> ## Documentation Index
> Fetch the complete documentation index at: https://fastpay-mintlify-983ed565.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# List products

> Returns a paginated list of products in the catalog.



## OpenAPI

````yaml /api-reference/openapi.yaml get /v1/products
openapi: 3.0.0
info:
  title: FastPay API
  version: 1.0.0
  description: >-
    API for creating and managing payment charges.


    ## Authentication


    This API uses **Basic Authentication** for direct API access, such as
    creating charges.

    Use your API key as the username and an empty string as password.

    The header should be formatted as:


    `Authorization: Basic {base64(apiKey:)}`.


    For example:


    ```

    Authorization: Basic YWxleG91dG9uOiIi

    ```


    ## Webhooks


    FastPay sends webhooks to notify your application about charge status
    changes in real-time.

    Webhooks are sent via HTTP POST requests to your configured webhook
    endpoints.


    ### Webhook Events


    The following webhook events are available for charges:


    - `charge.created` - Sent when a new charge is created

    - `charge.pending` - Sent when a charge is pending payment

    - `charge.paid` - Sent when a charge is successfully paid

    - `charge.updated` - Sent when a charge is updated


    ### Webhook Payload Structure


    All webhook payloads follow this structure:


    ```json

    {
      "id": "webhook_event_id",
      "event": "charge.paid",
      "data": {
        // Complete charge object
      }
    }

    ```


    ### Webhook Delivery


    - Webhooks are sent via HTTP POST requests

    - Content-Type: `application/json`

    - Retry logic is implemented for failed deliveries

    - Webhook events are stored in the database for audit purposes

    - Delivery logs are maintained for debugging and monitoring


    ### Webhook Security


    - Webhooks are sent to pre-configured endpoints

    - Endpoints can be enabled/disabled per merchant

    - Event filtering is supported (only receive specific events)

    - Failed deliveries are retried with exponential backoff
servers:
  - url: https://api-global.fastpaybrasil.com
    description: Produção e Sandbox (diferenciados pela API key)
security: []
paths:
  /v1/products:
    get:
      tags:
        - Products
      summary: List products
      description: Returns a paginated list of products in the catalog.
      parameters:
        - name: merchantId
          in: query
          required: false
          schema:
            type: string
          description: Filter by merchant (admin use).
        - name: type
          in: query
          required: false
          schema:
            type: string
            enum:
              - physical
              - digital
          description: Filter by product type.
        - name: status
          in: query
          required: false
          schema:
            type: string
            enum:
              - active
              - inactive
          description: Filter by status.
        - name: search
          in: query
          required: false
          schema:
            type: string
          description: Search by `name` or `sku`.
        - name: page
          in: query
          required: false
          schema:
            type: integer
            default: 1
        - name: size
          in: query
          required: false
          schema:
            type: integer
            default: 10
        - name: orderBy
          in: query
          required: false
          schema:
            type: string
          description: |-
            Order results by fields (comma-separated). Prefix with `-` for
            descending order. Example: `-createdAt,name`.
      responses:
        '200':
          description: Successfully retrieved the list of products
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedProductList'
        '401':
          description: Unauthorized - invalid credentials
        '403':
          description: Forbidden - insufficient permissions
      security:
        - basic: []
components:
  schemas:
    PaginatedProductList:
      type: object
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/Product'
        page:
          type: integer
          example: 1
        pages:
          type: integer
          example: 10
        total:
          type: integer
          example: 100
        size:
          type: integer
          example: 10
    Product:
      type: object
      properties:
        id:
          type: string
          example: 2RhQg9M7ZCg3X3nMb9W1kX8Q
        merchantId:
          type: string
          example: 2RhQg9M7ZCg3X3nMb9W1kX8Q
        name:
          type: string
          example: Camiseta Preta P
        description:
          type: string
          nullable: true
        productLink:
          type: string
          nullable: true
        price:
          type: number
          example: 89.9
        currency:
          type: string
          example: BRL
        productType:
          type: string
          enum:
            - physical
            - digital
        sku:
          type: string
          nullable: true
        trackStock:
          type: boolean
        stock:
          type: integer
          nullable: true
        weight:
          type: number
          nullable: true
        heightCm:
          type: number
          nullable: true
        widthCm:
          type: number
          nullable: true
        lengthCm:
          type: number
          nullable: true
        status:
          type: string
          enum:
            - active
            - inactive
        imageUrl:
          type: string
          nullable: true
          description: |-
            Signed, short-lived URL for the product image. `null` when no
            image was uploaded.
        createdAt:
          type: string
          format: date-time
        updatedAt:
          type: string
          format: date-time
  securitySchemes:
    basic:
      type: http
      scheme: basic
      description: |-
        HTTP Basic authentication. Use your secret key as the
        username and an empty string as password. The API key
        should be base64 encoded in the format 'username:' when
        sending the Authorization header.

````