Deleting your Data](https://docs.pluggy.ai/en/recipes/deleting-your-data.md): Delete Items to remove user consents from Pluggy. - [Encrypt parameters](https://docs.pluggy.ai/en/recipes/encrypt-parameters.md): Example to encrypt your parameters before create or update an item. - [Generate a Connect Token with permissions to update an existing Item](https://docs.pluggy.ai/en/recipes/generate-a-connect-token-with-permissions-to-update-an-existing-item.md): In order to update an Item you should generate, in your server, a Connect Token linked to the Item Id you want to update. - [PluggyConnect: Continue connecting item in background as soon as user's login is completed](https://docs.pluggy.ai/en/recipes/pluggyconnect-continue-connecting-item-in-background-as-soon-as-users-login-is-completed.md): Hide PluggyConnect in background as soon as the login step has been completed, so the User can focus again on your application. PluggyConnect will continue polling the item status until it's completed. - [Polling an item connector's execution status](https://docs.pluggy.ai/en/recipes/polling-an-item-connectors-execution-status.md): How to check and poll for the Item status, to know when the Item execution finishes and be able to act on it. - [Update an Item using Pluggy Connect](https://docs.pluggy.ai/en/recipes/update-an-item-using-pluggy-connect.md): Full standalone HTML client example to update an existing Item using Pluggy Connect widget. ## Changelog - [Product Updates | July/2026](https://docs.pluggy.ai/en/changelog#2026.07): Published 2026-08-13 - [Product Updates | June/2026](https://docs.pluggy.ai/en/changelog#2026.06): Published 2026-08-12 - [Product Updates | May/2026](https://docs.pluggy.ai/en/changelog#2026.05): Published 2026-07-22 - [Product Updates | March/2026](https://docs.pluggy.ai/en/changelog#2026.03): Published 2026-04-09 - [Product Updates | February 2026](https://docs.pluggy.ai/en/changelog#2026.02): Published 2026-03-18 - [Atualizações de Produto | Setembro 2025](https://docs.pluggy.ai/en/changelog#2025.09): Published 2025-10-07 - [[Atualizações de Produto] Agosto-25](https://docs.pluggy.ai/en/changelog#2025.08): Published 2025-09-15 - [[Atualizações de Produto] Julho-25](https://docs.pluggy.ai/en/changelog#2025.07): Published 2025-08-07 - [[Atualizações de Produto] Junho-25](https://docs.pluggy.ai/en/changelog#2025.06): Published 2025-07-04 - [[Atualizações de Produto] Maio-25](https://docs.pluggy.ai/en/changelog#2025.05): Published 2025-06-05 - [[Atualizações de Produto] Abril-25](https://docs.pluggy.ai/en/changelog#2025.04): Published 2025-05-05 - [[Atualizações de Produto] Março-25](https://docs.pluggy.ai/en/changelog#2025.03): Published 2025-04-04 - [[Atualizações de Produto] Fevereiro-25](https://docs.pluggy.ai/en/changelog#2025.02): Published 2025-03-05 - [[Atualizações de Produto] Janeiro-25](https://docs.pluggy.ai/en/changelog#2025.01): Published 2025-02-05 - [[Atualizações de Produto] Dezembro-24](https://docs.pluggy.ai/en/changelog#2024.12): Published 2025-01-05 - [Product Updates | December-24](https://docs.pluggy.ai/en/changelog#2024.12): Published 2024-12-16 - [[Atualizações de Produto] Novembro-24](https://docs.pluggy.ai/en/changelog#2024.11): Published 2024-11-18 - [[Atualizações de Produto] Outubro-24](https://docs.pluggy.ai/en/changelog#2024.10): Published 2024-10-08 - [Q3 (Jun-Sep) 2024](https://docs.pluggy.ai/en/changelog#2024.Q3): Published 2024-08-27 - [Q1 (Jan-Mar) 2024](https://docs.pluggy.ai/en/changelog#2024.Q1): Published 2024-06-21 - [Q2 (Apr-Jun) 2024](https://docs.pluggy.ai/en/changelog#2024.Q2): Published 2024-06-21 - [Q2 (Apr-Jun) 2024](https://docs.pluggy.ai/en/changelog#2024.Q2): Published 2024-06-21 - [Q1 (Jan-Mar) 2024](https://docs.pluggy.ai/en/changelog#2024.Q1): Published 2024-06-21 - [Initial Platform Launch](https://docs.pluggy.ai/en/changelog#1.0.0): Published 2024-01-10 - [December 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.12): Published 2023-12-07 - [December 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.12): Published 2023-12-07 - [September 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.09): Published 2023-10-08 - [September 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.09): Published 2023-10-08 - [August 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.08): Published 2023-09-07 - [August 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.08): Published 2023-09-07 - [July 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.07): Published 2023-08-07 - [July 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.07): Published 2023-08-07 - [June 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.06): Published 2023-07-04 - [June 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.06): Published 2023-07-04 - [May 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.05): Published 2023-05-31 - [May 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.05): Published 2023-05-31 - [April 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.04): Published 2023-05-03 - [April 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.04): Published 2023-05-03 - [March 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.03): Published 2023-04-03 - [March 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.03): Published 2023-03-14 - [February 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.02): Published 2023-02-20 - [February 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.02): Published 2023-02-20 - [January 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.01): Published 2023-01-10 - [January 2023 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2023.01): Published 2023-01-10 - [December 2022 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2022.12): Published 2022-12-15 - [December 2022 (Monthly Update)](https://docs.pluggy.ai/en/changelog#2022.12): Published 2022-12-15 --- ## Slack Integration Source: