# Ethoca enrollment status webhook

> Ethoca enrollment status changes, payload fields, signature verification, and acknowledgement requirements.

```yaml
openapi: 3.1.0
info:
  title: Ethoca enrollment status webhook
  version: 1.0.0
  description: Ethoca enrollment status changes, payload fields, signature
    verification, and acknowledgement requirements.
webhooks:
  ethoca.enrollment.changed:
    post:
      summary: Ethoca enrollment status webhook
      description: Ethoca enrollment status changes, payload fields, signature
        verification, and acknowledgement requirements.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                id:
                  type: number
                  description: Enrollment application ID.
                  x-onerway-constraints:
                    - kind: rule
                      text: This JSON number can exceed the JavaScript safe integer range. Use
                        lossless JSON parsing to preserve its full decimal value
                        for signature verification and acknowledgement.
                    - kind: rule
                      text: Different status changes for the same application can carry the same `id`.
                        Do not use this field alone to deduplicate
                        notifications.
                  x-onerway-signature-participation: included
                merchantNo:
                  type: number
                  description: Merchant number assigned by Onerway, identifying the merchant
                    account.
                  x-onerway-signature-participation: included
                preDisputeService:
                  type: string
                  description: Service associated with the enrollment application. Always
                    `ETHOCA_ALERT`.
                  enum:
                    - ETHOCA_ALERT
                  x-enum-descriptions:
                    ETHOCA_ALERT: Ethoca alert service.
                  x-onerway-signature-participation: included
                billDesc:
                  type: string
                  description: Merchant billing descriptor recorded in the enrollment application,
                    as shown on cardholder statements.
                  x-onerway-signature-participation: included
                resellerSubMerchantId:
                  type: string
                  description: Sub-merchant identifier assigned by the agency operator.
                  x-onerway-signature-participation: included
                fromEnrollmentStatus:
                  type: string
                  description: Enrollment status before this change.
                  enum:
                    - PENDING_SUBMISSION
                    - SUBMITTED_AND_PENDING_ENROLLMENT
                    - ENROLLING
                    - ENROLLED
                    - ENROLLMENT_FAILED
                    - SUBMITTED_AND_PENDING_DISENROLLMENT
                    - DISENROLLING
                    - DISENROLLED
                  x-enum-descriptions:
                    PENDING_SUBMISSION: Pending submission.
                    SUBMITTED_AND_PENDING_ENROLLMENT: Submitted and pending enrollment.
                    ENROLLING: Enrolling.
                    ENROLLED: Enrolled. The service is active.
                    ENROLLMENT_FAILED: Enrollment failed.
                    SUBMITTED_AND_PENDING_DISENROLLMENT: Submitted and pending disenrollment.
                    DISENROLLING: Disenrolling.
                    DISENROLLED: Disenrolled. The service has been disabled.
                  x-onerway-signature-participation: included
                enrollmentStatus:
                  type: string
                  description: Enrollment status after this change.
                  enum:
                    - PENDING_SUBMISSION
                    - SUBMITTED_AND_PENDING_ENROLLMENT
                    - ENROLLING
                    - ENROLLED
                    - ENROLLMENT_FAILED
                    - SUBMITTED_AND_PENDING_DISENROLLMENT
                    - DISENROLLING
                    - DISENROLLED
                  x-enum-descriptions:
                    PENDING_SUBMISSION: Pending submission.
                    SUBMITTED_AND_PENDING_ENROLLMENT: Submitted and pending enrollment.
                    ENROLLING: Enrolling.
                    ENROLLED: Enrolled. The service is active.
                    ENROLLMENT_FAILED: Enrollment failed.
                    SUBMITTED_AND_PENDING_DISENROLLMENT: Submitted and pending disenrollment.
                    DISENROLLING: Disenrolling.
                    DISENROLLED: Disenrolled. The service has been disabled.
                  x-onerway-constraints:
                    - kind: rule
                      text: Do not assume that every enrollment status change triggers a notification.
                  x-onerway-signature-participation: included
                notes:
                  type: string
                  description: Application or status transition note.
                  x-onerway-signature-participation: included
                comments:
                  type: string
                  description: Review comments for the enrollment application.
                  x-onerway-signature-participation: included
                createOpr:
                  type: string
                  description: Operator recorded as the creator of the enrollment application.
                  x-onerway-signature-participation: included
                createTime:
                  type: string
                  description: Enrollment application creation time.
                  x-onerway-constraints:
                    - kind: rule
                      text: Formatted as `yyyy-MM-dd HH:mm:ss`.
                  x-onerway-signature-participation: included
                updateOpr:
                  type: string
                  description: Operator recorded for the most recent update to the enrollment
                    application.
                  x-onerway-signature-participation: included
                updateTime:
                  type: string
                  description: Enrollment application update time.
                  x-onerway-constraints:
                    - kind: rule
                      text: Formatted as `yyyy-MM-dd HH:mm:ss`.
                  x-onerway-signature-participation: included
                sign:
                  type: string
                  description: Notification signature. Verify it with the `SECRET` for the current
                    environment using the [Payments signing
                    algorithm](/payments/get-started/request-signing).
                  x-onerway-constraints:
                    - kind: rule
                      text: Exclude `sign` itself when calculating the signature.
                  x-onerway-signature-participation: signature-field
            examples:
              onerway_review_approved:
                summary: Ethoca enrollment in progress
                value:
                  id: 100001
                  merchantNo: 100000
                  preDisputeService: ETHOCA_ALERT
                  billDesc: EXAMPLE STORE US
                  resellerSubMerchantId: demo_sub_merchant_001
                  fromEnrollmentStatus: SUBMITTED_AND_PENDING_ENROLLMENT
                  enrollmentStatus: ENROLLING
                  notes: Example enrollment request
                  comments: Example review approved
                  createOpr: demo_operator
                  createTime: 2026-09-01 10:00:00
                  updateOpr: demo_reviewer
                  updateTime: 2026-09-01 10:01:00
                  sign: replace_with_sha256_signature
              ethoca_enrollment_completed:
                summary: Ethoca enrollment completed
                value:
                  id: 100001
                  merchantNo: 100000
                  preDisputeService: ETHOCA_ALERT
                  billDesc: EXAMPLE STORE US
                  resellerSubMerchantId: demo_sub_merchant_001
                  fromEnrollmentStatus: ENROLLING
                  enrollmentStatus: ENROLLED
                  notes: Example enrollment request
                  comments: Example enrollment completed
                  createOpr: demo_operator
                  createTime: 2026-09-01 10:00:00
                  updateOpr: demo_reviewer
                  updateTime: 2026-09-01 10:02:00
                  sign: replace_with_sha256_signature
      responses:
        "200":
          description: "After verifying the signature and accepting the notification,
            return HTTP 200 with Content-Type: text/plain. The response body
            must contain the received id value unchanged, with no loss of
            precision. If Onerway does not receive a successful response, it
            retries at 30-minute intervals, up to 3 times."
          content:
            text/plain:
              schema:
                type: string
              examples:
                return_enrollment_id:
                  summary: Return the received application ID
                  value: "100001"
```
