curl --request PATCH \
--url https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id} \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"key_type": "EMAIL",
"key": "[email protected]",
"primary": false
}
'import requests
url = "https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}"
payload = {
"key_type": "EMAIL",
"key": "[email protected]",
"primary": False
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({key_type: 'EMAIL', key: '[email protected]', primary: false})
};
fetch('https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'key_type' => 'EMAIL',
'key' => '[email protected]',
'primary' => false
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}"
payload := strings.NewReader("{\n \"key_type\": \"EMAIL\",\n \"key\": \"[email protected]\",\n \"primary\": false\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"key_type\": \"EMAIL\",\n \"key\": \"[email protected]\",\n \"primary\": false\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"key_type\": \"EMAIL\",\n \"key\": \"[email protected]\",\n \"primary\": false\n}"
response = http.request(request)
puts response.read_body{
"id": "123e4567-e89b-12d3-a456-426614174001",
"company_id": "a3dbd0c2-9f79-4f86-8caa-47779b3f2793",
"key_type": "EMAIL",
"key": "[email protected]",
"primary": false,
"status": "ACTIVE",
"deleted_at": null,
"created_at": "2025-01-01T10:00:00.000Z",
"updated_at": "2025-01-01T10:05:00.000Z",
"dict_key_information": {
"bank": "18236120",
"account": "********",
"branch": "0",
"account_type": "********",
"owner_name": "teste celcoin",
"owner_document": "***778477**",
"is_owned_by_company": true
}
}{
"error": {
"code": "VALIDATION_ERROR",
"message": "Validation error",
"status": 400,
"details": {
"issues": [
{
"field": "email",
"type": "REQUIRED",
"message": "Field 'email' is required",
"value": "invalid_value",
"constraints": {
"min": 18,
"max": 120
}
}
]
},
"path": "/companies",
"timestamp": "2023-12-01T10:00:00.000Z",
"requestId": "req_123456789"
}
}{
"error": {
"code": "AUTHENTICATION_ERROR",
"message": "Authentication required to access this resource",
"status": 401,
"details": {
"reason": "Invalid API key"
},
"path": "/companies/me",
"timestamp": "2023-12-01T10:00:00.000Z",
"requestId": "req_123456789"
}
}{
"error": {
"code": "RESOURCE_NOT_FOUND",
"message": "Company with ID '123' not found",
"status": 404,
"path": "/companies/me",
"timestamp": "2023-12-01T10:00:00.000Z",
"requestId": "req_123456789"
}
}{
"error": {
"code": "CONFLICT_ERROR",
"message": "A Resource with this origin_bank_account_id + request_id already exists",
"status": 409,
"details": {
"field": "origin_bank_account_id + request_id",
"value": "12345678"
},
"path": "/companies/bank-accounts",
"timestamp": "2023-12-01T10:00:00.000Z",
"requestId": "req_123456789"
}
}{
"error": {
"code": "INTERNAL_SERVER_ERROR",
"message": "An unexpected error occurred",
"status": 500,
"path": "/companies",
"timestamp": "2023-12-01T10:00:00.000Z",
"requestId": "req_123456789"
}
}Update a company PIX key
Requires the banking.edit permission.
Updates a specific PIX key for the authenticated company. When key is sent, a DICT
lookup is performed using the company’s active enabled CELCOIN affiliation (same
flow as create), the result is persisted, and returned in dict_key_information.
Per BACEN’s rules, several fields may be masked as part of DICT read-attack
prevention. Updates that only change primary do not perform a lookup. When key is sent it is
normalized and validated before the lookup (CPF/CNPJ stored bare, phone
separators stripped, emails lowercased, EVPs lowercase UUIDs); a key matching no
canonical form is rejected with 400 before any DICT lookup.
