Onerway
POST

Create card token

Use this endpoint to create a card token in a PCI DSS compliant integration. The synchronous response carries the processing status and any required next action; receive the final tokenization result through notifyUrl.

Request

appId
Store ID generated when the merchant is onboarded with Onerway.
Example:
Card payment information collected directly by the merchant backend in a PCI DSS compliant environment. Do not store sensitive authentication data after authorization.
country
Customer country in ISO 3166-1 alpha-2 format.
Example:
email
Customer email address, used for transaction confirmation and dispute handling.
Example:
merchantCustId
Unique customer identifier in the merchant system. The saved card token is associated with this customer.
Example:
merchantNo
Merchant number assigned by Onerway. See Setup for how to obtain it.
Example:
notifyUrl
HTTPS endpoint that receives the final card-token creation result callback, including the card token and masked card details. The callback contract is the Saved payment method result webhook.
Example:
returnUrl
HTTPS browser return URL used when a card-binding 3DS challenge requires redirect handling.
Example:
sign
Request signature string. See Request signing for how to generate it.
transactionIp
Cardholder transaction IP collected by the merchant. Submit the end-user IP, not the merchant server IP.
Example:

Request example

curl -X POST 'https://sandbox-acq.onerway.com/v1/txn/bindCard' \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "appId": "replace_with_app_id",
  "cardInfo": "{\"holderName\":\"replace_with_cardholder_name\",\"cardNumber\":\"{{CARD-NUMBER}}\",\"month\":\"12\",\"year\":\"2030\",\"cvv\":\"{{CVV}}\"}",
  "country": "US",
  "email": "customer@example.com",
  "merchantCustId": "cust_demo_tokenization_202606150001",
  "merchantNo": "replace_with_merchant_no",
  "notifyUrl": "https://developers.onerway.com/example-card-token-notify",
  "returnUrl": "https://developers.onerway.com/example-card-token-return",
  "sign": "{{SIGN}}",
  "transactionIp": "192.0.2.10"
}'

Response

respCode
Response code; 20000 means the request was processed successfully, other values are error codes. See Response codes.
respMsg
Human-readable message for the response code.
Business data object carrying synchronous processing status and next-action fields for this tokenization request.

Response example

{
  "respCode": "20000",
  "respMsg": "Success",
  "data": {
    "transactionId": "txn_demo_tokenization_202606150001",
    "tokenId": "example_token_id",
    "status": "S",
    "redirectUrl": null,
    "sign": "{{SIGN}}"
  }
}
No error responses are documented for this endpoint.