Onerway
API Reference

WEBHOOK description

Understand Issuing webhook headers, payload envelope, merchant acknowledgement, and HMAC-SHA256 signature verification.

Use this page before implementing Issuing webhook callbacks. Onerway pushes card operation, card transaction, and 3DS events to the callback URL configured for the merchant.

Request headers

HeaderTypeRequiredDescription
Content-TypeStringYesFixed to application/json;charset=UTF-8.
x-timestampStringYesUnix timestamp in seconds.
x-signatureStringYesGenerate the HMAC-SHA256 signature from webhook_secret and x-timestamp + "." + raw_body. See Signature and verification.

Payload structure

FieldTypeRequiredDescription
request_idStringYesUnique event identifier for deduplication.
event_typeStringYesEvent type. Issuing currently sends issuing.cardOperateEvent, issuing.cardTransactionEvent, and issuing.card3dsEvent.
created_atStringYesEvent creation time in ISO 8601 format.
versionStringNoWebhook API version selected when the subscription is created. Defaults to 1.0 when not specified.
dataObjectYesBusiness data. The structure depends on event_type.

Merchant response requirements

The merchant callback must return a JSON response. Onerway uses this response to decide whether the push was received successfully.

FieldTypeDescription
respCodeStringReturn 20000 to confirm receipt.
respMsgStringResponse message.

If the callback response code is not 20000, Onerway retries every 15 seconds, up to 10 times.

Signature and verification

Onerway signs asynchronous notifications such as card operation, transaction, and 3DS events. Verify the signature before processing the event.

Build the signed content as:

x-timestamp + "." + raw_body

Generate the expected signature with HMAC-SHA256 and compare it with x-signature case-insensitively.

import javax.crypto.Mac;
import javax.crypto.spec.SecretKeySpec;
import java.nio.charset.StandardCharsets;
import java.security.MessageDigest;
import java.util.Base64;
import java.util.HexFormat;

public final class HmacSHA256Util {
    private HmacSHA256Util() {
    }

    public static String signHmacSHA256(String webhook_secret, String content) throws Exception {
        byte[] key = Base64.getDecoder().decode(webhook_secret);
        Mac mac = Mac.getInstance("HmacSHA256");
        mac.init(new SecretKeySpec(key, "HmacSHA256"));
        return HexFormat.of().formatHex(mac.doFinal(content.getBytes(StandardCharsets.UTF_8)));
    }

    public static boolean verifyHmacSHA256(String webhook_secret, String content, String signed) throws Exception {
        String expected = signHmacSHA256(webhook_secret, content);
        return MessageDigest.isEqual(
            expected.toLowerCase().getBytes(StandardCharsets.UTF_8),
            signed.toLowerCase().getBytes(StandardCharsets.UTF_8)
        );
    }
}