# AX Check: dlocal.com
Checked 2026-09-29.

Docs and setup steps are clear, but pricing stays behind Sales
Quickstart, API reference, and setup steps all resolve cleanly. No pricing page exists; rates are custom-quoted, confirmed by all 3 of 3 sessions.

## Onboarding needs a login

## Coding sessions
All three independent sessions completed and reached the same conclusion on pricing: dLocal publishes no public rate card. Each described a negotiated, per-transaction commission structure varying by country, payment method, and volume, plus FX spread, sourced from docs rather than a pricing page.

### DeepSeek V4.1 Flash
[View public run](https://agents.withgauge.com/p/runs/caabb3d6-a45e-4b16-a989-f5548ea542e9) · [Read transcript](https://www.ax-check.com/dlocal.com/sessions/deepseek.json)
README.md 'How pricing works' section states enterprise pricing is negotiated (percentage + FX spread) and dLocal Go is per-transaction commission varying by country/method, citing the official pricing PDF and help center as sources plus flagging third-party 0.99%-7.99% estimates as unverified.
#### End-to-end onboarding
- **Onboarding needs a login**: The agent never obtained real dLocal or dLocal Go credentials during the session. It only probed both hosted sandboxes with dummy/no credentials, which correctly returned auth errors, and then wrote a local example project with placeholder .env values, guarding cleanly on missing keys. No self-service signup or credential-issuance flow was exercised, and no authenticated product operation (e.g., a real payment creation) was ever completed.
  Event 94:

  ```text
  HTTP 403
  {"code":3001,"message":"Invalid Credentials."}
  ```
  Event 36:

  ```text
  Sandbox API credential. Get them from the [Settings section](https://dashboard.dlocal.com/settings) in the Dashboard.
  ```
  Event 133:

  ```text
  Blocker: I could build and unit-test the code here, but I cannot run a real call without merchant credentials.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-service credentials for either dLocal product**: The agent could not obtain sandbox API keys for dLocal Go or enterprise dLocal within the session. It confirmed both hosted sandbox endpoints are reachable but require real merchant credentials, which is normal login/account-provisioning gating rather than a product defect. Enterprise dLocal additionally requires account approval before sandbox keys are issued, which is a heavier onboarding requirement than typical self-serve APIs.
  Event 94:

  ```text
  HTTP 403
  {"code":3001,"message":"Invalid Credentials."}
  ```
  Event 133:

  ```text
  I can't execute a real call without merchant keys; enterprise also isn't self-serve, so sandbox access depends on account approval.
  ```
- **No official first-party SDK for either product**: The agent searched npm and PyPI for a dLocal SDK and found no legitimate first-party package, only unrelated or community packages, meaning developers must hand-roll HTTP clients and HMAC signing themselves. This is a gap in the developer tooling ecosystem rather than an agent error, but it adds implementation burden compared to APIs with an official SDK.
  Event 47:

  ```text
  npm error code E404
  npm error 404 Not Found - GET https://registry.npmjs.org/dlocal - Not found
  ```
  Event 47:

  ```text
  Traceback (most recent call last):
    File "<string>", line 1, in <module>
  KeyError: 'info'
  ```

#### Suggested Changes
- **Publish an official pricing page linked from the docs quickstart**: No public rate card exists on docs.dlocal.com or dlocal.com/pricing; the agent had to fall back to a dLocal Go PDF, a help-center article, and third-party comparison sites to estimate fees. Add a pricing/fees page linked from the 'Get started' guide (https://docs.dlocal.com/docs/get-started) for both enterprise and dLocal Go, and confirm it works by checking that dlocal.com/pricing/ no longer 404s.
  Event 48:

  ```text
  pricing HTTP 404
  <title>dLocal</title>
  <title>Oops!</title>
  ```
  Event 56:

  ```text
  dLocal uses custom pricing that is negotiated based on your transaction volume, the markets you operate in, and the payment methods you use.
  ```
- **Link an official SDK (or state there isn't one) in the get-started guide**: The agent had to hand-write an HTTP client and HMAC signer because no official npm/PyPI package exists; only the GitHub 'Starter-Code-Examples' repo is referenced for signature snippets. Add an explicit note in the get-started/generate-signature docs pointing to a maintained SDK if one exists, or clarify that raw HTTP + provided code snippets are the intended integration path, and verify by checking the rendered https://docs.dlocal.com/docs/generate-signature page.
  Event 47:

  ```text
  npm error 404 Not Found - GET https://registry.npmjs.org/dlocal - Not found
  ```
  Event 35:

