# Query fraud notifications

> Query fraud notifications by notification ID, fraud type, original transaction, or creation time range.

```yaml
openapi: 3.1.0
info:
  title: Query fraud notifications
  version: 1.0.0
  description: Query fraud notifications by notification ID, fraud type, original
    transaction, or creation time range.
paths:
  /fraud/list:
    post:
      summary: Query fraud notifications
      description: Query fraud notifications by notification ID, fraud type, original
        transaction, or creation time range.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                merchantNo:
                  type: string
                  description: Merchant number assigned by Onerway. See
                    [Setup](/payments/get-started/setup#retrieve-your-credentials)
                    for how to obtain it.
                notificationId:
                  type: string
                  description: Unique identifier of the fraud notification. Submit it to query one
                    fraud notification precisely.
                fraudType:
                  type: string
                  description: Fraud type used to filter fraud notifications.
                  enum:
                    - Lost
                    - Lost Fraud
                    - Stolen
                    - Stolen Fraud
                    - NRI
                    - Never Received Issue
                    - Fraud Application
                    - Fraudulent Application
                    - Counterfeit
                    - Counterfeit Card Fraud
                    - Miscellaneous
                    - Fraudulent Use of Account Number
                    - Card Not Present Fraud
                    - Account Takeover Fraud
                    - First-Party Fraud
                    - Bust-out Collusive Merchant
                    - Incorrect Processing
                    - Merchant Misrepresentation
                    - Manipulation of Account Holder
                    - Manipulation of Cardholder
                    - Modification of Payment Order
                  x-enum-descriptions:
                    Lost: Lost card.
                    Lost Fraud: Fraud involving a lost card.
                    Stolen: Stolen card.
                    Stolen Fraud: Fraud involving a stolen card.
                    NRI: Never Received Issue.
                    Never Received Issue: Fraud involving a card that was never received.
                    Fraud Application: Fraud application.
                    Fraudulent Application: Fraudulent card application.
                    Counterfeit: Counterfeit card.
                    Counterfeit Card Fraud: Counterfeit card fraud.
                    Miscellaneous: Miscellaneous fraud type.
                    Fraudulent Use of Account Number: Fraudulent use of account number.
                    Card Not Present Fraud: Card-not-present fraud.
                    Account Takeover Fraud: Account takeover fraud.
                    First-Party Fraud: First-party fraud.
                    Bust-out Collusive Merchant: Bust-out collusive merchant.
                    Incorrect Processing: Incorrect processing.
                    Merchant Misrepresentation: Merchant misrepresentation.
                    Manipulation of Account Holder: Manipulation of account holder.
                    Manipulation of Cardholder: Manipulation of cardholder.
                    Modification of Payment Order: Modification of payment order.
                originTransactionId:
                  type: string
                  description: Original Onerway transaction ID, transmitted as a JSON string and
                    used to filter fraud notifications for one source
                    transaction.
                createTimeStart:
                  type: string
                  description: Start of the notification creation time range, in `yyyy-MM-dd
                    HH:mm:ss` format.
                  x-onerway-constraints:
                    - kind: rule
                      text: When querying only by time range, submit both `createTimeStart` and
                        `createTimeEnd`. The maximum range is 90 days.
                createTimeEnd:
                  type: string
                  description: End of the notification creation time range, in `yyyy-MM-dd
                    HH:mm:ss` format. It should be later than `createTimeStart`.
                  x-onerway-constraints:
                    - kind: rule
                      text: When querying only by time range, submit both `createTimeStart` and
                        `createTimeEnd`. The maximum range is 90 days.
                current:
                  type: string
                  description: Query page number. `0` and `1` both mean the first page. The
                    response `current` value is always returned as a 1-based
                    page number.
                sign:
                  type: string
                  description: Request signature string. See [Request
                    signing](/payments/get-started/request-signing) for how to
                    generate it.
              required:
                - merchantNo
                - current
                - sign
            examples:
              query-fraud-notifications-by-time-range:
                summary: Query fraud notifications by time range
                value:
                  createTimeEnd: 2026-06-21 23:59:59
                  createTimeStart: 2026-06-01 00:00:00
                  current: "1"
                  merchantNo: replace_with_merchant_no
                  sign: "{{SIGN}}"
      responses:
        "200":
          description: Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  respCode:
                    type: string
                    description: "`20000` means the query request was processed successfully. Other
                      values are error codes. See [Response
                      codes](/payments/api-reference/response-codes)."
                  respMsg:
                    type: string
                    description: Human-readable message for the response code.
                  data:
                    type: object
                    properties:
                      content:
                        type: array
                        description: Fraud notifications matching the query conditions.
