Onerway
POST

Fraud alert webhook

Webhook URL
Use this webhook to receive fraud alerts and link each alert back to the original transaction through originTransactionId.

Signature coverage

Request signing guide

All payload fields are included in the signature except:

  • sign(legacy signature value)

Webhook payload fields

notificationId
Unique identifier of the fraud alert, used for deduplication, idempotent processing, and later investigation.
Constraints
Rule
This value is a large-ID-style string. Preserve it as a string in JavaScript systems to avoid precision loss.
fraudType
Fraud type identified by this notification.
Allowed values
Lost
Lost card.
Lost Fraud
Fraud involving a lost card.
Stolen
Stolen card.
createTime
Fraud alert creation time in yyyy-MM-dd HH:mm:ss format.
originTransactionId
Original Onerway transaction ID associated with this fraud alert. Use it to reconcile the source transaction through payment, chargeback, or refund queries.
Constraints
Rule
This value is a large-ID-style string. Preserve it as a string in JavaScript systems to avoid precision loss.
txnAmount
Legacy amount converted to the settlement currency.
txnCurrency
Legacy settlement currency field.
cardBrand
Payment method or card brand used by the original transaction.
chargebackStatus
Chargeback flag of the original transaction.
Allowed values
0
The original transaction has no chargeback.
1
The original transaction has a chargeback.
Constraints
Consistency
This field is a 0 / 1 flag and is different from the chargeback lifecycle status returned by Query chargebacks.
refundStatus
Refund status of the original transaction.
Allowed values
0
Not refunded.
1
Fully refunded.
2
Partially refunded.
merchantNo
Merchant number assigned by Onerway, identifying the merchant account receiving this fraud alert.
merchantTxnId
Merchant-side transaction reference for the original transaction, returned consistently for reconciliation, deduplication, and order association.
sign
Legacy signature string kept for compatibility. It is computed with only the first enabled key and can mismatch your configured key during key rotation; verify notifications with the X-Rh-Signature header instead.
Constraints
Rule
Exclude sign itself from the canonical string when verifying this webhook.

Webhook example

{
  "notificationId": "replace_with_fraud_notification_id",
  "fraudType": "Fraudulent Use of Account Number",
  "createTime": "2025-08-04 10:54:04",
  "originTransactionId": "replace_with_origin_transaction_id",
  "txnAmount": "16.41",
  "txnCurrency": "USD",
  "cardBrand": "VISA",
  "chargebackStatus": "0",
  "refundStatus": "0",
  "merchantNo": "replace_with_merchant_no",
  "merchantTxnId": "replace_with_merchant_transaction_id",
  "sign": "replace_with_sha256_signature"
}

Acknowledgement

Return HTTP 200 with 20000 in the response body after the fraud alert is received and accepted.

Response body example

20000