Onerway
POST

Ethoca enrollment status webhook

Webhook URL
Receive Ethoca enrollment status changes at the notification URL configured in the merchant portal.

Signature coverage

Request signing guide

All payload fields are included in the signature except:

  • sign(signature value)

Webhook payload fields

id
Enrollment application ID.
Constraints
Rule
This JSON number can exceed the JavaScript safe integer range. Use lossless JSON parsing to preserve its full decimal value for signature verification and acknowledgement.
Rule
Different status changes for the same application can carry the same id. Do not use this field alone to deduplicate notifications.
merchantNo
Merchant number assigned by Onerway, identifying the merchant account.
preDisputeService
Service associated with the enrollment application. Always ETHOCA_ALERT.
Allowed values
ETHOCA_ALERT
Ethoca alert service.
billDesc
Merchant billing descriptor recorded in the enrollment application, as shown on cardholder statements.
resellerSubMerchantId
Sub-merchant identifier assigned by the agency operator.
fromEnrollmentStatus
Enrollment status before this change.
Allowed values
PENDING_SUBMISSION
Pending submission.
SUBMITTED_AND_PENDING_ENROLLMENT
Submitted and pending enrollment.
ENROLLING
Enrolling.
enrollmentStatus
Enrollment status after this change.
Allowed values
PENDING_SUBMISSION
Pending submission.
SUBMITTED_AND_PENDING_ENROLLMENT
Submitted and pending enrollment.
ENROLLING
Enrolling.
Constraints
Rule
Do not assume that every enrollment status change triggers a notification.
notes
Application or status transition note.
comments
Review comments for the enrollment application.
createOpr
Operator recorded as the creator of the enrollment application.
createTime
Enrollment application creation time.
Constraints
Rule
Formatted as yyyy-MM-dd HH:mm:ss.
updateOpr
Operator recorded for the most recent update to the enrollment application.
updateTime
Enrollment application update time.
Constraints
Rule
Formatted as yyyy-MM-dd HH:mm:ss.
sign
Notification signature. Verify it with the SECRET for the current environment using the Payments signing algorithm.
Constraints
Rule
Exclude sign itself when calculating the signature.

Webhook example

{
  "id": 100001,
  "merchantNo": 100000,
  "preDisputeService": "ETHOCA_ALERT",
  "billDesc": "EXAMPLE STORE US",
  "resellerSubMerchantId": "demo_sub_merchant_001",
  "fromEnrollmentStatus": "SUBMITTED_AND_PENDING_ENROLLMENT",
  "enrollmentStatus": "ENROLLING",
  "notes": "Example enrollment request",
  "comments": "Example review approved",
  "createOpr": "demo_operator",
  "createTime": "2026-09-01 10:00:00",
  "updateOpr": "demo_reviewer",
  "updateTime": "2026-09-01 10:01:00",
  "sign": "replace_with_sha256_signature"
}

Acknowledgement

After verifying the signature and accepting the notification, return HTTP 200 with Content-Type: text/plain. The response body must contain the received id value unchanged, with no loss of precision. If Onerway does not receive a successful response, it retries at 30-minute intervals, up to 3 times.

Response body example

100001