                        items:
                          type: object
                          properties:
                            merchantNo:
                              type: string
                              description: Merchant number assigned by Onerway, identifying the merchant
                                account.
                            notificationId:
                              type: string
                              description: Unique identifier of the fraud notification.
                            fraudType:
                              type: string
                              description: Fraud type.
                              enum:
                                - Lost
                                - Lost Fraud
                                - Stolen
                                - Stolen Fraud
                                - NRI
                                - Never Received Issue
                                - Fraud Application
                                - Fraudulent Application
                                - Counterfeit
                                - Counterfeit Card Fraud
                                - Miscellaneous
                                - Fraudulent Use of Account Number
                                - Card Not Present Fraud
                                - Account Takeover Fraud
                                - First-Party Fraud
                                - Bust-out Collusive Merchant
                                - Incorrect Processing
                                - Merchant Misrepresentation
                                - Manipulation of Account Holder
                                - Manipulation of Cardholder
                                - Modification of Payment Order
                              x-enum-descriptions:
                                Lost: Lost card.
                                Lost Fraud: Fraud involving a lost card.
                                Stolen: Stolen card.
                                Stolen Fraud: Fraud involving a stolen card.
                                NRI: Never Received Issue.
                                Never Received Issue: Fraud involving a card that was never received.
                                Fraud Application: Fraud application.
                                Fraudulent Application: Fraudulent card application.
                                Counterfeit: Counterfeit card.
                                Counterfeit Card Fraud: Counterfeit card fraud.
                                Miscellaneous: Miscellaneous fraud type.
                                Fraudulent Use of Account Number: Fraudulent use of account number.
                                Card Not Present Fraud: Card-not-present fraud.
                                Account Takeover Fraud: Account takeover fraud.
                                First-Party Fraud: First-party fraud.
                                Bust-out Collusive Merchant: Bust-out collusive merchant.
                                Incorrect Processing: Incorrect processing.
                                Merchant Misrepresentation: Merchant misrepresentation.
                                Manipulation of Account Holder: Manipulation of account holder.
                                Manipulation of Cardholder: Manipulation of cardholder.
                                Modification of Payment Order: Modification of payment order.
                            createTime:
                              type: string
                              description: Fraud notification creation time in `yyyy-MM-dd HH:mm:ss` format.
                            originTransactionId:
                              type: string
                              description: Original Onerway transaction ID associated with this fraud
                                notification, transmitted as a JSON string.
                            txnAmount:
                              type: string
                              description: Original transaction amount. Actual received and settled amounts
                                follow the corresponding settlement batch,
                                detail, or report.
                            cardBrand:
                              type: string
                              description: Card brand or card network used by the original transaction.
                            chargebackStatus:
                              type: string
                              description: Chargeback flag of the original transaction.
                              enum:
                                - "0"
                                - "1"
                              x-enum-descriptions:
                                "0": The original transaction has no chargeback.
                                "1": The original transaction has a chargeback.
                              x-onerway-constraints:
                                - kind: consistency
                                  text: This field is a `0` / `1` flag and is different from the chargeback
                                    lifecycle status returned by [Query
                                    chargebacks](/payments/api-reference/endpoints/query-chargebacks).
                            refundStatus:
                              type: number
                              description: Refund status of the original transaction.
                              enum:
                                - "0"
                                - "1"
                                - "2"
                              x-enum-descriptions:
                                "0": Not refunded.
                                "1": Fully refunded.
                                "2": Partially refunded.
                      current:
                        type: string
                        description: Current returned page number, using 1-based numbering.
                      size:
                        type: number
                        description: Number of records in the current page. The current page size is
                          fixed at 10 records.
                      totalPages:
                        type: number
                        description: Total number of pages based on the current page size.
                      totalElements:
                        type: number
                        description: Total number of fraud notifications matching the query conditions.
                    description: Business data object containing fraud notifications and pagination
                      information.
```
