# Validate Apple Pay merchant

> Obtain an Apple merchant session through Onerway to complete merchant validation for an Apple Pay session when Onerway registers your Apple Pay domains.

```yaml
openapi: 3.1.0
info:
  title: Validate Apple Pay merchant
  version: 1.0.0
  description: Obtain an Apple merchant session through Onerway to complete
    merchant validation for an Apple Pay session when Onerway registers your
    Apple Pay domains.
paths:
  /txn/apiCheckApplePay:
    post:
      summary: Validate Apple Pay merchant
      description: Obtain an Apple merchant session through Onerway to complete
        merchant validation for an Apple Pay session when Onerway registers your
        Apple Pay domains.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                merchantNo:
                  type: string
                  description: Merchant number assigned by Onerway. See
                    [Setup](/payments/get-started/setup#retrieve-your-credentials)
                    for how to obtain it.
                appId:
                  type: string
                  description: Application or site identifier assigned by Onerway. It identifies
                    the merchant application that shows the Apple Pay button.
                requestId:
                  type: string
                  description: Merchant-generated unique request identifier used for request
                    tracing.
                verifyUrl:
                  type: string
                  description: Apple merchant validation URL that Onerway calls on your behalf to
                    request the merchant session.
                  x-onerway-constraints:
                    - kind: rule
                      text: Pass through the `validationURL` from the `onvalidatemerchant` event
                        unchanged. Before forwarding it, confirm on your server
                        that the host is an Apple Pay gateway domain and reject
                        any other URL.
                website:
                  type: string
                  description: Merchant domain that shows the Apple Pay button, without the
                    protocol prefix.
                  x-onerway-constraints:
                    - kind: rule
                      text: Must be a domain that Onerway has registered and Apple has verified for
                        this merchant, and must match the domain of the page
                        that starts the Apple Pay session. It maps to Apple
                        `initiativeContext`.
                sign:
                  type: string
                  description: Request signature string. See [Request
                    signing](/payments/get-started/request-signing) for how to
                    generate it.
              required:
                - merchantNo
                - appId
                - requestId
                - verifyUrl
                - website
                - sign
            examples:
              validate-apple-pay-merchant:
                summary: Validate Apple Pay merchant
                value:
                  merchantNo: replace_with_merchant_no
                  appId: replace_with_app_id
                  requestId: req_demo_apple_pay_202609090001
                  verifyUrl: https://apple-pay-gateway.apple.com/paymentservices/startSession
                  website: example.com
                  sign: "{{SIGN}}"
      responses:
        "200":
          description: Merchant session obtained
          content:
            application/json:
              schema:
                type: object
                properties:
                  respCode:
                    type: string
                    description: Response code returned by Onerway. `20000` means the merchant
                      session was obtained; other values indicate failure. See
                      [Response codes](/payments/api-reference/response-codes).
                  respMsg:
                    type: string
                    description: Human-readable message for the response code.
                  data:
                    type:
                      - string
                      - "null"
                    description: Apple merchant session returned by Apple for this validation
                      request.
                    x-onerway-constraints:
                      - kind: rule
                        text: The value is a JSON string. Parse it on the client and pass the resulting
                          object to `session.completeMerchantValidation()`
                          unchanged; do not inspect, modify, cache, or reuse it.
                          Apple merchant sessions are short-lived, so request
                          one only inside `onvalidatemerchant` and complete
                          validation immediately.
                    x-onerway-value:
                      nullable: true
                      when:
                        en: Has a value only when `respCode=20000`.
                        zh: 仅当 `respCode=20000` 时有值。
              examples:
                merchant-session-obtained:
                  summary: Merchant session obtained
                  value:
                    respCode: "20000"
                    respMsg: Success
                    data: '{"epochTimestamp":1757400000000,"expiresAt":1757400300000,"merchantSessionIdentifier":"replace_with_merchant_session_identifier","nonce":"replace_with_nonce","merchantIdentifier":"replace_with_merchant_identifier","domainName":"example.com","displayName":"Example
                      Store","signature":"replace_with_signature"}'
```
