# Postman (/en/docs/cartao/postman)

<QuickLinks>
  <QuickLink href="https://docs.payzu.com.br/payzu-cartao.postman_collection.json" title="Collection (JSON)" />

  <QuickLink href="/cartao-openapi.json" title="OpenAPI" />

  <QuickLink href="/api-scalar-cartao" title="Scalar" />

  <QuickLink href="/api-swagger-cartao" title="Swagger" />
</QuickLinks>

The **PayZu Credit Card API** collection covers the 12 routes of the Cards API, in four folders: `Token`, `Charges`, `Recurrences` and `Currencies`. Each request comes with a saved response example.

## Import [#import]

In Postman, **Import → Link**:

```
https://docs.payzu.com.br/payzu-cartao.postman_collection.json
```

## Variables [#variables]

| Variable            | Value                                                                                              |
| ------------------- | -------------------------------------------------------------------------------------------------- |
| `baseUrl`           | `https://api.payzu.io/v1` (production, default). In the sandbox, `https://api.sandbox.payzu.io/v1` |
| `basicAuthUsername` | `client_id`, used only in `POST /token`                                                            |
| `basicAuthPassword` | `client_secret`, used only in `POST /token`                                                        |
| `token`             | The `access_token` returned by `POST /token`                                                       |

Authentication is set at the collection level, with `Authorization: Bearer {{token}}`, and every request inherits it. The exception is `POST /token`, which uses Basic Auth with `basicAuthUsername` and `basicAuthPassword`.

## Client certificate (mTLS) [#client-certificate-mtls]

Every call requires the client certificate issued by PayZu. In Postman, it goes under **Settings → Certificates**:

* **Client certificates**: the `baseUrl` host (`api.payzu.io` or `api.sandbox.payzu.io`), the `.crt` file and the `.key` file.
* **CA certificates**: the `ca.pem`.

Without the certificate, the server closes the connection right after the request is sent and Postman shows a socket error. The mTLS details are in [Authentication](/docs/cartao/authentication).

<Callout type="warn">
  With the default `baseUrl`, calls go to **production**. To test, use the sandbox and the [test cards](/docs/cartao/test-cards).
</Callout>