https://docs.pluggy.ai/en/docs/integrations/slack.md ## Overview Pluggy runs a **hosted, public Slack bot** that answers questions from Pluggy's live documentation right inside Slack. Add it to your workspace and your team can ask about the API, look things up, and get answers with doc links — without leaving Slack and without building anything. Just like the [MCP server](/docs/developer-tools/mcp), the bot is **hosted by Pluggy**: there's no Slack app to create, no OAuth scopes to configure, no request URLs, and no environment variables. You add it and use it. ## Add the bot to your workspace Click **Add to Slack** and approve the install for your workspace (you'll need workspace-admin permission to install apps): Add to Slack That's the whole setup. Once installed, invite the bot to any channel where you want to use it. ## Use it - **Mention it** in a channel it's in: ``` @Pluggy Docs how do I create a connect token and open the Connect Widget? ``` - **Direct-message it** a question — no command needed: ``` What scopes does the Connect Widget need? ``` The bot replies with a concise answer grounded in Pluggy's documentation, with links to the relevant guides. ## What it can access (today) For now the bot answers from Pluggy's **public documentation** only — the same content served at [v2.docs.pluggy.ai](https://v2.docs.pluggy.ai): guides, API reference, changelog, recipes, and curated Q&A. It does **not** access your Pluggy account, applications, or data. Like the MCP server, the bot will optionally let you **sign in with your Pluggy dashboard account** and keep a session, so it can answer questions scoped to **your team** — your applications, items, and usage. Until you sign in — and today, in v0 — it stays on the **public docs**. ## Privacy The bot only reads the messages that mention it or that you DM it, uses them to search the documentation, and replies. It doesn't store your Slack data. ## Troubleshooting - **The bot doesn't reply** — make sure it's been **invited to the channel** (mentions only work where the bot is a member), or try a direct message. - **"Add to Slack" didn't install** — you need **workspace-admin** permission to add apps; ask your Slack admin to run the install. - **Answers look off or outdated** — the bot answers from the live public docs; if something's wrong in the docs themselves, let the Pluggy team know. ## Overview Source: https://docs.pluggy.ai/en/docs/overview.md Pluggy is an open finance platform for Latin America. One API integration reaches hundreds of financial institutions — bank accounts, credit cards, investments, loans, identity and payments — and returns their data in a single, normalized shape, whether it came from a regulated Open Finance connector or from one of Pluggy's own. ## The three objects Almost everything in the API is one of these, and the rest hangs off them: - **Connector** — one financial institution, and the products it can return. - **Item** — one user's connection through a connector, created after they consent. It is the entry point to their data and the thing you store on your side. - **Product** — the normalized data an item gives you: accounts, transactions, investments, identity, loans. The [Glossary](/docs/get-started/glossary) has the rest of the vocabulary; the [Item](/docs/connections/item) guide covers the lifecycle you will actually spend your time on. ## Two ways to build the first integration Both end in the same place — an item created and its transactions on your screen. Connect your coding agent to these docs with one URL, then hand it the prompt that builds the whole flow. Five steps with curl: an application, an API key, a connect token, the widget, the data. ### Point an agent at the live docs If you code with Claude, Cursor, Copilot, Codex or Gemini, connect them to our documentation first. It is one URL, hosted, no key: ```bash claude mcp add --transport http pluggy-docs https://mcp.pluggy.ai/mcp ``` The agent then reads the current guides and OpenAPI spec at runtime instead of recalling whatever version of our API was in its training data — the difference between code that runs and code that looks right. Setup for every other client is on the [MCP server](/docs/developer-tools/mcp) page, and the prompt that builds the whole flow is in the [Quick Start](/docs/quickstart). Two more surfaces, for agents you cannot configure: every page here has a markdown twin — add `.md` to its URL — and [`/llms.txt`](https://v2.docs.pluggy.ai/llms.txt) indexes all of them. Anything that can fetch a URL can read our docs properly. ### Or follow the steps yourself The [Quick Start](/docs/quickstart) is five steps: create an application, get an API key, issue a connect token, open the widget, read the data. Nothing on this site assumes you use an agent. ## Sandbox first New applications start with access to the [Sandbox connectors](/docs/guides/sandbox), so you can run the entire flow — including the failure cases you would rather find now than in production — against fake institutions, with no real credentials involved. ## Quick Start Source: https://docs.pluggy.ai/en/docs/quickstart.md By the end of this page a user has connected a financial institution and you are reading their accounts and transactions. Five steps, whichever way you go through them: create an application, get an API key, issue a connect token, open the widget, read the data. ## Build it with an agent Your agent can write this integration, and it writes a much better one when it is reading our current documentation instead of remembering an older version of it. ### 1. Connect the docs One hosted URL, no API key, nothing to install: ```bash claude mcp add --transport http pluggy-docs https://mcp.pluggy.ai/mcp ``` Cursor, ChatGPT, Codex, VS Code, Windsurf and Gemini each take the same URL in their own config — the exact snippet for each is on the [MCP server](/docs/developer-tools/mcp) page. Adding our [Agent Skill](/docs/developer-tools/ai-skills) on top gives it the integration patterns to go with the reference. ### 2. Describe what you want Paste this, with your stack filled in: ```text Use the Pluggy Docs MCP server (pluggy-docs) for every Pluggy question — read the current guides and OpenAPI spec before writing code, and cite the pages you used. Build a minimal Pluggy integration in : 1. A server route that exchanges CLIENT_ID and CLIENT_SECRET for an API key. 2. A server route that issues a connect token for a given user. 3. A frontend page that opens the Pluggy Connect widget with that token and stores the itemId from its onSuccess callback. 