  ```text
  Our GitHub repository hosts a variety of signature examples, which can be a valuable resource for understanding implementation details
  ```

### Kimi K3
[View public run](https://agents.withgauge.com/p/runs/2bd73961-a112-4ad3-a1e4-18630f14348c) · [Read transcript](https://www.ax-check.com/dlocal.com/sessions/kimi.json)
Final output states dLocal has no public price list, pricing is custom-quoted per-merchant based on countries/methods/volume, per-transaction % with FX spread, plus extra fees for payouts/refunds/chargebacks — clear assumptions named rather than a bare figure.
#### End-to-end onboarding
- **Onboarding needs a login**: No credentials of any kind were obtained during the session. The agent had no dLocal account/API keys, tested the payment endpoint with placeholder dummy values, and got a 403 Invalid credentials response confirming it never authenticated. The agent explicitly states dLocal has no self-serve trial keys and a merchant account (KYB) is required, plus the sandbox host did not resolve from the test network.
  Event 53:

  ```text
  HTTP 403
  {
    "code": 3001,
    "message": "Invalid credentials"
  }
  ```
  Event 55:

  ```text
  Blocked on a real end-to-end call.** dLocal has no self-serve trial keys: you need a merchant account (business onboarding/KYB) to get sandbox credentials, and additionally the sandbox host (`api-sandbox.dlocal.com`) doesn't resolve from this sandbox's network.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-serve API credentials available**: dLocal requires a full merchant/business onboarding (KYB) process to obtain even sandbox API keys; there is no free trial or self-service signup. This is a product/business-model characteristic, not an agent error, and it stopped the agent from completing an authenticated end-to-end call.
  Event 55:

  ```text
  dLocal has no self-serve trial keys: you need a merchant account (business onboarding/KYB) to get sandbox credentials
  ```
- **Sandbox API host unreachable from test network**: The documented sandbox hostname api-sandbox.dlocal.com failed to resolve from the sandbox environment's network, separate from the credential issue, preventing any sandbox-based testing even if credentials had been available.
  Event 55:

  ```text
  the sandbox host (`api-sandbox.dlocal.com`) doesn't resolve from this sandbox's network
  ```
- **No published pricing page**: dLocal's public pricing page returns a 404, and the site has no rate card; pricing is only available via custom sales quotes. This is a product/business decision (enterprise sales-led pricing) rather than a broken link, since the agent found no evidence the URL was guessed incorrectly versus genuinely absent.
  Event 32:

  ```text
  404 https://www.dlocal.com/pricing/
  ```
  Event 55:

  ```text
  dLocal does **not publish a price list** — there's no pricing page or rate card on their site (I checked; it 404s).
  ```

#### Suggested Changes
- **Publish a lightweight self-service sandbox signup flow**: Developers currently cannot get any sandbox X-Login/X-Trans-Key/Secret without going through business KYB onboarding, which blocked this session from ever completing an authenticated call. Adding a free self-serve sandbox key generator (similar to Stripe's test-mode keys) on the dLocal developer portal would let evaluators verify the API end-to-end; success can be checked by confirming a newly signed-up developer receives working sandbox credentials without a sales conversation.
  Event 55:

  ```text
  dLocal has no self-serve trial keys: you need a merchant account (business onboarding/KYB) to get sandbox credentials
  ```
- **Fix DNS/reachability for the documented sandbox host**: The example code and docs reference api-sandbox.dlocal.com as the sandbox base URL, but the host failed to resolve entirely, and a related sandbox host also failed to resolve. Confirming the correct, resolvable sandbox hostname in the docs and testing it with a plain curl request would validate the fix.
  Event 55:

  ```text
  the sandbox host (`api-sandbox.dlocal.com`) doesn't resolve from this sandbox's network
  ```
  Event 18:

  ```text
  Could not resolve host: api-sandbox.dlocalgo.com
  ```
- **Add an official Node.js SDK or clarify its absence in the quickstart**: npm has no official dlocal-node package, only unofficial community packages exist, forcing the agent to hand-roll HMAC-SHA256 auth from scratch. Publishing an official SDK, or explicitly stating in the quickstart docs that none exists and linking the correct auth reference, would reduce this friction; check by searching npm for an official '@dlocal' scoped package.
  Event 18:

  ```text
  npm error 404
  npm error 404  'dlocal-node@*' is not in this registry.
  ```

