Setup
Account service APIs use dedicated base URLs and an environment-specific apikey request header. Before you call account balance, account transaction, account statement, or Global Account endpoints, make sure the target environment, API access, apikey, x-timestamp, and outbound IP allowlist are ready.
Setup steps
Confirm API access
Account service APIs are restricted. Onerway must enable the corresponding capability for your merchant account before you can call the endpoints.
- Before calling account balance, account transaction, and account statement APIs, confirm that Account service API access is enabled.
- Before calling Global Account APIs, confirm that Global Account opening, collection, or payout capabilities are enabled.
- If a platform merchant queries on behalf of a sub-merchant, confirm that the parent-child merchant relationship and
onBehalfOfpermission are configured.
Select the base URL
Use the Account service base URL that matches the environment of your apikey.
| Environment | Base URL |
|---|---|
| Production | https://api.onerway.com/account-server |
| Sandbox | https://sandbox-api.onerway.com/account-server |
/api/v2/... or with the /api/v1/... path shown on the current Global Account page. The base URL, API path, and apikey must come from the same environment.Store the apikey
Account service APIs identify caller permissions through the apikey request header.
| Header | Required | Description |
|---|---|---|
apikey | Yes | Credential value assigned for Account service access. |
apikey on your server. Do not expose it in frontend pages, mobile apps, client-side bundles, logs, or public repositories.Send x-timestamp
Account balance, account transaction, and account statement APIs require both apikey and x-timestamp. The gateway uses x-timestamp to check whether the request is within the accepted time window and reduce replay risk.
| Header | Required | Description |
|---|---|---|
x-timestamp | Yes | Request timestamp. Accepts 10-digit seconds or 13-digit milliseconds. Must be within 10 minutes of the server time. |
Content-Type | Yes (POST) | application/json. |
Provide outbound IP addresses
Send your stable server outbound IP addresses to Onerway so they can be added to the Account service allowlist.
- Provide only stable server outbound IP addresses.
- If sandbox and production use different outbound IP addresses, provide them separately.
- If an outbound IP address changes, update the allowlist before switching traffic.
Send a server-side request
After the environment, apikey, x-timestamp, and IP allowlist are ready, call the API from your server and include the required request headers.
curl https://sandbox-api.onerway.com/account-server/api/v2/account/balance/overview/query \
-H 'Content-Type: application/json' \
-H 'apikey: replace_with_account_service_apikey' \
-H 'x-timestamp: 1776931200' \
-d '{
"requestId": "REQ-BAL-OV-20260423-0001",
"displayCurrency": "USD"
}'
Endpoint URLs
The current public Account service endpoint URLs are listed below. Build the request URL by appending the API path to the base URL for the target environment.
| Category | Endpoint | Method | Path |
|---|---|---|---|
| Account balance | Query account balance overview | POST | /api/v2/account/balance/overview/query |
| Account balance | Query account balance | POST | /api/v2/account/balance/query |
| Account transaction | Query account transactions | POST | /api/v2/account/transactions/query |
| Account transaction | Query account transactions by transaction order number | POST | /api/v2/account/transactions/service/query |
| Account statement | Export daily account statement | POST | /api/v2/account/statement/daily/export |
| Global Account | Create Global Account | POST | /api/v1/account/global/create |
| Global Account | Get Global Account details | POST | /api/v1/account/global/getDetail |
Complete Sandbox examples:
https://sandbox-api.onerway.com/account-server/api/v2/account/balance/overview/queryhttps://sandbox-api.onerway.com/account-server/api/v2/account/balance/queryhttps://sandbox-api.onerway.com/account-server/api/v2/account/transactions/queryhttps://sandbox-api.onerway.com/account-server/api/v2/account/transactions/service/queryhttps://sandbox-api.onerway.com/account-server/api/v2/account/statement/daily/exporthttps://sandbox-api.onerway.com/account-server/api/v1/account/global/createhttps://sandbox-api.onerway.com/account-server/api/v1/account/global/getDetail
Idempotency
Account balance, account transaction, and account statement APIs are idempotent. Reuse the same requestId to safely retry a request within 10 minutes. A repeated requestId returns a 10006 DUPLICATE_REQUEST error of type idempotency_error.
Next steps
- Query account balance overview - Query multi-currency account balance summaries
- Query account balance - Read the balance for one account currency
- Query account transactions - Review account transaction records and balance movements
- Query account transactions by transaction order number - Query related account transactions by transaction order number
- Export daily account statement - Export a daily account statement CSV
- Create Global Account - Create a Global Account for collection and payout scenarios
- Get Global Account details - Retrieve Global Account onboarding details and status
- Response codes - Handle Account service response codes and troubleshooting actions