4. A server route that lists that item's accounts and its transactions, handling pagination. Rules: CLIENT_SECRET never leaves the server, credentials come from environment variables, and the item's status is handled — not every connection is ready the moment the widget closes. ``` Then ask it the questions you would otherwise have searched for — *why is this item in `WAITING_USER_INPUT`?*, *what does this webhook event mean?* — and it will answer from the same pages you are reading now. ### 3. What is still yours to do An agent cannot sign up for you. Create the account and the application in step 1 below, put the credentials in your environment, and read the code it wrote before running it against anything real — the Sandbox exists for exactly that. Every page here has a markdown twin: add `.md` to any docs URL. The full index is at [`/llms.txt`](https://v2.docs.pluggy.ai/llms.txt), the whole site as one file is at [`/llms-full.txt`](https://v2.docs.pluggy.ai/llms-full.txt), and the OpenAPI spec is at [`/openapi/pluggy-api.json`](https://v2.docs.pluggy.ai/openapi/pluggy-api.json). The **Copy for LLM** button at the top of each page gives you the same thing for a single page. ## Or do it by hand > **Start even faster** > > Check out our [quickstart repository](https://github.com/pluggyai/quickstart) on GitHub -- it contains ready-to-run sample apps (Node, Python, Java, and frontend examples) that implement this entire flow. ### 1. Create your account and application 1. Sign up at the [Pluggy Dashboard](https://dashboard.pluggy.ai). 2. Create an **application**. Every application has its own `CLIENT_ID` and `CLIENT_SECRET` -- you'll find them on the application's page in the Dashboard. New applications start with access to our [Sandbox connectors](/docs/guides/sandbox), so you can test the whole flow with fake institutions before going to production. ### 2. Get an API Key Authenticate with your credentials to get an API Key. This step must be done from your **server** -- never expose your `CLIENT_SECRET` in client-side code. ```bash curl -X POST https://api.pluggy.ai/auth \ -H "Content-Type: application/json" \ -d '{ "clientId": "YOUR_CLIENT_ID", "clientSecret": "YOUR_CLIENT_SECRET" }' ``` The response contains an `apiKey`, valid for 2 hours, with full access to the API: ```json { "apiKey": "eyJhbGciOiJIUzI1..." } ``` ### 3. Create a Connect Token To let your users connect their accounts from your app, create a short-lived Connect Token (valid for 30 minutes) with your API Key: ```bash curl -X POST https://api.pluggy.ai/connect_token \ -H "Content-Type: application/json" \ -H "X-API-KEY: YOUR_API_KEY" \ -d '{}' ``` The response contains an `accessToken` -- this is the token you pass to the widget. See [Authentication](/docs/authentication) for the full details on scopes and options. ### 4. Open the Connect Widget Use the [Connect Widget](/docs/connect-widget/introduction) in your frontend, initialized with the `accessToken` from the previous step. The widget handles the entire authentication flow with the financial institution and creates an [Item](/docs/connections/item) -- the representation of the user's connection. Grab the `itemId` from the widget's `onSuccess` event. ### 5. Fetch the data With the connection created, use your API Key (server-side) to retrieve the data: ```bash # List the accounts of the connection curl "https://api.pluggy.ai/accounts?itemId=YOUR_ITEM_ID" \ -H "X-API-KEY: YOUR_API_KEY" # List the transactions of an account curl "https://api.pluggy.ai/transactions?accountId=YOUR_ACCOUNT_ID" \ -H "X-API-KEY: YOUR_API_KEY" ``` ## Next steps - Understand the core concepts in the [Glossary](/docs/get-started/glossary) - Test every flow with the [Sandbox](/docs/guides/sandbox) - Explore all endpoints in the [API Reference](/reference) ## Authentication Source: https://docs.pluggy.ai/en/docs/authentication.md Pluggy uses two kinds of credentials, depending on where the request is made from: - **API Key** -- used for server-side requests. It gives full access to all Pluggy API endpoints. - **Connect Token** -- used from client-side applications (i.e. the [Connect Widget](/docs/connect-widget/introduction)). Its access is limited in scope. The Connect Token access is limited to only the generated Item resource data ([GET /items/:id](/reference/items-retrieve)), and a reduced access to the data of the recovered Accounts ([GET /accounts?itemId=](/reference/accounts-list)). So, for example, a newly created Connect Token can't be used to access information that was created previously with a different Connect Token. For any other kind of request, such as retrieving all the Item related products data, configuring webhooks, [and more](/reference/auth), you'll need to do server-side requests using your API Key. ## Create an API Key First, you'll need to authenticate with the Pluggy API, using your `CLIENT_ID` and `CLIENT_SECRET`, to [create an API Key](/reference/auth-create) via `POST /auth`. *Note that these credentials are extremely **sensitive**, so please ensure to do this step in your secured server only.