### Qwen 3.8 Max
[View public run](https://agents.withgauge.com/p/runs/c34a2058-c4d4-408d-988d-bb05c065f512) · [Read transcript](https://www.ax-check.com/dlocal.com/sessions/qwen.json)
Final output gives pricing structure (per-country/per-method MDR, FX spread, settlement_period/pricing_level, installments_responsible) and explicitly names the assumption that no public rate card exists and terms are negotiated per merchant — grounded rather than a bare number.
#### End-to-end onboarding
- **Onboarding needs a login**: The agent never obtained real dLocal API credentials on its own. It built a complete, well-structured client and tried it against the live sandbox endpoint with placeholder values, which correctly returned an authenticated-but-rejected response (403 invalid credentials). This proves the signing/request plumbing works, but it is not a successful authenticated operation — no resource was created and no real account was reached. The docs explicitly require a human to sign up on the Merchant Dashboard to get sandbox keys, and the agent flagged this as the sole blocker and stopped there.
  Event 51:

  ```text
  **A dLocal account**. [Sign up](https://dashboard.dlocal.com/signup) or [log in](https://dashboard.dlocal.com/login) if you already have one.
  * **Sandbox API credential**. Get them from the [Settings section](https://dashboard.dlocal.com/settings) in the Dashboard.
  ```
  Event 99:

  ```text
  HTTP 403
  {
    "code": 3001,
    "message": "Invalid credentials"
  }
  exit=1
  ```
  Event 137:

  ```text
  **Blocked only on credentials**: sandbox keys require a human signup at dashboard.dlocal.com (Settings → Integration, Test mode).
  ```

#### Hallucinated URLs
- **Guessed npm package name for dLocal SDK**: The agent tried installing a package named 'dlocal-node' without having seen it referenced anywhere, and it failed with a 404 from the npm registry. This was a reasonable guess given the product name, and the agent immediately pivoted to searching the registry properly, so it is a minor, quickly-corrected guess rather than a lasting hallucination.
  Event 10:

  ```text
  timeout 25 npm view dlocal-node version 2>&1 | tail -5
  ```
  Event 12:

  ```text
  npm error 404  'dlocal-node@*' is not in this registry.
  ```

#### Blockers
- **Sandbox API credentials require human dashboard signup**: dLocal's own documentation states that sandbox and production credentials can only be obtained by creating an account and logging into the Merchant Dashboard. This is normal product behavior (a standard signup/login wall), not a defect or agent error, and it fully blocked any real authenticated call. The agent correctly identified this, verified the request pipeline still worked end-to-end against the sandbox with placeholder keys, and stopped rather than fabricating success.
  Event 51:

  ```text
  **A dLocal account**. [Sign up](https://dashboard.dlocal.com/signup) or [log in](https://dashboard.dlocal.com/login) if you already have one.
  * **Sandbox API credential**. Get them from the [Settings section](https://dashboard.dlocal.com/settings) in the Dashboard.
  ```
  Event 99:

  ```text
  HTTP 403
  {
    "code": 3001,
    "message": "Invalid credentials"
  }
  exit=1
  ```

#### Suggested Changes
- **Publish an official Node.js server SDK on npm**: The agent's search of the npm registry for a dLocal Node SDK returned only unmaintained community packages, forcing it to hand-write a ~120-line HMAC signing and HTTP client from scratch. Publishing and documenting a first-party 'dlocal-node' (or similarly named) package would remove this from every future integration. Check by searching npm for 'dlocal' and confirming an official, actively-maintained package appears at the top of results.
  Event 17:

  ```text
  dlocaljs 0.0.2-a A Node.js library for interacting with the DLocal API.
  ```
  Event 12:

  ```text
  npm error 404  'dlocal-node@*' is not in this registry.
  ```
- **Fix the broken README.md encoding in the JavaScript Starter-Code-Examples repo**: The Javascript Payouts Payins sample README.md in dlocal/Starter-Code-Examples on GitHub renders as UTF-16-with-null-byte garbage when fetched as raw text, making the setup instructions unreadable without manual decoding. Re-save that file as plain UTF-8 in the repo and verify by curling the raw README URL and confirming it prints normal readable Markdown.
  Event 36:

  ```text
  ��#� �N�o�d�e�.�j�s� �P�a�y�m�e�n�t�s� �P�r�o�j�e�c�t�
  ```

### Task given to each agent
Help me build a simple example using dLocal. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.

No product credentials were supplied and no purchases were authorized.

## Score: B · 81/100 (provisional)
Grades come from completed site checks. Coding sessions and skipped checks do not affect the score.

