name: dLocal API Rate Limits description: dLocal does not publicly publish specific rate limit thresholds in their API documentation. Rate limiting policies are communicated privately to merchants based on their contract and expected transaction volumes. The API uses HMAC-SHA256 signature authentication and idempotency keys to manage request integrity. Merchants experiencing rate-related issues should contact dLocal support. version: "0.1" url: https://docs.dlocal.com/reference/api authentication: method: HMAC-SHA256 description: All API requests must be signed using HMAC-SHA256. The signature is generated by concatenating X-Login, X-Date, and the request body, then hashing with the merchant Secret Key. headers: - name: X-Login description: Merchant identifier from the dLocal Merchant Dashboard required: true - name: X-Trans-Key description: Authentication credential paired with X-Login required: true - name: X-Date description: ISO8601 datetime in UTC format required: true - name: X-Version description: API version, currently "2.1" required: true - name: Authorization description: "V2-HMAC-SHA256, Signature: {generated_signature}" required: true - name: Content-Type description: Must be "application/json" required: true - name: User-Agent description: Application identifier required: true - name: X-Idempotency-Key description: Optional. Prevents duplicate operations. Max 42 characters, TTL of 7 days. required: false - name: X-Dlocal-Payment-Source description: Optional. Identifies the payment orchestrator managing the payment. required: false environments: - name: Sandbox url: https://sandbox.dlocal.com description: Testing environment with full API parity for integration development rateLimits: published: false notes: Rate limits not publicly documented for sandbox environment - name: Production url: https://api.dlocal.com description: Live production environment rateLimits: published: false notes: Rate limits are negotiated per merchant contract; contact dLocal for specifics notes: - dLocal does not publish rate limits publicly in their API documentation - Use X-Idempotency-Key to safely retry requests without risk of duplicate processing - Contact dLocal merchant support for rate limit information specific to your account