Skip to main content
Each domain owns a specific part of the instant payment flow. Together, the domains provide interoperability, security, and real-time execution across the ecosystem. This overview introduces the four core domains that form the foundation of Pix. Each child page in this section gives more detail.

Core Pix domains


DICT — Pix Key Directory

The DICT is the national registry of Pix keys. It maps simple identifiers (CPF/CNPJ, phone, email, random key) to transactional accounts. Users send and receive Pix without full bank details.

Pix Transactions

This domain manages the execution lifecycle of an instant payment — authorization, validation, settlement, status updates, and traceability. Every transaction flows through regulated paths and must settle within seconds in the SPI infrastructure.

QR Codes

Pix supports static and dynamic QR Codes for payment initiation. Static codes are reusable. Pix generates a dynamic code for each transaction. The dynamic code can carry the amount, metadata, and expiration.

MED — Special Refund Mechanism

The Mecanismo Especial de Devolução governs fraud-related refund scenarios. It defines mandatory rules, timelines, and workflows for disputes, error handling, and fraud investigation across institutions.

Additional Pix characteristics


Pix also follows system-wide principles for safety, inclusiveness, and nationwide compatibility.

Universal interoperability

Every participant in Pix communicates through shared standards — no closed networks, no proprietary protocols. Any participant can send and receive Pix with any other.

Regulatory standardization

BACEN defines the rules, message formats, limits, fraud controls, and operational requirements. All participants must follow the same specifications.

Open participation model

Pix supports many types of institution:
  • Banks
  • Payment institutions
  • Fintechs
  • Digital wallets
  • Cooperatives
  • Government entities

Security posture

Pix enforces a strict security framework with:
  • Strong encryption
  • Standardized authentication and authorization
  • Mandatory fraud-prevention processes
  • Full auditability and traceability of every event