> ## Documentation Index
> Fetch the complete documentation index at: https://fastpay-mintlify-9618a7a2.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Melhor Envio OAuth callback

> Endpoint Melhor Envio redirects to after the merchant authorizes the
integration. Exchanges the `code` for access/refresh tokens, persists
them encrypted, and redirects back to the merchant dashboard.

Not intended to be called directly — it is the redirect target
configured on the merchant's Melhor Envio app.



## OpenAPI

````yaml /api-reference/openapi.yaml get /v1/melhor-envio/oauth/callback
openapi: 3.0.0
info:
  title: FastPay API
  version: 1.0.0
  description: >-
    API for creating and managing payment charges.


    ## Authentication


    This API uses **Basic Authentication** for direct API access, such as
    creating charges.

    Use your API key as the username and an empty string as password.

    The header should be formatted as:


    `Authorization: Basic {base64(apiKey:)}`.


    For example:


    ```

    Authorization: Basic YWxleG91dG9uOiIi

    ```


    ## Webhooks


    FastPay sends webhooks to notify your application about charge status
    changes in real-time.

    Webhooks are sent via HTTP POST requests to your configured webhook
    endpoints.


    ### Webhook Events


    The following webhook events are available for charges:


    - `charge.created` - Sent when a new charge is created

    - `charge.pending` - Sent when a charge is pending payment

    - `charge.paid` - Sent when a charge is successfully paid

    - `charge.updated` - Sent when a charge is updated


    ### Webhook Payload Structure


    All webhook payloads follow this structure:


    ```json

    {
      "id": "webhook_event_id",
      "event": "charge.paid",
      "data": {
        // Complete charge object
      }
    }

    ```


    ### Webhook Delivery


    - Webhooks are sent via HTTP POST requests

    - Content-Type: `application/json`

    - Retry logic is implemented for failed deliveries

    - Webhook events are stored in the database for audit purposes

    - Delivery logs are maintained for debugging and monitoring


    ### Webhook Security


    - Webhooks are sent to pre-configured endpoints

    - Endpoints can be enabled/disabled per merchant

    - Event filtering is supported (only receive specific events)

    - Failed deliveries are retried with exponential backoff
servers:
  - url: https://api-global.fastpaybrasil.com
    description: Produção e Sandbox (diferenciados pela API key)
security: []
paths:
  /v1/melhor-envio/oauth/callback:
    get:
      tags:
        - Melhor Envio
      summary: Melhor Envio OAuth callback
      description: |-
        Endpoint Melhor Envio redirects to after the merchant authorizes the
        integration. Exchanges the `code` for access/refresh tokens, persists
        them encrypted, and redirects back to the merchant dashboard.

        Not intended to be called directly — it is the redirect target
        configured on the merchant's Melhor Envio app.
      parameters:
        - in: query
          name: code
          required: true
          schema:
            type: string
          description: Authorization code returned by Melhor Envio.
        - in: query
          name: state
          required: true
          schema:
            type: string
          description: Opaque state generated by `GET /v1/melhor-envio/oauth/authorize`.
      responses:
        '302':
          description: Redirect to the dashboard (success or error).

````