POST
Validate Apple Pay merchant
Use this endpoint in the
onvalidatemerchant event to obtain an Apple merchant session through Onerway when Onerway registers your Apple Pay domains. Merchants with their own Apple Developer account request the session from Apple directly with their own Merchant Identity certificate and do not call this endpoint; setup tiers and the session flow are covered in Apple Pay.Request
merchantNoMerchant number assigned by Onerway. See Setup for how to obtain it.
Example:
replace_with_merchant_noappIdApplication or site identifier assigned by Onerway. It identifies the merchant application that shows the Apple Pay button.
Example:
replace_with_app_idrequestIdMerchant-generated unique request identifier used for request tracing.
Example:
req_demo_apple_pay_202609090001verifyUrlApple merchant validation URL that Onerway calls on your behalf to request the merchant session.
Constraints
- Rule
- Pass through the
validationURLfrom theonvalidatemerchantevent unchanged. Before forwarding it, confirm on your server that the host is an Apple Pay gateway domain and reject any other URL.
websiteMerchant domain that shows the Apple Pay button, without the protocol prefix.
Example:
example.comConstraints
- Rule
- Must be a domain that Onerway has registered and Apple has verified for this merchant, and must match the domain of the page that starts the Apple Pay session. It maps to Apple
initiativeContext.
signRequest signature string. See Request signing for how to generate it.
curl -X POST 'https://sandbox-acq.onerway.com/txn/apiCheckApplePay' \
-H 'Content-Type: application/json' \
--data-raw '{
"merchantNo": "replace_with_merchant_no",
"appId": "replace_with_app_id",
"requestId": "req_demo_apple_pay_202609090001",
"verifyUrl": "https://apple-pay-gateway.apple.com/paymentservices/startSession",
"website": "example.com",
"sign": "{{SIGN}}"
}'Response
respCodeResponse code returned by Onerway.
20000 means the merchant session was obtained; other values indicate failure. See Response codes.respMsgHuman-readable message for the response code.
dataApple merchant session returned by Apple for this validation request.
Constraints
- Rule
- The value is a JSON string. Parse it on the client and pass the resulting object to
session.completeMerchantValidation()unchanged; do not inspect, modify, cache, or reuse it. Apple merchant sessions are short-lived, so request one only insideonvalidatemerchantand complete validation immediately.
{
"respCode": "20000",
"respMsg": "Success",
"data": "{\"epochTimestamp\":1757400000000,\"expiresAt\":1757400300000,\"merchantSessionIdentifier\":\"replace_with_merchant_session_identifier\",\"nonce\":\"replace_with_nonce\",\"merchantIdentifier\":\"replace_with_merchant_identifier\",\"domainName\":\"example.com\",\"displayName\":\"Example Store\",\"signature\":\"replace_with_signature\"}"
}No error responses are documented for this endpoint.
Update SDK order
Update the order amount, billing information, or shipping information of an SDK transaction before the customer confirms payment.
Check Google Pay PAN_ONLY token
Check whether a Google Pay token is PAN_ONLY and needs a CVC before creating the direct transaction when you collect the CVC yourself.