POST
Authorization, capture, and void webhook
Use this webhook to receive
AUTH, CAPTURE, and VOID transaction notifications and associate the authorization lifecycle through paymentId.Signature coverage
Request signing guideAll payload fields are included in the signature except:
sign(legacy signature value)periodValuepaymentMethod
Webhook payload fields
notifyTypeNotification type, identifying the webhook business category.
Constraints
- Values
- Fixed to
TXNfor authorization, capture, and void notifications.
transactionIdOnerway transaction number generated for this authorization, capture, or void operation, used for tracking, queries, and idempotent processing.
Constraints
- Rule
- This value is a large-ID-style string. Preserve it as a string in JavaScript systems to avoid precision loss.
- Consistency
- In the same authorization lifecycle,
AUTH,CAPTURE, andVOIDare related but separate transaction operations, and theirtransactionIdvalues are different.
paymentIdPayment intent ID used to associate the original pre-authorization and its later capture or void operation.
Constraints
- Rule
- This value is a large-ID-style string. Preserve it as a string in JavaScript systems to avoid precision loss.
- Consistency
- Authorization, capture, and void operations under the same pre-authorization lifecycle can be associated through the same
paymentId.
txnTypeTransaction operation type, indicating whether this notification is for pre-authorization creation, capture, or void.
Allowed values
AUTH- Pre-authorization creation. Funds are authorized first; use
statusandpaymentStatusto determine the authorization state. CAPTURE- Pre-authorization capture. Captures an already authorized amount.
VOID- Pre-authorization void. Releases the authorized amount without capturing it.
merchantNoMerchant number assigned by Onerway, identifying the merchant account receiving this notification.
merchantTxnIdMerchant transaction number used for reconciliation and order association.
Constraints
- Rule
- Capture notifications may echo the merchant transaction number of the original pre-authorization order.
VOIDnotifications can return the merchant transaction number from the void request. UsetransactionIdto deduplicate operation notifications. Associate lifecycle records withpaymentId,transactionId, and transaction query results.
responseTimeTime when Onerway generated this notification result in
yyyy-MM-dd HH:mm:ss format.txnTimeTime when this authorization, capture, or void transaction occurred in
yyyy-MM-dd HH:mm:ss format.txnTimeZoneTime zone offset used by
txnTime, in ±HH:mm format.orderAmountOriginal pre-authorization order amount. In capture or void notifications, this represents the associated original authorization amount.
Constraints
- Rule
- Amount values are returned as decimal strings. Avoid binary floating-point arithmetic for money.
orderCurrencyOriginal pre-authorization order currency, as a three-letter ISO 4217 currency code.
statusCurrent processing status of this authorization, capture, or void operation.
Allowed values
S- Successful transaction.
F- Failed transaction.
P- Processing transaction.
Constraints
- Consistency
- This field represents the result of the current operation. Do not confuse it with the payment-intent-level
paymentStatus.
paymentStatusPayment-intent-level status representing the current state of the pre-authorization lifecycle.
Allowed values
A- Payment intent is authorized and waiting for a later action, such as capture.
O- Payment intent remains open and can be retried.
S- Payment intent succeeded.
Constraints
- Rule
- After a successful
AUTH, this field can returnA; whenAUTHfails but the payment intent remains retryable it can returnO; after a successfulCAPTUREit can returnS; after a successfulVOIDit returnsN(closed).
eciElectronic Commerce Indicator (ECI), indicating the 3DS authentication state related to the transaction.
cardBinCountryCard BIN country or region, as an ISO 3166-1 alpha-2 two-letter code.
reason{ respCode, respMsg }Transaction result reason object, carried as a JSON string in the notification.
periodValueInstallment period count.
signLegacy signature string kept for compatibility. It is computed with only the first enabled key and can mismatch your configured key during key rotation; verify notifications with the
X-Rh-Signature header instead.Constraints
- Rule
- Exclude
signitself from the canonical string when verifying this webhook.
paymentMethodPayment method or card brand used by this authorization, capture, or void.
channelRequestIdPayment channel or processor request identifier, used for channel-side reconciliation or troubleshooting.
paymentMethodDetails{ card }Payment method details object. Card transaction details are under the
card child object.{
"notifyType": "TXN",
"transactionId": "replace_with_authorization_transaction_id",
"paymentId": "replace_with_payment_id",
"txnType": "AUTH",
"merchantNo": "replace_with_merchant_no",
"merchantTxnId": "replace_with_merchant_transaction_id",
"responseTime": "2026-05-01 03:08:19",
"txnTime": "2026-05-01 03:05:45",
"txnTimeZone": "+08:00",
"orderAmount": "79.97",
"orderCurrency": "USD",
"status": "S",
"paymentStatus": "A",
"reason": "{\"respCode\":\"20000\",\"respMsg\":\"Success\"}",
"sign": "replace_with_sha256_signature",
"paymentMethod": "MASTERCARD",
"channelRequestId": "replace_with_channel_request_id",
"paymentMethodDetails": "{\"card\":{\"checks\":null,\"cardType\":\"MASTERCARD\",\"cardNumber\":\"512345******0008\"}}"
}Acknowledgement
Return HTTP 200 with the received
transactionId as the raw response body after the authorization, capture, or void webhook is received and accepted.replace_with_transaction_id