POST
Create direct transaction
Use this endpoint to create a server-to-server direct API transaction for card, wallet, saved-token, subscription, installment, or local payment method payments.
Request
billingInformation{ email, country, ... }Condition: Required except for later subscription billing or update (
Transaction billing information, including customer billing address and contact details.subscription.requestType=1 or 2).cardInfo{ holderName, cardNumber, ... }Condition:
Card payment information. Merchants that collect card details themselves, including - Required for direct card payments with merchant-collected card details.
- Required for merchant-decrypted Apple Pay / Google Pay wallet payments.
- Required for card token payments (
subProductType=TOKEN); submitcardInfo.cvvtogether withtokenInfo. - Required for Onerway-decrypted Google Pay
PAN_ONLYpayments when you collect the CVC yourself;cardInfomust contain onlycvvand be submitted together withtokenInfo.
cardInfo.cvv for card token payments, must be PCI DSS compliant. For wallet payments, submit either merchant-decrypted card data in cardInfo or the encrypted token in tokenInfo for Onerway decryption; the two are combined only when a Google Pay PAN_ONLY token needs the CVC, in which case cardInfo carries cvv only.Constraints
- Rule
- For merchant-decrypted Google Pay payments, configure
allowedAuthMethodsaccording to the Onerway requirement documented under tokenInfo.
merchantCustIdCondition: Required for card token payments (
Unique customer identifier in the merchant system. For subscriptions, subProductType=TOKEN) and subscription scenarios.subscription.merchantCustId is the subscription customer identifier; if this top-level field is also submitted, it must match.Example:
customer_12345merchantNoMerchant number assigned by Onerway. See Setup for how to obtain it.
Example:
800209Constraints
- Rule
- In the platform model, submit the merchant number of the sub-merchant the transaction is initiated for, not the platform merchant number. The sub-merchant must already be registered with Onerway.
merchantTxnIdUnique transaction identifier generated by the merchant system for tracking, reconciliation, and duplicate prevention.
merchantTxnTimeTransaction timestamp when the merchant initiated the transaction, in
yyyy-MM-dd HH:mm:ss format. If omitted, Onerway records the transaction time in UTC+8.merchantTxnTimeZoneTimezone offset for
merchantTxnTime. If omitted, Onerway records the transaction time in UTC+8.Example:
+08:00metaDataCustom data for this transaction. Must be a string containing valid JSON. Returned unchanged in transaction queries and asynchronous notifications; when omitted,
metaData is empty there.mpiInfo{ version, eci, ... }Condition: Required when
External 3DS / MPI authentication result. Direct API integrations may complete 3DS through their own MPI or 3DS Server and pass the result through unchanged.risk3dsStrategy=EXTERNAL.lpmsInfo{ lpmsType, bankName, ... }Condition: Required when
Local payment method information containing configuration parameters for the selected local payment method.productType=LPMS.orderAmountTransaction amount in the specified currency, formatted as a decimal string. For zero-decimal currencies, the amount must represent a whole amount; an all-zero decimal part is accepted, while non-zero decimals are rejected. Format rules follow currency and amount validation.
Example:
99.99osTypeCondition: Required when
Operating system type for mobile and app transactions.paymentMode is not WEB.Example:
IOSAllowed values
IOS- iOS device.
ANDROID- Android device.
paymentModePayment mode indicating the transaction platform or environment. Defaults to
WEB.Example:
WEBAllowed values
WEB- Desktop browser payment.
APP- Native mobile app payment.
WAP- Mobile browser payment.
paymentMethodOptions{ card, share }Payment method configuration options. Direct API transactions support the
card and share objects.productTypePayment method scope. Direct API calls must explicitly choose
CARD or LPMS; ALL is not supported because aggregated payment-method display is a Checkout concept.Example:
CARDAllowed values
CARD- Card payment scope, including direct card payments with merchant-collected card details and Apple Pay / Google Pay wallet payments.
LPMS- Local payment method scope.
lpmsInfois required when this value is used.
retailers{ retailerId, retailerName, ... }Retailer information for marketplace transactions. Submit one entry for each retailer whose products are included in this order.
