Onerway
POST

Authorization, capture, and void webhook

Webhook URL
Use this webhook to receive AUTH, CAPTURE, and VOID transaction notifications and associate the authorization lifecycle through paymentId.

Signature coverage

Request signing guide

All payload fields are included in the signature except:

Webhook payload fields

notifyType
Notification type, identifying the webhook business category.
Constraints
Values
Fixed to TXN for authorization, capture, and void notifications.
transactionId
Onerway transaction number generated for this authorization, capture, or void operation, used for tracking, queries, and idempotent processing.
Constraints
Rule
This value is a large-ID-style string. Preserve it as a string in JavaScript systems to avoid precision loss.
Consistency
In the same authorization lifecycle, AUTH, CAPTURE, and VOID are related but separate transaction operations, and their transactionId values are different.
paymentId
Payment intent ID used to associate the original pre-authorization and its later capture or void operation.
Constraints
Rule
This value is a large-ID-style string. Preserve it as a string in JavaScript systems to avoid precision loss.
Consistency
Authorization, capture, and void operations under the same pre-authorization lifecycle can be associated through the same paymentId.
txnType
Transaction operation type, indicating whether this notification is for pre-authorization creation, capture, or void.
Allowed values
AUTH
Pre-authorization creation. Funds are authorized first; use status and paymentStatus to determine the authorization state.
CAPTURE
Pre-authorization capture. Captures an already authorized amount.
VOID
Pre-authorization void. Releases the authorized amount without capturing it.
merchantNo
Merchant number assigned by Onerway, identifying the merchant account receiving this notification.
merchantTxnId
Merchant transaction number used for reconciliation and order association.
Constraints
Rule
Capture notifications may echo the merchant transaction number of the original pre-authorization order. VOID notifications can return the merchant transaction number from the void request. Use transactionId to deduplicate operation notifications. Associate lifecycle records with paymentId, transactionId, and transaction query results.
responseTime
Time when Onerway generated this notification result in yyyy-MM-dd HH:mm:ss format.
txnTime
Time when this authorization, capture, or void transaction occurred in yyyy-MM-dd HH:mm:ss format.
txnTimeZone
Time zone offset used by txnTime, in ±HH:mm format.
orderAmount
Original pre-authorization order amount. In capture or void notifications, this represents the associated original authorization amount.
Constraints
Rule
Amount values are returned as decimal strings. Avoid binary floating-point arithmetic for money.
orderCurrency
Original pre-authorization order currency, as a three-letter ISO 4217 currency code.
status
Current processing status of this authorization, capture, or void operation.
Allowed values
S
Successful transaction.
F
Failed transaction.
P
Processing transaction.
Constraints
Consistency
This field represents the result of the current operation. Do not confuse it with the payment-intent-level paymentStatus.
paymentStatus
Payment-intent-level status representing the current state of the pre-authorization lifecycle.
Allowed values
A
Payment intent is authorized and waiting for a later action, such as capture.
O
Payment intent remains open and can be retried.
S
Payment intent succeeded.
Constraints
Rule
After a successful AUTH, this field can return A; when AUTH fails but the payment intent remains retryable it can return O; after a successful CAPTURE it can return S; after a successful VOID it returns N (closed).
eci
Electronic Commerce Indicator (ECI), indicating the 3DS authentication state related to the transaction.
cardBinCountry
Card BIN country or region, as an ISO 3166-1 alpha-2 two-letter code.
Transaction result reason object, carried as a JSON string in the notification.
periodValue
Installment period count.
sign
Legacy signature string kept for compatibility. It is computed with only the first enabled key and can mismatch your configured key during key rotation; verify notifications with the X-Rh-Signature header instead.
Constraints
Rule
Exclude sign itself from the canonical string when verifying this webhook.
paymentMethod
Payment method or card brand used by this authorization, capture, or void.
channelRequestId
Payment channel or processor request identifier, used for channel-side reconciliation or troubleshooting.
Payment method details object. Card transaction details are under the card child object.

Webhook example

{
  "notifyType": "TXN",
  "transactionId": "replace_with_authorization_transaction_id",
  "paymentId": "replace_with_payment_id",
  "txnType": "AUTH",
  "merchantNo": "replace_with_merchant_no",
  "merchantTxnId": "replace_with_merchant_transaction_id",
  "responseTime": "2026-05-01 03:08:19",
  "txnTime": "2026-05-01 03:05:45",
  "txnTimeZone": "+08:00",
  "orderAmount": "79.97",
  "orderCurrency": "USD",
  "status": "S",
  "paymentStatus": "A",
  "reason": "{\"respCode\":\"20000\",\"respMsg\":\"Success\"}",
  "sign": "replace_with_sha256_signature",
  "paymentMethod": "MASTERCARD",
  "channelRequestId": "replace_with_channel_request_id",
  "paymentMethodDetails": "{\"card\":{\"checks\":null,\"cardType\":\"MASTERCARD\",\"cardNumber\":\"512345******0008\"}}"
}

Acknowledgement

Return HTTP 200 with the received transactionId as the raw response body after the authorization, capture, or void webhook is received and accepted.

Response body example

replace_with_transaction_id