# API specifications

> Review common Issuing API request headers, response envelope, currency and timestamp rules, and response codes.

Use this page before integrating Issuing APIs. All Issuing merchant APIs use `POST` requests under the `/api/v1/merchant` base path unless an endpoint page states otherwise.

### Request headers

| Header | Type | Required | Description |
| --- | --- | --- | --- |
| `Content-Type` | String | Yes | Use `application/json;charset=UTF-8`. |
| `ApiKey` | String | Yes | Merchant identity credential assigned by Onerway for Issuing API access. |

### Response structure

| Field | Type | Description |
| --- | --- | --- |
| `respCode` | String | Response code. `20000` means the request was processed successfully. |
| `respMsg` | String | Response message. |
| `data` | Object / Array | Business data. The value can be `null` when the request fails. |

### Currency

Currency values use the ISO 4217 international standard.

### Timezone

Long timestamp fields are UTC timestamps. Query parameters use seconds unless the endpoint page states otherwise; operation, settlement, authorization, and transaction event timestamps can be returned in milliseconds.

### Response codes

When the HTTP status code is not `200`:

| HTTP status code | Description |
| --- | --- |
| `401 Unauthorized` | Invalid API credentials. |
| `403 Forbidden` | IP allowlist restriction or insufficient API permissions. |

When the HTTP status code is `200`, read the business response code:

| Code | Description |
| --- | --- |
| `20000` | Success. |
| `40000` | Parameter error. |
| `80000` | Internal service error. Contact Onerway. |
| `80001` | Cardholder not found. |
| `80002` | Cardholder email already exists. |
| `80003` | Incorrect cardholder merchant number. |
| `80004` | Merchant status is invalid. |
| `80005` | Merchant has no issuing business. |
| `80006` | Merchant account not found. |
| `80007` | Merchant balance is not enough. |
| `80008` | The recharge amount exceeds the maximum limit. |
| `80009` | The recharge amount is less than the minimum limit. |
| `80010` | Duplicate data. |
| `80011` | Cardholder card count limit. |
| `81000` | Unauthorized merchant. |
| `81001` | Business does not exist. |
| `40004` | System exception: `NoHandlerFoundException`. |
| `40005` | System exception: `HttpRequestMethodNotSupportedException`. |
| `40013` | System exception: `HttpMessageNotReadableException`. |
| `40015` | System exception: `HttpMediaTypeNotSupportedException`. |
