Cash · Reference
Cash API
Cash API · version 1.0.0. 7 endpoints, generated from the OpenAPI spec.
Overview
Monato Cash API provides secure cash-in and cash-out operations for physical locations in Mexico. This API enables businesses to create cash operations that users can complete at physical payment locations, with real-time webhook notifications for status updates.
Webhook Events
After configuring your webhook endpoint, Monato will send the following events to your server:
Only one webhook can be enabled at a time per client.
Webhook Activation Test
- Event:
webhook.activation - Purpose: Test your endpoint during webhook configuration
- Payload:
{"event": "webhook.activation", "processed_at": "2025-01-15T10:30:00Z"}
Operation Status
There are several operation statuses used across cash in & cash out processes:
unpaid: Initial status when a reference is created. The operation is ready to be paid.paid: Once the end customer completes a cash deposit or cash withdrawal and all required validations succeed.expired: Each generated reference has an expiration window. For cash-in, the reference expires after 3 days. For cash-out, it expires after 60 minutes, For Open References it expires based on the custom date you set during creation.reversed: If an issue occurs during processing at the physical location, the transaction is voided.
Operation Status Updates
Please note that webhooks are triggered exclusively for operations of the type closed references. Operations involving open references do not currently support automated status updates via webhook.
paid- Event:
webhook.paid.success - Purpose: Notify when cash operation was paid.
- Payload:
{"event": "webhook.paid.success", "operation_id": 123, "external_user_id": "USER123456", "type": "cash_in", "amount": 500, "reference": "10511175512161627448", "status": "paid", "processed_at": "2025-01-15T10:30:00Z"}
- Event:
expired- Event:
webhook.expired.success - Purpose: Notify when cash operation expired.
- Payload:
{"event": "webhook.expired.success", "operation_id": 123, "external_user_id": "USER123456", "type": "cash_in", "amount": 500, "reference": "10511175512161627448", "status": "expired", "processed_at": "2025-01-15T10:30:00Z"}
- Event:
reversed- Event:
webhook.reversed.success - Purpose: Notify when cash operation was reversed.
- Payload:
{"event": "webhook.reversed.success", "operation_id": 123, "external_user_id": "USER123456", "type": "cash_in", "amount": 500, "reference": "10511175512161627448", "status": "reversed", "processed_at": "2025-01-15T10:30:00Z"}
- Event:
All webhook requests include signature headers for verification:
X-Webhook-Timestamp: Unix timestampX-Webhook-Signature: HMAC-SHA256 signature
Authentication
All API requests require HMAC-SHA256 authentication using three headers:
X-Client-Id: Your 32-character API keyX-Signature: HMAC-SHA256 signature oftimestamp + "." + requestBodyusing your API secretX-Timestamp: Unix timestamp (seconds since epoch) to prevent replay attacks
Signature Generation: HMAC-SHA256(timestamp + "." + JSON.stringify(requestBody), api_secret)
Handling Errors
Responses may return different HTTP status codes depending on request data and authorization.
| Status | Description | Client action |
|---|---|---|
| 401 | Unauthorized | Invalid X-Client-Id or signature verification failed |
| 400 | Bad request | The request parameters are invalid. This may be due to malformed values, incorrect formatting, or missing required parameters. |
| 404 | Not found | The requested resource doesn't exist. |
| 503 | Service Unavailable | The service is under maintenance. |
| 422 | Unprocessable Content | The request is syntactically valid, but it cannot be processed because one or more business rules or semantic validations failed. |
| 500 | Internal Server Error | The server encountered an unexpected condition that prevented it from fulfilling the request. |
Servers
| URL | Description |
|---|---|
https://api.finco.lat | Production server |
https://dev-api.finco.lat | Staging server |
Authentication
X-Client-Id· used by 7 endpointsClient API key (32-character hex) obtained from client creation process. Must be used with X-Signature and X-Timestamp headers for HMAC authentication.
X-Signature· used by 7 endpointsHMAC-SHA256 signature generated using your api_secret. Format: HMAC-SHA256(timestamp + "." + requestBody, api_secret)
X-Timestamp· used by 7 endpointsUnix timestamp (seconds since epoch) when the request was created. Used in HMAC signature generation to prevent replay attacks.
Postman collection
Endpoints
| POST | /api/v1/cash/webhooks Create Webhook |
| GET | /api/v1/cash/webhooks/active Get Active Webhook |
| PUT | /api/v1/cash/webhooks/active Update Webhook |
| POST | /api/v1/cash/cash_in Create Cash-In |
| POST | /api/v1/cash/cash_out Create Cash-Out |
| POST | /api/v1/cash/bulk_operations Create Bulk Cash-In Operations |
| GET | /api/v1/cash/consult Consult Operation |