* This API Key expires after 2 hours and will give you full access to all Pluggy API endpoints. ## Create a Connect Token Then, with your API Key, you'll have to make a call to [POST /connect_token](/reference/connect-token-create). > **Important** > > The `connectToken` is valid for 30 minutes only. > The recommended usage is 1-per-connection, so we suggest creating a new one each time you want to create or update an Item. The usage of this **Connect Token** is identical to the **API Key**: simply pass it in the request authentication header, and the Pluggy API will take care of validating its scope. > **Warning** > > Attempts to access detailed products data using a Connect Token (instead of an API Key) will result in a `403 Forbidden` API response. ### Configuring a Connect Token When you are creating a Connect Token you can provide some `ItemOptions` that will be passed down to all Items created using the same Connect Token. **They must be sent nested inside the `options` attribute of the request body** -- this is the complete payload: ```json { "options": { "webhookUrl": "https://example.com/webhook", "clientUserId": "My App UserId", "oauthRedirectUri": "https://pluggy.ai/demo", "avoidDuplicates": true } } ``` - `webhookUrl`: URL where you will receive all the events of the Items created with this token. - `clientUserId`: You can use this field to link an Item with your user's identifier. - `oauthRedirectUri`: URL to redirect the user to after the connect flow. - `avoidDuplicates`: Avoids creating a new Item if there is already one with the same credentials. The only other attribute accepted at the root of the body is `itemId`, used when the widget updates an existing Item (see [Updating an Item](/docs/connect-widget/updating-item)). > **Warning** > > Any other property sent at the **root** of the body is ignored. Sending `clientUserId` > at the root instead of inside `options` still returns `200 OK`, but the value is > discarded: the Items created with that token will have `clientUserId: null`, and the > field will also be `null` in the `item/created`, `item/updated` and `item/error` > webhook payloads. > > ```json > // ❌ Wrong -- clientUserId is silently discarded > { "clientUserId": "My App UserId", "options": { "avoidDuplicates": true } } > > // ✅ Correct > { "options": { "clientUserId": "My App UserId", "avoidDuplicates": true } } > ``` > > If you already have Items created this way, you can backfill the value with > [PATCH /items/{id}](/reference/items-update). ## Creating an Item To summarize, the flow to create an [Item](/docs/connections/item) using a `connectToken` is: 1. Your server authenticates with `CLIENT_ID` and `CLIENT_SECRET` to get an API Key. 2. Your server creates a Connect Token and sends it to your client application. 3. Your client application uses the Connect Token to create the Item. If you are using our [Connect Widget](/docs/connect-widget/introduction), you'll only need to take care of providing the Connect Token -- the rest will be handled by us. ### Keeping a connection reference When initializing the Connect Widget for your user, you may want to track which user the created connection belongs to. This can be done in a few ways: - **Connect Widget `onSuccess` event**: When the connection is created and returned, you can recover the `itemId` to store on your side. - **Webhooks**: After the Item has been successfully created and synchronized, you will receive events. See [Webhooks](/docs/developer-tools/webhooks-ref). - **Linking your user identifier with an Item**: If you need to link the Item to your user, you can store a reference on our Item by using the `clientUserId`. This value can be provided when creating the `connectToken` or when creating an Item directly through the [Items endpoint](/docs/connections/item). ## Glossary Source: https://docs.pluggy.ai/en/docs/get-started/glossary.md ## Product A Product represents standardized data from a financial institution with a specific set of attributes for a specific purpose. ie. Accounts, Credit Cards, Investments, Identity, Transactions. ## Connector A Connector represents an integration with a financial institution that recovers specific products based on the user's access. ## Item An Item is the representation of a connection through a specific connector of an Institution, and serves as the entry point to access the set of products recovered, after the user gave their consent to collect his data. To create an Item, the easiest way for an user is interacting with our [Pluggy Connect Widget](/docs/pluggy-connect-introduction) where he can provide his consent, follow through authentication steps, and finally enable access to all their products through our API. ## API key An **API key** works as an API secret and expires 2 hours after creation. This one will be used to authenticate all requests done to Pluggy's API. Once the token expires, a new one has to be created, by using your corresponding **CLIENT_ID** and **CLIENT_SECRET** secret credentials. You can obtain your own **Client ID** and **Client Secret** credentials by signing up in our [Dashboard](http://dashboard.pluggy.ai/). > All API keys can be revoked from our Dashboard in case you need, and get new fresh ones. ## Connect Token The **Connect Token** is another type of API secret. It expires 30 minutes after creation. It's orientated to be used on the `client-side` since its access is restricted to ([`GET /items/:id`](/reference/items-retrieve)), and reduced access to the data of the recovered Accounts ([`GET /accounts?itemId`](/reference/accounts-list)). To generate it, (note: this must be done on the `server-side`) you should make a call to [POST /connect_token](/reference/connect-token-create) using your **API key**. See more information about **Connect Token** [here](/docs/authentication). ## FAQ Source: https://docs.pluggy.ai/en/docs/get-started/faq.md ## Basic concepts ### What is an item? An item represents the connection between a user and a financial institution, together with all the data returned by that connection. ### What is an application, and which types are available? An application is the pair of `clientId` and `clientSecret` keys used to reach the API. Handle them carefully: they are the only thing standing between the outside world and your data. You can create applications in both the `Development` and `Production` environments. ### What is the difference between an apiKey and a connectToken? The [apiKey](/reference/auth/auth-create) grants access to the API. You obtain it from your Pluggy credentials (`clientId` and `clientSecret`) and it is valid for 2 hours. The [connectToken](/reference/auth/connect-token-create) is the key used to open the Pluggy Connect widget — the graphical interface on top of the API. Getting a connectToken requires an apiKey first, and it lasts 30 minutes. ## Connectors and financial institutions ### What is the difference between Pluggy connectors and Open Finance connectors? | | Pluggy connectors (unregulated) | Open Finance connectors (regulated) | | -------------- | --------------------------------------- | ---------------------------------------- | | **Technology** | Pluggy's own | Framework regulated by the Central Bank | | **Access** | Direct to the financial institution | Through the user's consent | | **Data** | As shown in the internet banking | Standardised and enriched | For more detail, see [Item](/docs/connections/item). ### How do I check which financial institutions are available? There are three ways to look up the available institutions (connectors): - **Documentation** — [Open Finance (regulated)](/docs/open-finance/overview#institutions-supported-by-open-finance) and [Pluggy connectors (unregulated)](/docs/connections/connectors-coverage). - **API** — [`GET /connectors`](/reference/connector/connectors-list). - **Dashboard** — the [Customization](https://dashboard.pluggy.ai/customization) tab. ### Which institutions need a token to connect? The institutions that require a token are listed in [Connectors coverage](/docs/connections/connectors-coverage). ### How do I enable connectors in my application? Open the **Customization** tab in the [dashboard](https://dashboard.pluggy.ai/customization). ### Can I skip the bank-selection step in the Pluggy Connect widget? Yes. The `selectedConnectorId` attribute shows only the connector you pre-select. See [Environments and configurations](/docs/connect-widget/environments#available-configurations). ## Managing items and connections ### If a user connects the same account twice, are two different connections created? Yes. Every time the user gives consent — entering credentials on a Pluggy connector, or picking which data to share on an Open Finance one — a new connection is created with a new `itemId`. To avoid this, create the connection once and update that same `itemId` whenever you need fresher data. There is also a setting that checks whether the account has been connected before: see [avoiding duplicates](/docs/connections/item#avoiding-duplicates). ### How can I tell which of my users an `itemId` belongs to? Send the `clientUserId` field when the item is created, or when you open the Pluggy Connect widget. It takes any string you like; we recommend `"name | email | cpf_or_cnpj"`. See the [connect token options](/reference/auth/connect-token-create). ### How do I revoke a consent (a connection)? Delete the corresponding item through the API. That ends the connection and removes the data associated with it. ### Why did my `itemId` stop updating? The most common cause is hitting the institution's request limit, which happens when the same account is connected many times over. **Limit per CPF/CNPJ**: this limit is shared across every `itemId` belonging to the same CPF or CNPJ. Once it is reached, transactions only resume updating the **following month**. ### The item hit the limit — what can I do? The limit cannot be lifted within the current month. To keep it from happening again, avoid creating multiple connections for the same account: reuse the same `itemId` and update it when you need more recent data. ### Can I list every item I have created at Pluggy? No. Listing items is not available for security reasons, so that no data can leak across clients. ### Are new transactions on an account updated in real time? No. New transactions become available only after the connection is updated — see [updating an item](/docs/connect-widget/updating-item). On Open Finance (regulated) connectors, new transactions can take up to 24h to become available. ### How does automatic updating work? Pluggy can update your `itemId`s on a schedule — just ask through any of our channels. You can choose the hour the updates start; items are queued and updated according to available processing capacity, so nothing is overloaded. ## Environments and production ### How do I go to production? Create a production application in the dashboard, under `Applications`, using `Go to production`. A production application matters because: - automatic updating is available; - there is no limit on the number of `itemId`s; - there is no demo page, so no customer data is exposed. ### Can I keep Development and Production separate? Does the client_id/secret change? Yes. Create the environments in the [dashboard](https://dashboard.pluggy.ai/); each new environment gets its own `clientId` and `clientSecret`. The **Development** environment is capped at **100 items**. ## Webhooks and events ### Which webhook events are available? The full list is in the [webhooks reference](/docs/developer-tools/webhooks-ref). ## Sandbox Source: https://docs.pluggy.ai/en/docs/guides/sandbox.md Using our production environment you can access `Live` and `Sandbox` connectors. For testing purposes, you can experiment with your integration using our **Sandbox connector** (which represents our `Sandbox` environment). This will let you see how the transactions update daily and test all the possible valid connections and erroneous flows. > **Warning** > > All the sandbox items that are not updated for more than **30 