Docs

Cash · Reference

Cash API

Cash API · version 1.0.0. 7 endpoints, generated from the OpenAPI spec.

7endpoints in 1 group
X-Client-Id + X-Signature + X-Timestampauthentication
https://dev-api.finco.latStaging server

Overview

Monato Cash API provides secure cash-in and cash-out operations for physical locations in Mexico. This API enables businesses to create cash operations that users can complete at physical payment locations, with real-time webhook notifications for status updates.

Webhook Events

After configuring your webhook endpoint, Monato will send the following events to your server:

Note: Note

Only one webhook can be enabled at a time per client.

Webhook Activation Test

  • Event: webhook.activation
  • Purpose: Test your endpoint during webhook configuration
  • Payload: {"event": "webhook.activation", "processed_at": "2025-01-15T10:30:00Z"}

Operation Status

There are several operation statuses used across cash in & cash out processes:

  • unpaid: Initial status when a reference is created. The operation is ready to be paid.
  • paid: Once the end customer completes a cash deposit or cash withdrawal and all required validations succeed.
  • expired: Each generated reference has an expiration window. For cash-in, the reference expires after 3 days. For cash-out, it expires after 60 minutes, For Open References it expires based on the custom date you set during creation.
  • reversed: If an issue occurs during processing at the physical location, the transaction is voided.

Operation Status Updates

Please note that webhooks are triggered exclusively for operations of the type closed references. Operations involving open references do not currently support automated status updates via webhook.

  • paid
    • Event: webhook.paid.success
    • Purpose: Notify when cash operation was paid.
    • Payload: {"event": "webhook.paid.success", "operation_id": 123, "external_user_id": "USER123456", "type": "cash_in", "amount": 500, "reference": "10511175512161627448", "status": "paid", "processed_at": "2025-01-15T10:30:00Z"}
  • expired
    • Event: webhook.expired.success
    • Purpose: Notify when cash operation expired.
    • Payload: {"event": "webhook.expired.success", "operation_id": 123, "external_user_id": "USER123456", "type": "cash_in", "amount": 500, "reference": "10511175512161627448", "status": "expired", "processed_at": "2025-01-15T10:30:00Z"}
  • reversed
    • Event: webhook.reversed.success
    • Purpose: Notify when cash operation was reversed.
    • Payload: {"event": "webhook.reversed.success", "operation_id": 123, "external_user_id": "USER123456", "type": "cash_in", "amount": 500, "reference": "10511175512161627448", "status": "reversed", "processed_at": "2025-01-15T10:30:00Z"}

All webhook requests include signature headers for verification:

  • X-Webhook-Timestamp: Unix timestamp
  • X-Webhook-Signature: HMAC-SHA256 signature

Authentication

All API requests require HMAC-SHA256 authentication using three headers:

  • X-Client-Id: Your 32-character API key
  • X-Signature: HMAC-SHA256 signature of timestamp + "." + requestBody using your API secret
  • X-Timestamp: Unix timestamp (seconds since epoch) to prevent replay attacks

Signature Generation: HMAC-SHA256(timestamp + "." + JSON.stringify(requestBody), api_secret)

Handling Errors

Responses may return different HTTP status codes depending on request data and authorization.

StatusDescriptionClient action
401UnauthorizedInvalid X-Client-Id or signature verification failed
400Bad requestThe request parameters are invalid. This may be due to malformed values, incorrect formatting, or missing required parameters.
404Not foundThe requested resource doesn't exist.
503Service UnavailableThe service is under maintenance.
422Unprocessable ContentThe request is syntactically valid, but it cannot be processed because one or more business rules or semantic validations failed.
500Internal Server ErrorThe server encountered an unexpected condition that prevented it from fulfilling the request.

Servers

URLDescription
https://api.finco.latProduction server
https://dev-api.finco.latStaging server

Authentication

ClientAuthAPI key in header X-Client-Id· used by 7 endpoints

Client API key (32-character hex) obtained from client creation process. Must be used with X-Signature and X-Timestamp headers for HMAC authentication.

HMACSignatureAPI key in header X-Signature· used by 7 endpoints

HMAC-SHA256 signature generated using your api_secret. Format: HMAC-SHA256(timestamp + "." + requestBody, api_secret)

TimestampAPI key in header X-Timestamp· used by 7 endpoints

Unix timestamp (seconds since epoch) when the request was created. Used in HMAC signature generation to prevent replay attacks.

Postman collection

Monato · Cash8 requests for 7 endpoints, generated from this spec

Endpoints

POST/api/v1/cash/webhooks
Create Webhook
GET/api/v1/cash/webhooks/active
Get Active Webhook
PUT/api/v1/cash/webhooks/active
Update Webhook
POST/api/v1/cash/cash_in
Create Cash-In
POST/api/v1/cash/cash_out
Create Cash-Out
POST/api/v1/cash/bulk_operations
Create Bulk Cash-In Operations
GET/api/v1/cash/consult
Consult Operation