Onerway
Get Started

Setup

Configure the Account service base URL, apikey, x-timestamp, and outbound IP allowlist before calling account balance, account transaction, account statement, and Global Account APIs.

Account service APIs use dedicated base URLs and an environment-specific apikey request header. Before you call account balance, account transaction, account statement, or Global Account endpoints, make sure the target environment, API access, apikey, x-timestamp, and outbound IP allowlist are ready.

Setup steps

Confirm API access

Account service APIs are restricted. Onerway must enable the corresponding capability for your merchant account before you can call the endpoints.

  • Before calling account balance, account transaction, and account statement APIs, confirm that Account service API access is enabled.
  • Before calling Global Account APIs, confirm that Global Account opening, collection, or payout capabilities are enabled.
  • If a platform merchant queries on behalf of a sub-merchant, confirm that the parent-child merchant relationship and onBehalfOf permission are configured.

Select the base URL

Use the Account service base URL that matches the environment of your apikey.

EnvironmentBase URL
Productionhttps://api.onerway.com/account-server
Sandboxhttps://sandbox-api.onerway.com/account-server
Sandbox and production credentials are separate. API paths start with /api/v2/... or with the /api/v1/... path shown on the current Global Account page. The base URL, API path, and apikey must come from the same environment.

Store the apikey

Account service APIs identify caller permissions through the apikey request header.

HeaderRequiredDescription
apikeyYesCredential value assigned for Account service access.
Store the apikey on your server. Do not expose it in frontend pages, mobile apps, client-side bundles, logs, or public repositories.

Send x-timestamp

Account balance, account transaction, and account statement APIs require both apikey and x-timestamp. The gateway uses x-timestamp to check whether the request is within the accepted time window and reduce replay risk.

HeaderRequiredDescription
x-timestampYesRequest timestamp. Accepts 10-digit seconds or 13-digit milliseconds. Must be within 10 minutes of the server time.
Content-TypeYes (POST)application/json.

Provide outbound IP addresses

Send your stable server outbound IP addresses to Onerway so they can be added to the Account service allowlist.

  • Provide only stable server outbound IP addresses.
  • If sandbox and production use different outbound IP addresses, provide them separately.
  • If an outbound IP address changes, update the allowlist before switching traffic.

Send a server-side request

After the environment, apikey, x-timestamp, and IP allowlist are ready, call the API from your server and include the required request headers.

curl https://sandbox-api.onerway.com/account-server/api/v2/account/balance/overview/query \
  -H 'Content-Type: application/json' \
  -H 'apikey: replace_with_account_service_apikey' \
  -H 'x-timestamp: 1776931200' \
  -d '{
    "requestId": "REQ-BAL-OV-20260423-0001",
    "displayCurrency": "USD"
  }'

Endpoint URLs

The current public Account service endpoint URLs are listed below. Build the request URL by appending the API path to the base URL for the target environment.

CategoryEndpointMethodPath
Account balanceQuery account balance overviewPOST/api/v2/account/balance/overview/query
Account balanceQuery account balancePOST/api/v2/account/balance/query
Account transactionQuery account transactionsPOST/api/v2/account/transactions/query
Account transactionQuery account transactions by transaction order numberPOST/api/v2/account/transactions/service/query
Account statementExport daily account statementPOST/api/v2/account/statement/daily/export
Global AccountCreate Global AccountPOST/api/v1/account/global/create
Global AccountGet Global Account detailsPOST/api/v1/account/global/getDetail

Complete Sandbox examples:

  • https://sandbox-api.onerway.com/account-server/api/v2/account/balance/overview/query
  • https://sandbox-api.onerway.com/account-server/api/v2/account/balance/query
  • https://sandbox-api.onerway.com/account-server/api/v2/account/transactions/query
  • https://sandbox-api.onerway.com/account-server/api/v2/account/transactions/service/query
  • https://sandbox-api.onerway.com/account-server/api/v2/account/statement/daily/export
  • https://sandbox-api.onerway.com/account-server/api/v1/account/global/create
  • https://sandbox-api.onerway.com/account-server/api/v1/account/global/getDetail

Idempotency

Account balance, account transaction, and account statement APIs are idempotent. Reuse the same requestId to safely retry a request within 10 minutes. A repeated requestId returns a 10006 DUPLICATE_REQUEST error of type idempotency_error.

Next steps