POST
Ethoca enrollment status webhook
Receive Ethoca enrollment status changes at the notification URL configured in the merchant portal.
Signature coverage
Request signing guideAll payload fields are included in the signature except:
sign(signature value)
Webhook payload fields
idEnrollment application ID.
Constraints
- Rule
- This JSON number can exceed the JavaScript safe integer range. Use lossless JSON parsing to preserve its full decimal value for signature verification and acknowledgement.
- Rule
- Different status changes for the same application can carry the same
id. Do not use this field alone to deduplicate notifications.
merchantNoMerchant number assigned by Onerway, identifying the merchant account.
preDisputeServiceService associated with the enrollment application. Always
ETHOCA_ALERT.Allowed values
ETHOCA_ALERT- Ethoca alert service.
billDescMerchant billing descriptor recorded in the enrollment application, as shown on cardholder statements.
resellerSubMerchantIdSub-merchant identifier assigned by the agency operator.
fromEnrollmentStatusEnrollment status before this change.
Allowed values
PENDING_SUBMISSION- Pending submission.
SUBMITTED_AND_PENDING_ENROLLMENT- Submitted and pending enrollment.
ENROLLING- Enrolling.
enrollmentStatusEnrollment status after this change.
Allowed values
PENDING_SUBMISSION- Pending submission.
SUBMITTED_AND_PENDING_ENROLLMENT- Submitted and pending enrollment.
ENROLLING- Enrolling.
Constraints
- Rule
- Do not assume that every enrollment status change triggers a notification.
notesApplication or status transition note.
commentsReview comments for the enrollment application.
createOprOperator recorded as the creator of the enrollment application.
createTimeEnrollment application creation time.
Constraints
- Rule
- Formatted as
yyyy-MM-dd HH:mm:ss.
updateOprOperator recorded for the most recent update to the enrollment application.
updateTimeEnrollment application update time.
Constraints
- Rule
- Formatted as
yyyy-MM-dd HH:mm:ss.
signNotification signature. Verify it with the
SECRET for the current environment using the Payments signing algorithm.Constraints
- Rule
- Exclude
signitself when calculating the signature.
{
"id": 100001,
"merchantNo": 100000,
"preDisputeService": "ETHOCA_ALERT",
"billDesc": "EXAMPLE STORE US",
"resellerSubMerchantId": "demo_sub_merchant_001",
"fromEnrollmentStatus": "SUBMITTED_AND_PENDING_ENROLLMENT",
"enrollmentStatus": "ENROLLING",
"notes": "Example enrollment request",
"comments": "Example review approved",
"createOpr": "demo_operator",
"createTime": "2026-09-01 10:00:00",
"updateOpr": "demo_reviewer",
"updateTime": "2026-09-01 10:01:00",
"sign": "replace_with_sha256_signature"
}Acknowledgement
After verifying the signature and accepting the notification, return HTTP 200 with Content-Type: text/plain. The response body must contain the received id value unchanged, with no loss of precision. If Onerway does not receive a successful response, it retries at 30-minute intervals, up to 3 times.
100001Saved payment method result webhook
Receive the final result notification for saved payment method (binding) transactions, covering standalone and subscription-with-binding flows.
RDR enrollment status webhook
RDR enrollment status changes, payload fields, signature verification, and acknowledgement requirements.