Returns 404 if the PIX key is not found or the company has no active enabled
CELCOIN affiliation, 409 if another active PIX key already holds the new key, and
400 if the update includes key while the PIX key has cashouts outside a failed
state (updates that only change primary are not subject to this restriction). In
all of those cases no DICT lookup is performed.
curl --request PATCH \
--url https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id} \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"key_type": "EMAIL",
"key": "[email protected]",
"primary": false
}
'import requests
url = "https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}"
payload = {
"key_type": "EMAIL",
"key": "[email protected]",
"primary": False
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({key_type: 'EMAIL', key: '[email protected]', primary: false})
};
fetch('https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'key_type' => 'EMAIL',
'key' => '[email protected]',
'primary' => false
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}"
payload := strings.NewReader("{\n \"key_type\": \"EMAIL\",\n \"key\": \"[email protected]\",\n \"primary\": false\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"key_type\": \"EMAIL\",\n \"key\": \"[email protected]\",\n \"primary\": false\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api-sandbox.rinne.com.br/core/v1/companies/me/pix-keys/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"key_type\": \"EMAIL\",\n \"key\": \"[email protected]\",\n \"primary\": false\n}"
response = http.request(request)
puts response.read_body{
"id": "123e4567-e89b-12d3-a456-426614174001",
"company_id": "a3dbd0c2-9f79-4f86-8caa-47779b3f2793",
"key_type": "EMAIL",
"key": "[email protected]",
"primary": false,
"status": "ACTIVE",
"deleted_at": null,
"created_at": "2025-01-01T10:00:00.000Z",
"updated_at": "2025-01-01T10:05:00.000Z",
"dict_key_information": {
"bank": "18236120",
"account": "********",
"branch": "0",
"account_type": "********",
"owner_name": "teste celcoin",
"owner_document": "***778477**",
"is_owned_by_company": true
}
}{
"error": {
"code": "VALIDATION_ERROR",
"message": "Validation error",
"status": 400,
"details": {
"issues": [
{
"field": "email",
"type": "REQUIRED",
"message": "Field 'email' is required",
"value": "invalid_value",
"constraints": {
"min": 18,
"max": 120
}
}
]
},
"path": "/companies",
"timestamp": "2023-12-01T10:00:00.000Z",
"requestId": "req_123456789"
}
}{
"error": {
"code": "AUTHENTICATION_ERROR",
"message": "Authentication required to access this resource",
"status": 401,
"details": {
"reason": "Invalid API key"
},
"path": "/companies/me",
"timestamp": "2023-12-01T10:00:00.000Z",
"requestId": "req_123456789"
}
}{
"error": {
"code": "RESOURCE_NOT_FOUND",
"message": "Company with ID '123' not found",
"status": 404,
"path": "/companies/me",
"timestamp": "2023-12-01T10:00:00.000Z",
"requestId": "req_123456789"
}
}{
"error": {
"code": "CONFLICT_ERROR",
"message": "A Resource with this origin_bank_account_id + request_id already exists",
"status": 409,
"details": {
"field": "origin_bank_account_id + request_id",
"value": "12345678"
},
"path": "/companies/bank-accounts",
"timestamp": "2023-12-01T10:00:00.000Z",
"requestId": "req_123456789"
}
}{
"error": {
"code": "INTERNAL_SERVER_ERROR",
"message": "An unexpected error occurred",
"status": 500,
"path": "/companies",
"timestamp": "2023-12-01T10:00:00.000Z",
"requestId": "req_123456789"
}
}Authorizations
Company API key for authentication
Path Parameters
The PIX key ID
Body
Schema for updating a company PIX key
PIX key type
CPF, CNPJ, EMAIL, PHONE, EVP "EMAIL"
PIX key value
Whether this is the primary PIX key
false
Response
PIX key updated successfully, including dict_key_information from the
DICT lookup (or null if no snapshot could be persisted).
Company PIX key response
PIX key ID
"123e4567-e89b-12d3-a456-426614174001"
Company ID
"a3dbd0c2-9f79-4f86-8caa-47779b3f2793"
PIX key type
CPF, CNPJ, EMAIL, PHONE, EVP "EMAIL"
PIX key value
Whether this is the primary PIX key
false
PIX key status
ACTIVE, DELETED "ACTIVE"
Deletion timestamp (null if not deleted)
null
Creation timestamp
"2025-01-01T10:00:00.000Z"
Last update timestamp
"2025-01-01T10:05:00.000Z"
Last persisted DICT key lookup snapshot for this PIX key (from create or
update). Always present on every company and merchant PIX key response; use
null when no snapshot is stored (for example legacy keys) or the stored
snapshot is invalid.
Per BACEN's rules, DICT applies masking to protect against read attacks; fields such as account number, account type, and owner document may appear partially or fully masked (e.g. asterisks). Use the values as returned for any follow-up payment initiation on the same flow.
Show child attributes
Show child attributes

