Onerway
POST

Query fraud notifications

Use this endpoint to retrieve fraud notifications and link each notification back to the original transaction through originTransactionId.

Request

merchantNo
Merchant number assigned by Onerway. See Setup for how to obtain it.
Example:
notificationId
Unique identifier of the fraud notification. Submit it to query one fraud notification precisely.
fraudType
Fraud type used to filter fraud notifications.
Example:
Allowed values
Lost
Lost card.
Lost Fraud
Fraud involving a lost card.
Stolen
Stolen card.
originTransactionId
Original Onerway transaction ID, transmitted as a JSON string and used to filter fraud notifications for one source transaction.
createTimeStart
Start of the notification creation time range, in yyyy-MM-dd HH:mm:ss format.
Constraints
Rule
When querying only by time range, submit both createTimeStart and createTimeEnd. The maximum range is 90 days.
createTimeEnd
End of the notification creation time range, in yyyy-MM-dd HH:mm:ss format. It should be later than createTimeStart.
Constraints
Rule
When querying only by time range, submit both createTimeStart and createTimeEnd. The maximum range is 90 days.
current
Query page number. 0 and 1 both mean the first page. The response current value is always returned as a 1-based page number.
Example:
sign
Request signature string. See Request signing for how to generate it.

Request example

curl -X POST 'https://sandbox-acq.onerway.com/fraud/list' \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "createTimeEnd": "2026-06-21 23:59:59",
  "createTimeStart": "2026-06-01 00:00:00",
  "current": "1",
  "merchantNo": "replace_with_merchant_no",
  "sign": "{{SIGN}}"
}'

Response

respCode
20000 means the query request was processed successfully. Other values are error codes. See Response codes.
respMsg
Human-readable message for the response code.
Business data object containing fraud notifications and pagination information.

Response example

Example code is unavailable.

No error responses are documented for this endpoint.