Onerway
POST

Saved payment method result webhook

Webhook URL
Use this webhook to receive the authoritative server-side result of txnType=BIND_CARD saved payment method transactions; store and use the notified tokenId only when status is S.

Signature coverage

Request signing guide

All payload fields are included in the signature except:

Webhook payload fields

notifyType
Notification type, identifying the webhook business category.
Constraints
Values
Fixed to TXN for saved payment method result notifications.
transactionId
Onerway transaction number generated for this binding transaction, used for tracking, queries, and idempotent processing.
Constraints
Rule
This value is a large-ID-style string. Preserve it as a string in JavaScript systems to avoid precision loss.
Consistency
Standalone card tokenization: equals transactionId in the synchronous Create card token response; use it to match that response with this final result. Card subscriptions (bindCard=true) and local payment method subscriptions: differs from transactionId in the Subscription payment webhook, so it cannot match the two notifications. Process every notification idempotently by its own transactionId.
paymentId
Payment intent ID of the binding transaction.
Constraints
Consistency
Card subscriptions (bindCard=true): differs from paymentId in the Subscription payment webhook. Local payment method subscriptions: same as paymentId in the Subscription payment webhook. Do not apply either relation to other payment methods; match the two notifications by the token relation described under tokenId.
txnType
Transaction operation type represented by this notification.
Allowed values
BIND_CARD
Saved payment method (binding) transaction.
Constraints
Values
Always BIND_CARD. The subscription payment itself is reported separately by the Subscription payment webhook. Card subscriptions (bindCard=true): Onerway generates the Subscription payment webhook first and sends this notification after the payment succeeds. Local payment method subscriptions: Onerway sends this notification first for the subscription authorization, then the Subscription payment webhook for the first charge. The order in which your server receives them is not guaranteed.
merchantNo
Merchant number assigned by Onerway, identifying the merchant account receiving this notification.
merchantTxnId
Merchant transaction number of the binding transaction.
Constraints
Rule
Standalone card tokenization: generated by Onerway; it is not the transaction number from your request. Card subscriptions (bindCard=true): differs from merchantTxnId in the Subscription payment webhook; do not use it to match the two notifications. Local payment method subscriptions: same as merchantTxnId in the Subscription payment webhook.
responseTime
Time when Onerway generated this notification result in yyyy-MM-dd HH:mm:ss format.
txnTime
Time when the binding transaction occurred or reached this state in yyyy-MM-dd HH:mm:ss format.
txnTimeZone
Time zone offset used by txnTime, in ±HH:mm format.
orderAmount
Binding transaction amount.
Constraints
Rule
Amount values are returned as decimal strings. Avoid binary floating-point arithmetic for money.
Values
Binding transactions are zero-amount; this field returns 0.00.
orderCurrency
Binding transaction currency following the request or transaction currency, as a three-letter ISO 4217 currency code.
status
Result of the saved payment method transaction.
Allowed values
S
The payment method was saved successfully.
F
Saving the payment method failed or was declined.
Constraints
Rule
Use this field as the final state of the save-payment-method attempt: store and use tokenId only when status is S.
Rule
When the subscription authorization of a local payment method subscription fails, the subscription ends: no Subscription payment webhook follows, and subscriptionStatus in this notification is canceled.
tokenId
Token produced by this transaction. Its type depends on the flow; see the constraints.
Constraints
Rule
Store and use this token only when status is S. A failed notification can still carry a tokenId; do not use it.
Consistency
Standalone card tokenization and card subscriptions (bindCard=true): this is a saved payment method token for later subProductType=TOKEN payments through Create direct transaction. For card subscriptions, cardTokenId in the Subscription payment webhook has the same value, while tokenId there is a different subscription token.
Consistency
Local payment method subscriptions: this is a subscription token with the same value as tokenId in the Subscription payment webhook. Use it only for subscription operations; it cannot be used for subProductType=TOKEN payments, and the Subscription payment webhook does not return cardTokenId.
tokenExpireTime
Expiry time of the saved token in yyyy-MM-dd HH:mm:ss format.
cardBinCountry
Card BIN country or region, as an ISO 3166-1 alpha-2 two-letter code.
Binding result reason object, carried as a JSON string in the notification.
sign
Legacy signature string kept for compatibility. It is computed with only the first enabled key and can mismatch your configured key during key rotation; verify notifications with the X-Rh-Signature header instead.
Constraints
Rule
Exclude sign itself from the canonical string when verifying this webhook.
paymentMethod
Payment method or card brand that was saved. Besides cards, this webhook also reports the subscription authorization of local payment method subscriptions.
Example:
walletTypeName
Wallet type name.
channelRequestId
Payment channel or processor request identifier, used for channel-side reconciliation or troubleshooting.
Constraints
Consistency
Card subscriptions (bindCard=true) and local payment method subscriptions: differs from channelRequestId in the Subscription payment webhook, so it cannot match the two notifications.
paymentStatus
Payment intent status of the binding transaction.
contractId
Subscription contract ID.
Constraints
Rule
This value is a large-ID-style string. Preserve it as a string in JavaScript systems to avoid precision loss.
Consistency
Local payment method subscriptions: same as contractId in the Subscription payment webhook. Card subscriptions (bindCard=true) do not return it in this webhook, so it cannot serve as a universal key for matching the two notifications.
subscriptionStatus
Status of the associated subscription contract.
Example:
dataStatus
Data status of the associated subscription contract record.
Allowed values
0
Pending activation.
1
Active.
2
Inactive.
Product list submitted in txnOrderMsg.products of the subscription request, returned as a JSON string.
scenarios
Subscription scenario of this authorization. See the scenarios field of the Subscription payment webhook for the values.
Example:
Payment method details object. Card binding details are under the card child object.

Webhook example

{
  "notifyType": "TXN",
  "transactionId": "replace_with_bind_transaction_id",
  "paymentId": "replace_with_bind_payment_id",
  "txnType": "BIND_CARD",
  "merchantNo": "replace_with_merchant_no",
  "merchantTxnId": "replace_with_onerway_generated_bind_reference",
  "responseTime": "2026-09-02 08:19:04",
  "txnTime": "2026-09-02 08:19:02",
  "txnTimeZone": "+08:00",
  "orderAmount": "0.00",
  "orderCurrency": "USD",
  "status": "S",
  "tokenId": "replace_with_saved_payment_method_token",
  "tokenExpireTime": "2099-12-31 23:59:59",
  "cardBinCountry": "US",
  "reason": "{\"respCode\":\"20000\",\"respMsg\":\"Success\"}",
  "sign": "replace_with_sha256_signature",
  "paymentMethod": "VISA",
  "channelRequestId": "replace_with_channel_request_id",
  "paymentMethodDetails": "{\"card\":{\"checks\":null,\"holderName\":\"Example Cardholder\",\"year\":\"2028\",\"month\":\"05\",\"cardType\":null,\"productCategory\":null,\"issuer\":\"Example Issuer\",\"cardBinCountry\":\"US\",\"authorizationCode\":null,\"cardNumber\":\"400000******0002\"}}"
}

Acknowledgement

Return HTTP 200 with the received transactionId as the raw response body after the saved payment method webhook is received and accepted.

Response body example

replace_with_bind_transaction_id