# Create card token

> Create a card token in a PCI DSS compliant integration and receive the final tokenization result through notifyUrl.

```yaml
openapi: 3.1.0
info:
  title: Create card token
  version: 1.0.0
  description: Create a card token in a PCI DSS compliant integration and receive
    the final tokenization result through notifyUrl.
paths:
  /v1/txn/bindCard:
    post:
      summary: Create card token
      description: Create a card token in a PCI DSS compliant integration and receive
        the final tokenization result through notifyUrl.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                appId:
                  type: string
                  description: Store ID generated when the merchant is onboarded with Onerway.
                cardInfo:
                  type: string
                  description: Card payment information collected directly by the merchant backend
                    in a PCI DSS compliant environment. Do not store sensitive
                    authentication data after authorization.
                  contentMediaType: application/json
                  contentSchema:
                    type: object
                    properties:
                      holderName:
                        type: string
                        description: Cardholder name collected by the merchant in its PCI DSS compliant
                          environment.
                      cardNumber:
                        type: string
                        description: Full card number collected by the merchant in its PCI DSS compliant
                          environment.
                        x-onerway-constraints:
                          - kind: rule
                            text: Submit digits only, without spaces. Validate the number with the Luhn
                              algorithm before sending.
                      month:
                        type: string
                        description: Card expiration month.
                        x-onerway-constraints:
                          - kind: values
                            text: Use two digits from `01` to `12`.
                      year:
                        type: string
                        description: Card expiration year.
                        x-onerway-constraints:
                          - kind: rule
                            text: Use four digits and submit a future expiration date.
                      cvv:
                        type: string
                        description: Card security code collected for authorization.
                        x-onerway-constraints:
                          - kind: rule
                            text: Visa, Mastercard, and Discover usually use 3 digits; American Express uses
                              4 digits. Do not store CVV after authorization.
                    required:
                      - holderName
                      - cardNumber
                      - month
                      - year
                      - cvv
                  x-onerway-format: json_string
                country:
                  type: string
                  description: Customer country in [ISO 3166-1
                    alpha-2](https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2)
                    format.
                email:
                  type: string
                  description: Customer email address, used for transaction confirmation and
                    dispute handling.
                merchantCustId:
                  type: string
                  description: Unique customer identifier in the merchant system. The saved card
                    token is associated with this customer.
                merchantNo:
                  type: string
                  description: Merchant number assigned by Onerway. See
                    [Setup](/payments/get-started/setup#retrieve-your-credentials)
                    for how to obtain it.
                notifyUrl:
                  type: string
                  description: HTTPS endpoint that receives the final card-token creation result
                    callback, including the card token and masked card details.
                    The callback contract is the [Saved payment method result
                    webhook](/payments/api-reference/webhooks/payment-method-result).
                returnUrl:
                  type: string
                  description: HTTPS browser return URL used when a card-binding 3DS challenge
                    requires redirect handling.
                sign:
                  type: string
                  description: Request signature string. See [Request
                    signing](/payments/get-started/request-signing) for how to
                    generate it.
                transactionIp:
                  type: string
                  description: Cardholder transaction IP collected by the merchant. Submit the
                    end-user IP, not the merchant server IP.
              required:
                - appId
                - cardInfo
                - country
                - email
                - merchantCustId
                - merchantNo
                - notifyUrl
                - returnUrl
                - sign
                - transactionIp
            examples:
              card-tokenization:
                summary: Create card token
                value:
                  appId: replace_with_app_id
                  cardInfo: '{"holderName":"replace_with_cardholder_name","cardNumber":"{{CARD-NUMBER}}","month":"12","year":"2030","cvv":"{{CVV}}"}'
                  country: US
                  email: customer@example.com
                  merchantCustId: cust_demo_tokenization_202606150001
                  merchantNo: replace_with_merchant_no
                  notifyUrl: https://developers.onerway.com/example-card-token-notify
                  returnUrl: https://developers.onerway.com/example-card-token-return
                  sign: "{{SIGN}}"
                  transactionIp: 192.0.2.10
      responses:
        "200":
          description: Tokenization accepted as successful
          content:
            application/json:
              schema:
                type: object
                properties:
                  respCode:
                    type: string
                    description: Response code; `20000` means the request was processed
                      successfully, other values are error codes. See [Response
                      codes](/payments/api-reference/response-codes).
                  respMsg:
                    type: string
                    description: Human-readable message for the response code.
                  data:
                    type: object
                    properties:
                      transactionId:
                        type: string
                        description: Onerway transaction ID generated for this tokenization request.
                      tokenId:
                        type:
                          - string
                          - "null"
                        description: Card token used for later token payments through [Create direct
                          transaction](/payments/api-reference/endpoints/direct-create-transaction)
                          with `subProductType=TOKEN`. Store it only after
                          tokenization succeeds.
                        x-onerway-value:
                          nullable: true
                          empty: true
                          when:
                            en: Has a value when `data.status=S` and card tokenization has succeeded.
                            zh: 当 `data.status=S` 且卡 token 生成成功后才有值。
                      status:
                        type: string
                        description: "`respCode=20000` only means the request was processed
                          successfully. Read this synchronous processing status
                          and receive the final tokenization result through
                          `notifyUrl`."
                        enum:
                          - S
                          - R
                          - F
                        x-enum-descriptions:
                          S: Tokenization succeeded. Store `tokenId` only after confirming the
                            tokenization result.
                          R: 3DS verification is required. Redirect the cardholder to `redirectUrl` to
                            continue verification.
                          F: Tokenization failed. Handle the failure according to the response code and
                            business message.
                      redirectUrl:
                        type:
                          - string
                          - "null"
                        description: 3DS verification URL. Redirect the cardholder to this URL to
                          continue verification.
                        x-onerway-value:
                          nullable: true
                          empty: true
                          when:
                            en: Has a value when `data.status=R` and 3DS verification is required.
                            zh: 当 `data.status=R` 且需要 3DS 验证时才有值。
                      sign:
                        type: string
                        description: Response signature string. Onerway currently does not recommend
                          response signature verification by merchants.
                    description: Business data object carrying synchronous processing status and
                      next-action fields for this tokenization request.
              examples:
                tokenized:
                  summary: Tokenization accepted as successful
                  value:
                    respCode: "20000"
                    respMsg: Success
                    data:
                      transactionId: txn_demo_tokenization_202606150001
                      tokenId: example_token_id
                      status: S
                      redirectUrl: null
                      sign: "{{SIGN}}"
                redirect-required:
                  summary: 3DS redirect required
                  value:
                    respCode: "20000"
                    respMsg: Success
                    data:
                      transactionId: txn_demo_tokenization_202606150002
                      tokenId: null
                      status: R
                      redirectUrl: https://developers.onerway.com/example-card-token-3ds
                      sign: "{{SIGN}}"
```