days** will be deleted without any possibility to get them back in the future. **You will find different flows:** 1. Basic flow (we also include a special Caixa flow) 2. Basic flow Business 3. MFA 1-step 4. MFA 2-step 5. Joint accounts (Bradesco Conta Conjunta flow) 6. QR Login flow 7. Open Finance flow **For a successful flow, the credentials are:** - **Correct password**: `password-ok` - **Correct MFA Token**: `123456` Each test user name below maps to a specific execution status. See [Item lifecycle](/docs/connections/item-lifecycle) for the full description of item and execution statuses. ## Sandbox response structure The Sandbox (Pluggy Bank connector) returns synthetic data, but with the same field structure as production responses. Below is the field mapping observed in `/accounts` , `/transactions` , `/investments` , and `/loans` for a test item queried. ### Accounts ```json /accounts // Always returns at least 1 BANK/CHECKING_ACCOUNT and 1 CREDIT/CREDIT_CARD account: { "type": "BANK", "subtype": "CHECKING_ACCOUNT", "balance": 21544.6, "currencyCode": "BRL", "marketingName": "GOLD Conta Corrente", "taxNumber": "416.799.495-00", "owner": "John Doe", "bankData": { "transferNumber": "123/0001/12345-0", "closingBalance": 21544.6, "automaticallyInvestedBalance": 2154.46, "hasReservedBalance": true, "reservedBalances": [{ "name": "Caixinha Para Férias", "availableAmounts": [{ "amount": 1000.04, "remuneration": { "indexer": "CDI", "rateType": "LINEAR", "preFixedRate": 0.3 } }] }] }, "creditData": null } { "type": "CREDIT", "subtype": "CREDIT_CARD", "balance": -503.1, "creditData": { "level": "BLACK", "brand": "MASTERCARD", "balanceCloseDate": "2026-07-23", "balanceDueDate": "2026-07-28", "creditLimit": 300000, "availableCreditLimit": 300000, "minimumPayment": 100.62, "holderType": "MAIN", "status": "ACTIVE" } } // Note that bankData/creditData are mutually exclusive depending on the account's type - the Sandbox even simulates reservedBalances ("piggy banks") inside bankData, which isn't trivial to find documented elsewhere. ``` ### Transactions ```json /transactions // Simple transaction (recurring, no extra metadata) — salary, recurring debits: { "description": "SALARIO EMPRESA XYZ LTDA", "amount": 8500, "type": "CREDIT", "category": "Salary", "categoryId": "01010000", "paymentData": null, "creditCardMetadata": null } // Bank slip (boleto) payment — the only record with paymentData populated: { "description": "Pagamento de boleto", "amount": -100, "type": "DEBIT", "category": "Transfer - Bank Slip", "categoryId": "05010000", "paymentData": { "payer": { "documentNumber": { "type": "CPF", "value": "111.111.111-11" }, "name": "Francisco Souza", "routingNumberISPB": "60701190" }, "paymentMethod": "BOLETO", "receiver": { "documentNumber": { "type": "CNPJ", "value": "PL.UGG.Y12/AB00-42" }, "name": "Pluggy Brasil Instituição de Pagamento LTDA" }, "boletoMetadata": { "baseAmount": 90, "discountAmount": 0, "interestAmount": 10, "digitableLine": "11190000111001113911100000021110600000000111000" } } } // Installment credit card purchase — the only record with creditCardMetadata populated: { "description": "NETFLIX.COM", "amount": -55.9, "creditCardMetadata": { "installmentNumber": 2, "totalInstallments": 6, "totalAmount": -335.4, "payeeMCC": 5812, "billId": "3b3341e4-d30c-48d6-bcbe-79a3fe47d704" } } // In other words: the Sandbox simulates bank-slip (boleto) payments and installment card purchases, but the checking account queried here has no Pix, TED, or inter-account transfers — all 17 checking-account transactions are: boleto payment, recurring debits (telecom, electricity, condo fees), salary, and bill payment. On the credit card, all 9 transactions are purchases (subscriptions/gym), with no dispute, refund, or cash-advance examples. ``` ### Investments ```json /investments // 8 investments across 6 type/subtype combinations: // SECURITY/PGBL — pension plan { "type": "SECURITY", "subtype": "PGBL", "name": "ITAU Sandbox previdencia", "balance": 11720.42, "value": 3.605103, "amount": 1720.42, "lastMonthRate": -0.8, "lastTwelveMonthsRate": 5.97, "annualRate": 7.64, "issuer": "ITAU UNIBANCO ASSET MANAGEMENT LTDA", "issuerCNPJ": "40.430.971/0001-96" } // SECURITY/RETIREMENT — pension plan issued by Pluggy itself { "type": "SECURITY", "subtype": "RETIREMENT", "name": "Pluggy PREVIDENCIA", "balance": 1359.39, "amountProfit": 359.39, "amountOriginal": 1000, "issuer": "Banco do Pluggy", "dueDate": "2026-07-23T16:16:27.300Z" } // MUTUAL_FUND/INVESTMENT_FUND — appears twice (Premium/Basic) { "type": "MUTUAL_FUND", "subtype": "INVESTMENT_FUND", "name": "Fondo de Investimento Premium", "balance": 1359.39, "quantity": 3, "value": 500, "amount": 1500, "taxes": 40.61, "taxes2": 100, "amountProfit": 359.39, "amountOriginal": 1000 } // FIXED_INCOME/CDB — fixed-income bond { "type": "FIXED_INCOME", "subtype": "CDB", "name": "CDR", "balance": 2000, "rate": 150, "rateType": "CDI", "fixedAnnualRate": 2.5, "dueDate": "2026-07-23T16:16:27.300Z", "issuer": "Banco do Pluggy", "institution": { "name": "BANCO BTG PACTUAL S/A", "number": "30306294000145" } } // ETF/ETF — appears twice: one active, one fully withdrawn { "type": "ETF", "subtype": "ETF", "name": "ISUS11 STOCK", "code": "ISUS11", "isin": "123456789", "quantity": 1, "amount": 2000, "status": "ACTIVE" } { "type": "ETF", "subtype": "ETF", "name": "BOVA11", "code": "BOVA11", "quantity": 0, "value": 118.4, "status": "TOTAL_WITHDRAWAL" } // EQUITY/REAL_ESTATE_FUND — REIT (FII) { "type": "EQUITY", "subtype": "REAL_ESTATE_FUND", "name": "GGRC11", "code": "GGRC11", "isin": "BRGGRCCTF002", "quantity": 1, "amount": 118.4, "issuer": "GGR COVEPI RENDA FDO INV IMOB" } // No SECURITY/individual-stock example (equity held outside a fund), and nothing explicitly // labeled Treasury Direct — the closest analog available is the FIXED_INCOME/CDB above. ``` ### Loans ```json /loans { "productName": "Crédito Pessoal