POST
Fraud alert webhook
Use this webhook to receive fraud alerts and link each alert back to the original transaction through
originTransactionId.Signature coverage
Request signing guideAll payload fields are included in the signature except:
sign(legacy signature value)
Webhook payload fields
notificationIdUnique identifier of the fraud alert, used for deduplication, idempotent processing, and later investigation.
Constraints
- Rule
- This value is a large-ID-style string. Preserve it as a string in JavaScript systems to avoid precision loss.
fraudTypeFraud type identified by this notification.
Allowed values
Lost- Lost card.
Lost Fraud- Fraud involving a lost card.
Stolen- Stolen card.
createTimeFraud alert creation time in
yyyy-MM-dd HH:mm:ss format.originTransactionIdOriginal Onerway transaction ID associated with this fraud alert. Use it to reconcile the source transaction through payment, chargeback, or refund queries.
Constraints
- Rule
- This value is a large-ID-style string. Preserve it as a string in JavaScript systems to avoid precision loss.
txnAmountLegacy amount converted to the settlement currency.
txnCurrencyLegacy settlement currency field.
cardBrandPayment method or card brand used by the original transaction.
chargebackStatusChargeback flag of the original transaction.
Allowed values
0- The original transaction has no chargeback.
1- The original transaction has a chargeback.
Constraints
- Consistency
- This field is a
0/1flag and is different from the chargeback lifecycle status returned by Query chargebacks.
refundStatusRefund status of the original transaction.
Allowed values
0- Not refunded.
1- Fully refunded.
2- Partially refunded.
merchantNoMerchant number assigned by Onerway, identifying the merchant account receiving this fraud alert.
merchantTxnIdMerchant-side transaction reference for the original transaction, returned consistently for reconciliation, deduplication, and order association.
signLegacy signature string kept for compatibility. It is computed with only the first enabled key and can mismatch your configured key during key rotation; verify notifications with the
X-Rh-Signature header instead.Constraints
- Rule
- Exclude
signitself from the canonical string when verifying this webhook.
{
"notificationId": "replace_with_fraud_notification_id",
"fraudType": "Fraudulent Use of Account Number",
"createTime": "2025-08-04 10:54:04",
"originTransactionId": "replace_with_origin_transaction_id",
"txnAmount": "16.41",
"txnCurrency": "USD",
"cardBrand": "VISA",
"chargebackStatus": "0",
"refundStatus": "0",
"merchantNo": "replace_with_merchant_no",
"merchantTxnId": "replace_with_merchant_transaction_id",
"sign": "replace_with_sha256_signature"
}Acknowledgement
Return HTTP 200 with
20000 in the response body after the fraud alert is received and accepted.20000Check Google Pay PAN_ONLY token
Check whether a Google Pay token is PAN_ONLY and needs a CVC before creating the direct transaction when you collect the CVC yourself.
Ethoca alert webhook
Receive Ethoca alert payloads with the alert identifier, original transaction, chargeback details, and handling status.