Since 2026-08-10New field for marketplace retailer information.
Constraints
- Rule
- Applies to marketplace and platform models where products are sold by third-party retailers rather than by the merchant directly. Merchants selling only their own inventory do not need to submit it.
- Consistency
- When submitted, every entry in
txnOrderMsg.productsmust carry aretailerIdthat matches one of the retailers listed here.
risk3dsStrategy3DS risk strategy. Direct API supports
DEFAULT, INNER, NONE, and EXTERNAL; when using EXTERNAL, submit mpiInfo with the external authentication result. Contact Onerway before specifying a non-default strategy.Example:
DEFAULTAllowed values
DEFAULT- Default strategy. Onerway decides whether to trigger 3DS based on the transaction, merchant configuration, and risk controls.
INNER- Force Onerway-managed 3DS authentication.
NONE- Do not use 3DS authentication. Availability depends on merchant configuration and risk requirements.
shippingInformation{ email, country, ... }Condition: Required except for later subscription billing or update (
Transaction shipping information, including customer delivery address and contact details.subscription.requestType=1 or 2).signRequest signature string. See Request signing for how to generate it.
subProductTypeTransaction processing mode under the selected payment method scope. It works with
productType and txnType to define the transaction model.Example:
DIRECTAllowed values
DIRECT- Ordinary direct API payment. Execute a one-time debit, wallet payment, local payment method payment, or authorization according to
productTypeandtxnType. TOKEN- Card token payment. Use a saved card token with the customer identifier and always submit
cardInfo.cvv. SUBSCRIBE- Subscription transaction. Supports initial subscription, later merchant-triggered billing, and managed subscription update through
subscription.requestType.
subscription{ requestType, merchantCustId, ... }Condition: Required when
Subscription information. This direct API endpoint supports initial subscription (subProductType=SUBSCRIBE.requestType=0), later merchant-triggered billing (requestType=1), and managed subscription update (requestType=2).tokenInfo{ tokenId, provider }Condition:
Token credential used to initiate the payment. For wallet payments, submit the encrypted wallet token returned by the wallet SDK for Onerway decryption. For card token payments, submit the card token returned by card tokenization or the saved payment method flow; subscription tokens are submitted through - Required for Onerway-decrypted Apple Pay / Google Pay wallet payments.
- Required for card token payments (
subProductType=TOKEN).
subscription.tokenId, not here.Constraints
- Rule
- Onerway requires
allowedAuthMethodsin the Google PayCARDpayment method parameters to include bothPAN_ONLYandCRYPTOGRAM_3DS. This requirement applies to both Onerway decryption and merchant decryption. For merchant decryption, submit the decrypted payment data in cardInfo. - Rule
- For Google Pay, Onerway decryption corresponds to the
PAYMENT_GATEWAYtokenization: set the Google PaygatewayandgatewayMerchantIdparameters from thegatewayNameandgatewayMerchantIdreturned by List available payment methods. The token is encrypted with the Onerway key and cannot be decrypted by the merchant. - Rule
- For Onerway-decrypted Google Pay payments, calling Check Google Pay PAN_ONLY token before creating the transaction is optional. If you submit a
PAN_ONLYtoken withoutcardInfo.cvv, the transaction response containsdata.status=Randdata.redirectUrl, regardless of whether you called the check endpoint. Redirect the customer todata.redirectUrlto enter the CVC on the Onerway-hosted page. If you collect the CVC yourself, submit it in cardInfo.cvv together withtokenInfo.
txnOrderMsg{ products, returnUrl, ... }Condition: Required except for later subscription billing or update (
Transaction business information, including return URL, notification URL, store ID, products, browser data, device data, and cardholder IP data collected by the merchant.subscription.requestType=1 or 2).txnTypeTransaction operation type. It works with
productType and subProductType; REFUND and BIND_CARD are not used by this direct transaction endpoint.Example:
SALEAllowed values
SALE- Debit-style transaction. Together with
subProductType=DIRECT,TOKEN,SUBSCRIBE, orINSTALLMENT, it is used for ordinary payment, token payment, subscription, or installment payment. AUTH- Authorization-style transaction. Funds are authorized first and not captured immediately. It applies to direct card payments with merchant-collected card details and card token payments; it does not apply to LPMS, subscriptions, or installments.