### Clarity
- **Failed** — Homepage answers Markdown requests

  ```text
  Homepage returned text/html for a text/markdown request; no Markdown representation offered.
  ```

- **Pass** — llms.txt provides an actionable documentation index

  ```text
  llms.txt returns 200 with organized product, payment, country, industry, and developer doc links.
  ```

- **Pass** — llms.txt provides navigation guidance

  ```text
  llms.txt groups links under clear headings and points to docs, get-started, and docs llms.txt.
  ```

- **Pass** — llms.txt mentions offered API, MCP, and skills

  ```text
  llms.txt lists API reference, Postman collection, and an MCP Server blog entry.
  ```

- **Pass** — A compact guide representation exists

  ```text
  docs.dlocal.com/docs/get-started.md returns a standalone Markdown guide with concrete steps.
  ```

- **Pass** — A focused guide is directly retrievable

  ```text
  Get-started guide is directly retrievable as Markdown and HTML with account, credentials, signature, test steps.
  ```

- **Pass** — Equivalent instructions fit a token budget

  ```text
  Markdown guide is 4509 tokens, well under the 8000-token budget.
  ```

- **Skipped** — Product-docs links survive format changes

  ```text
  Homepage Markdown unsupported, so link preservation across formats cannot be measured.
  ```

- **Pass** — The compact guide is independently actionable

  ```text
  Get-started guide gives concrete steps: sign up, get API credentials, generate signature, test payment, go live.
  ```

- **Pass** — Install and next-step links resolve

  ```text
  Fetched get-started, API reference, and security pages all returned HTTP 200.
  ```


### Onboarding
- **Pass** — Docs lead to a relevant quickstart

  ```text
  Get started page gives a 5-step integration path: credentials, signature, test payment, settings, live mode.
  ```

- **Skipped** — Installation commands are extractable

  ```text
  No install commands; dLocal is a REST API with no SDK/CLI package shown in fetched docs.
  ```

- **Skipped** — Code examples are available without interaction

  ```text
  Fetched get-started page shows steps and links but no inline code examples or request samples.
  ```

- **Pass** — Prerequisites and auth boundaries are explicit

  ```text
  Get started requires account signup, 2FA, and API credentials from the dashboard Integration section.
  ```


### Pricing
- **Skipped** — Pricing is readable without interaction

  ```text
  No dLocal pricing page was fetched; homepage only offers Contact Sales.
  ```

- **Skipped** — Prices are stated, not gated

  ```text
  No dLocal pricing page was fetched; no stated prices observed.
  ```

- **Skipped** — Pricing units and limits are explicit

  ```text
  No dLocal pricing page was fetched, so units and limits are unobserved.
  ```

- **Pass** — Agents identify pricing and its assumptions

  ```text
  3 of 3 sessions were judged on pricing; 0 fell short. DeepSeek V4.1 Flash: README.md 'How pricing works' section states enterprise pricing is negotiated (percentage + FX spread) and dLocal Go is per-transaction commission varying by country/method, citing the official pricing PDF and help center as sources plus flagging third-party 0.99%-7.99% estimates as unverified. Kimi K3: Final output states dLocal has no public price list, pricing is custom-quoted per-merchant based on countries/methods/volume, per-transaction % with FX spread, plus extra fees for payouts/refunds/chargebacks — clear assumptions named rather than a bare figure. Qwen 3.8 Max: Final output gives pricing structure (per-country/per-method MDR, FX spread, settlement_period/pricing_level, installments_responsible) and explicitly names the assumption that no public rate card exists and terms are negotiated per merchant — grounded rather than a bare number. This behavioural item does not affect the fast grade.
  ```


### Activation
- **Pass** — An API reference or OpenAPI spec is reachable

  ```text
  API Reference page and full endpoint index reachable at docs.dlocal.com/reference with base URLs and auth.
  ```

- **Skipped** — An MCP server is documented and well-formed

  ```text
  llms.txt links a blog post about an MCP Server but no MCP server docs or endpoint are fetched.
  ```

- **Skipped** — A CLI install path is documented

  ```text
  No CLI install path is documented in the fetched pages; only API, SDK signature examples and Postman.
  ```

- **Skipped** — SDK packages resolve on their registries

  ```text
  No SDK package registry lookup result is supplied; only a GitHub signature-examples repo is mentioned.
  ```

- **Skipped** — Agent skills are published

  ```text
  No agent skills are published or referenced in the fetched dLocal documentation pages.
  ```



[Full report data](https://www.ax-check.com/dlocal.com/report.json)
