Onerway
POST

Validate Apple Pay merchant

Use this endpoint in the onvalidatemerchant event to obtain an Apple merchant session through Onerway when Onerway registers your Apple Pay domains. Merchants with their own Apple Developer account request the session from Apple directly with their own Merchant Identity certificate and do not call this endpoint; setup tiers and the session flow are covered in Apple Pay.

Request

merchantNo
Merchant number assigned by Onerway. See Setup for how to obtain it.
Example:
appId
Application or site identifier assigned by Onerway. It identifies the merchant application that shows the Apple Pay button.
Example:
requestId
Merchant-generated unique request identifier used for request tracing.
Example:
verifyUrl
Apple merchant validation URL that Onerway calls on your behalf to request the merchant session.
Constraints
Rule
Pass through the validationURL from the onvalidatemerchant event unchanged. Before forwarding it, confirm on your server that the host is an Apple Pay gateway domain and reject any other URL.
website
Merchant domain that shows the Apple Pay button, without the protocol prefix.
Example:
Constraints
Rule
Must be a domain that Onerway has registered and Apple has verified for this merchant, and must match the domain of the page that starts the Apple Pay session. It maps to Apple initiativeContext.
sign
Request signature string. See Request signing for how to generate it.

Request example

curl -X POST 'https://sandbox-acq.onerway.com/txn/apiCheckApplePay' \
  -H 'Content-Type: application/json' \
  --data-raw '{
  "merchantNo": "replace_with_merchant_no",
  "appId": "replace_with_app_id",
  "requestId": "req_demo_apple_pay_202609090001",
  "verifyUrl": "https://apple-pay-gateway.apple.com/paymentservices/startSession",
  "website": "example.com",
  "sign": "{{SIGN}}"
}'

Response

respCode
Response code returned by Onerway. 20000 means the merchant session was obtained; other values indicate failure. See Response codes.
respMsg
Human-readable message for the response code.
data
Apple merchant session returned by Apple for this validation request.
Constraints
Rule
The value is a JSON string. Parse it on the client and pass the resulting object to session.completeMerchantValidation() unchanged; do not inspect, modify, cache, or reuse it. Apple merchant sessions are short-lived, so request one only inside onvalidatemerchant and complete validation immediately.

Response example

{
  "respCode": "20000",
  "respMsg": "Success",
  "data": "{\"epochTimestamp\":1757400000000,\"expiresAt\":1757400300000,\"merchantSessionIdentifier\":\"replace_with_merchant_session_identifier\",\"nonce\":\"replace_with_nonce\",\"merchantIdentifier\":\"replace_with_merchant_identifier\",\"domainName\":\"example.com\",\"displayName\":\"Example Store\",\"signature\":\"replace_with_signature\"}"
}
No error responses are documented for this endpoint.