curl -X POST 'https://sandbox-acq.onerway.com/v1/txn/doTransaction' \
-H 'Content-Type: application/json' \
--data-raw '{
"billingInformation": "{\"firstName\":\"John\",\"lastName\":\"Doe\",\"phone\":\"4848980027\",\"phoneCountryCode\":\"1\",\"email\":\"customer@example.com\",\"postalCode\":\"94016\",\"address\":\"100 Market Street\",\"country\":\"US\",\"province\":\"CA\",\"city\":\"San Francisco\",\"street\":\"Market Street\",\"number\":\"100\"}",
"cardInfo": "{\"holderName\":\"John Smith\",\"cardNumber\":\"{{CARD-NUMBER}}\",\"month\":\"12\",\"year\":\"2030\",\"cvv\":\"{{CVV}}\"}",
"merchantNo": "{{MERCHANT-NO}}",
"merchantTxnId": "txn_demo_direct_202606140001",
"merchantTxnTime": "2026-06-14 10:30:00",
"merchantTxnTimeZone": "+08:00",
"metaData": "{\"orderSource\":\"direct-api-demo\"}",
"orderAmount": "99.99",
"orderCurrency": "USD",
"paymentMethodOptions": "{\"card\":{\"avsEnabled\":true}}",
"paymentMode": "WEB",
"productType": "CARD",
"risk3dsStrategy": "DEFAULT",
"shippingInformation": "{\"firstName\":\"John\",\"lastName\":\"Doe\",\"phone\":\"4848980027\",\"phoneCountryCode\":\"1\",\"email\":\"customer@example.com\",\"postalCode\":\"94016\",\"address\":\"100 Market Street\",\"country\":\"US\",\"province\":\"CA\",\"city\":\"San Francisco\",\"street\":\"Market Street\",\"number\":\"100\"}",
"sign": "{{SIGN}}",
"subProductType": "DIRECT",
"txnOrderMsg": "{\"returnUrl\":\"{{RETURN-URL}}\",\"products\":\"[{\\\"name\\\":\\\"Demo product\\\",\\\"price\\\":\\\"99.99\\\",\\\"num\\\":\\\"1\\\",\\\"currency\\\":\\\"USD\\\"}]\",\"transactionIp\":\"203.0.113.10\",\"appId\":\"{{APPID}}\",\"javaEnabled\":false,\"colorDepth\":\"24\",\"screenHeight\":\"1080\",\"screenWidth\":\"1920\",\"timeZoneOffset\":\"-480\",\"accept\":\"text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8\",\"userAgent\":\"Mozilla/5.0 (Demo Browser)\",\"contentLength\":\"0\",\"language\":\"en-US\",\"notifyUrl\":\"{{WEBHOOK-ENDPOINT}}\"}",
"txnType": "SALE"
}'Response
respCodeResponse code;
20000 means the request was processed successfully, other values are error codes. See Response codes.respMsgHuman-readable message for the response code.
data{ transactionId, paymentId, ... }Business data object for the direct transaction response. The synchronous response may be terminal or may instruct the merchant to redirect or present an action.
{
"respCode": "20000",
"respMsg": "Success",
"data": {
"transactionId": "2064485863093829632",
"paymentId": "2064485863068663808",
"responseTime": "2026-06-14 10:30:02",
"txnTime": null,
"txnTimeZone": null,
"orderAmount": "99.99",
"orderCurrency": "USD",
"txnAmount": "",
"txnCurrency": null,
"status": "R",
"paymentStatus": "R",
"redirectUrl": "https://developers.onerway.com/example-direct-redirect",
"contractId": null,
"tokenId": null,
"eci": null,
"periodValue": null,
"codeForm": null,
"presentContext": null,
"actionType": "RedirectURL",
"subscriptionManageUrl": null,
"rrn": null,
"authorizationCode": null,
"cardInfo": null,
"sign": "{{SIGN}}"
}
}No error responses are documented for this endpoint.