Consignado", "type": "CREDITO_PESSOAL_COM_CONSIGNACAO", "kind": "LOAN", "contractAmount": 50000, "currencyCode": "BRL", "contractDate": "2022-08-01T00:00:00.000Z", "dueDate": "2028-01-15T00:00:00.000Z", "installmentPeriodicity": "MONTHLY", "amortizationScheduled": "SAC", "CET": 0.29, "interestRates": [{ "interestRateType": "SIMPLE", "postFixedRate": 0.55, "preFixedRate": 0.6, "referentialRateIndexerSubType": "TJLP" }], "installments": { "dueInstallments": 57, "paidInstallments": 73, "pastDueInstallments": 73, "totalNumberOfInstallments": 130632 }, "payments": { "contractOutstandingBalance": 1000.04 } } // Only one loan type/kind is simulated: payroll-deductible personal credit. No mortgage, vehicle financing, or unsecured personal loan without consignação is represented. ``` The values above are illustrative examples of what the Sandbox can return - they exist to help you build against the right field structure. The Sandbox is not intended to be used as a target for automated tests that assert on Pluggy's specific behavior. ## 1- Basic flows > **Note** > > The basic flow also works for **Business connectors**. | Execution status | User name | Description | |---|---|---| | `SUCCESS` | `user-ok` | Successful connection. | | `ALREADY_LOGGED_IN` | `user-logged` | The user already has an opened login session (needs to manually log out). | | `ACCOUNT_LOCKED` | `user-locked` | User account is locked, needs manual action to be unlocked. | | `UNEXPECTED_ERROR` | `user-error` | Connector had a random error. | | `SITE_NOT_AVAILABLE` | `user-unavailable` | Provider site was not available. | | `ACCOUNT_NEEDS_ACTION` | `user-account-need-actions` | Provider is requesting some manual action from the user (ie. accept new terms of use). | | `ACCOUNT_NEEDS_ACTION` + `providerMessage` | `user-account-need-actions-provider-message` | Provider is requesting some manual action from the user, including instructions to address it in the item error `providerMessage` field. | | `CONNECTION_ERROR` | `user-connection-error` | There was an internal connection error with the provider (ie. Proxy issue). | | `INVALID_CREDENTIALS` | anything else | The user/password credentials were invalid. | | `PARTIAL_SUCCESS` | `user-ok-account-error` | Error recovering account product. | | `SUCCESS` with warnings | `user-ok-account-warning` | Warning in account product. | | `ACCOUNT_CREDENTIALS_RESET` | `user-account-credentials-reset` | The user needs to update some of their credentials in the institution. | | `USER_NOT_SUPPORTED` | `user-not-supported` | The user is not allowed to perform login in the institution through Pluggy. | | `SUCCESS` with two checking accounts data | `user-ok-two-checking-accounts` | Success, but returns an example of two checking accounts. | ### Enlarge result data In cases in which it is necessary to test large amounts of transactions in the result, you can use the `user-ok-perf` or `user-ok-perf-XXx` username to recreate this situation. `XX` represents the multiplier for the number of transactions to be retrieved. For example, if you choose 1000 as XX, the resulting username would be `user-ok-perf-1000x`, in order to multiply the result by this number. The limit of this multiplier is 5000, so if you use a larger number, the multiplier will be just 5000. ### Basic Flow | Authorization Pending status (Caixa flow) This is a special case that emulates the Caixa flow. It consists of three possible execution statuses to be returned. When a user connects for the first time, the expected execution returned will be to confirm the user device shown (i.e. "1234-5678"). So, the first execution (after the user confirms the device on his side) will return `USER_AUTHORIZATION_PENDING` and a message that informs the time that the user must wait until authorization is granted from Caixa. Once this step is completed, there are two possible scenarios: 1. If the user updates the item within the time to be awaited, the execution result will be `USER_AUTHORIZATION_NOT_GRANTED` and a message to remind the time to be awaited until the authorization is granted from Caixa (in the Sandbox case, the time is 2 minutes). 2. If the user updates the item after the wait is over, the data of the account will be retrieved successfully and the execution report will be `SUCCESS`. See the table below for more details: | Execution status | User name | Description | |---|---|---| | `USER_AUTHORIZATION_PENDING` | `user-ok-auth-pending` | This will report a `USER_AUTHORIZATION_PENDING` status, and a message to wait for 2 minutes until the institution grants authorization. Then, you can update the item to retrieve the data after those 2 minutes, or get a not-yet-granted authorization message (please read the next rows). | | `USER_AUTHORIZATION_NOT_GRANTED` | re-use credentials (update) | If the item is updated before the institution grants authorization, the status reported will be `USER_AUTHORIZATION_NOT_GRANTED` and you will be newly asked to wait for the 2 minutes after the first execution. | | `SUCCESS` | re-use credentials (update) | If the item is updated once the institution authorization is completed, then the data should be retrieved and the status report will be `SUCCESS`. | ## 3- MFA 1-step | Scenario | User name | MFA | Description | |---|---|---|---| | Login Ok | `user-ok` | `123456` | Successful connection. | | `INVALID_CREDENTIALS_MFA` | `user-ok` | ≠ `123456` | The MFA parameter provided was incorrect. | ## 4- MFA 2-step | Scenario | User name | MFA | Description | |---|---|---|---| | Login Ok | `user-ok` | `123456` | Successful connection. | | `INVALID_CREDENTIALS_MFA` | `user-ok` | ≠ `123456` | The MFA parameter provided was incorrect. | | Login Ok (MFA with QR image) | `user-ok-img` | `123456` | Successful connection. | | `INVALID_CREDENTIALS_MFA` (MFA with QR image) | `user-ok-img` | ≠ `123456` | The MFA parameter provided was incorrect. | | Login Ok (MFA with options to select) | `user-ok-select` | any | Successful connection. | | Login OK (with phone selection before MFA) | `user-ok-phone` | `123456` | Successful connection. | | `INVALID_CREDENTIALS_MFA` (with phone selection before MFA) | `user-ok-phone` | ≠ `123456` | The MFA parameter provided was incorrect. | | Login Ok (with company selection after MFA) | `user-ok-multi-company` | `123456` | Successful connection. | | `INVALID_CREDENTIALS_MFA` | `user-ok-multi-company` | ≠ `123456` | The MFA parameter provided was incorrect. | | `UNEXPECTED_ERROR` | `user-ok-mfa-error` | `123456` | Connector had a random error. | | `ACCOUNT_LOCKED` | `user-ok-mfa-locked` | `123456` | User account is locked, needs manual action to be unlocked. | | `SITE_NOT_AVAILABLE` | `user-ok-mfa-unavailable` | `123456` | Provider site was not available. | | `CONNECTION_ERROR` | `user-ok-mfa-connection-error` | `123456` | There was an internal connection error with the provider (ie. Proxy issue). | | `ALREADY_LOGGED_IN` | `user-ok-mfa-logged` | `123456` | The user already has an opened login session (needs to manually log out). | | `ACCOUNT_NEEDS_ACTION` | `user-ok-mfa-account-need-actions` | `123456` | Provider is requesting some manual action from the user (ie. accept new terms of use). | ## 5- Joint Accounts (Bradesco Conta Conjunta flow) This is a special case that emulates the Bradesco Conta Conjunta flow. **Below you will find two examples:** 1. Testing in the Pluggy Connect widget 2. Testing via Postman ### 1- Testing in the Pluggy Connect widget When using the [Pluggy Connect widget](/docs/developer-tools/connect-account), the user will be presented to choose first from either a "Single account" or a "Joint account". - If the user selects **"Single account"**, they will be asked for bank credentials and MFA in the same step as the credentials. - If the user selects **"Joint account"**, they will be asked only for bank credentials. Then, they will be asked which account they want to connect, and after that, the MFA will be required. If the MFA is correct, the account will connect successfully. ### 2- Testing via Postman - When testing "single account", the request is the same as sandbox MFA 1-step. The bank credentials and MFA are sent together. - When testing "joint account", you have to include an MFA 1-step parameter, with the mock value: `000000`. Note that this is the same as the Connect widget flow. When the user selects the "joint account" flow, the UI is not asking to complete the MFA parameter. ## 6- QR Login flow This is a case that originally simulates a flow similar to Inter QR. No credentials are necessary. Once started, the item will enter a `WAITING_USER_ACTION` status, and return a QR code for the user to scan. This flow will simulate a rapidly changing QR code for 10 seconds and then simulate the user reading the QR and advancing the state to a normal login flow. ## 7- Open Finance flow To connect using our sandbox connection (see [Creating an Open Finance item](/docs/open-finance/creating-item)), you will be required to send a CPF: | Scenario | CPF | |---|---| | Basic flow | 761.092.776-73 | | Multiple authorization flow - approved | 238.242.640-30 | | Multiple authorization flow - rejected | 051.177.670-55 | | Basic flow - with slow authentication | 002.502.737-99 | | Basic flow - force error getting OF resources | 163.511.711-99 | This will redirect you to the mock bank login page. Please use the following credentials: - User: `ralph.bragg@gmail.com` - Password: `P@ssword01` ### How does the multiple authorization (múltipla alçada) flow work? This flow simulates a scenario where, in order to retrieve account data, the item must be approved by another person (typically another company associate). To test this scenario, follow these steps: 1. Create a sandbox item using one of the CPFs listed in the table above. The item will not return accounts immediately. Instead, the `statusDetail` field will indicate that the accounts require authorization. 2. Update that item. Depending on the CPF you provided, the accounts may or may not be returned. ## Introduction Source: https://docs.pluggy.ai/en/docs/connect-widget/introduction.md ## What is Pluggy Connect? Pluggy Connect is a drop-in widget we offer to help you quickly get started with Pluggy. Your users will use it to connect their accounts, within your app, directly to the Pluggy API. The Connect Widget is Pluggy's plug & play frontend solution that allows users to connect their financial accounts on a step-by-step flow, so you will only need to worry about interacting with their data instead of worrying about painful login flows. Throughout the connection process, the widget handles: - Credential validation - Multi-factor authentication (MFA) - Error management ## How it Works The typical integration follows these key steps: 1. **Backend Token Setup**: First, you'll need to set up an endpoint on your backend that obtains and provides a **Connect Token**. This token grants Pluggy Connect authorization to access the Pluggy API on behalf of your application. This process must be done on your backend, since the endpoint requires authentication using your application's `CLIENT_ID` and `CLIENT_SECRET`. 2. **Frontend Integration**: With your Connect Token endpoint deployed, you are ready to integrate Pluggy Connect in your client-side application. There are fully working frontend examples that you can clone and start using right away to launch the Pluggy Connect interface, by replacing the Connect Token endpoint URL with your own. 3. **User Connection**: When your user clicks on "Connect my account", a Connect Token is obtained and the Connect Widget instantiates with this token and opens up a modal for the user to input their credentials. 4. **Data Retrieval**: Once the widget finishes, it emits an `onSuccess` event with the `id` of the newly created **Item**. This Item ID is needed for any future action you want to do with the connected banking data.