# 检查 Google Pay PAN_ONLY token

> 商户自行采集 CVC 时，在创建直连交易前检查 Google Pay token 是否为 PAN_ONLY、是否需要补收 CVC。

```yaml
openapi: 3.1.0
info:
  title: 检查 Google Pay PAN_ONLY token
  version: 1.0.0
  description: 商户自行采集 CVC 时，在创建直连交易前检查 Google Pay token 是否为 PAN_ONLY、是否需要补收 CVC。
paths:
  /txn/apiCheckGooglePay:
    post:
      summary: 检查 Google Pay PAN_ONLY token
      description: 商户自行采集 CVC 时，在创建直连交易前检查 Google Pay token 是否为 PAN_ONLY、是否需要补收 CVC。
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                merchantNo:
                  type: string
                  description: Onerway 分配的商户号；获取方式参见[接入准备](/zh/payments/get-started/setup#获取凭证)。
                appId:
                  type: string
                  description: Onerway 分配给商户应用或站点的标识，用于识别展示 Google Pay 按钮的应用。
                merchantTxnId:
                  type: string
                  description: 本次 Google Pay token 将用于支付的订单的商户交易 ID。
                  x-onerway-constraints:
                    - kind: consistency
                      text: 与随后调用[创建直连交易](/zh/payments/api-reference/endpoints/direct-create-transaction)时的
                        `merchantTxnId` 使用同一个值。
                gatewayName:
                  type: string
                  description: Google Pay
                    网关标识；取[查询可用支付方式](/zh/payments/api-reference/endpoints/list-available-payment-methods)返回的
                    `GooglePay` 记录中的 `gatewayName`。
                tokenInfoJson:
                  type: string
                  description: 待检查的 Google Pay token，结构与创建直连交易的 `tokenInfo` 相同。
                  contentMediaType: application/json
                  contentSchema:
                    type: object
                    properties:
                      provider:
                        type: string
                        description: 钱包 token 来源类型。
                        enum:
                          - GooglePay
                        x-enum-descriptions:
                          GooglePay: Google Pay 钱包。
                      tokenId:
                        type: string
                        description: Google Pay JS SDK 在 `paymentMethodData.tokenizationData.token`
                          返回的加密支付 token，需原样透传。
                    required:
                      - provider
                      - tokenId
                  x-onerway-constraints:
                    - kind: consistency
                      text: 随后创建直连交易时在 `tokenInfo` 中提交同一个加密 token；检查与下单之间不要向 Google Pay 重新获取 token。
                  x-onerway-format: json_string
                sign:
                  type: string
                  description: 请求签名字符串；生成方式详见[请求签名](/zh/payments/get-started/request-signing)。
              required:
                - merchantNo
                - appId
                - merchantTxnId
                - gatewayName
                - tokenInfoJson
                - sign
            examples:
              check-google-pay-pan-only:
                summary: 检查 Google Pay PAN_ONLY token
                value:
                  merchantNo: replace_with_merchant_no
                  appId: replace_with_app_id
                  merchantTxnId: txn_demo_google_pay_202609090001
                  gatewayName: replace_with_gateway_name
                  tokenInfoJson: '{"provider":"GooglePay","tokenId":"{{GOOGLE-PAY-TOKEN}}"}'
                  sign: "{{SIGN}}"
      responses:
        "200":
          description: PAN_ONLY token，需采集 CVC
          content:
            application/json:
              schema:
                type: object
                properties:
                  respCode:
                    type: string
                    description: Onerway 返回的请求处理结果代码；`20000`
                      表示已完成检查，其他代码表示失败。完整码表见[响应码](/zh/payments/api-reference/response-codes)。
                  respMsg:
                    type: string
                    description: 请求处理结果的可读说明。
                  data:
                    type:
                      - object
                      - "null"
                    properties:
                      cardNum:
                        type: string
                        description: 从 token 中提取的脱敏卡号，仅保留前 6 位与后 4 位，可用于商户 CVC 采集页面的展示。
                      checkResult:
                        type: boolean
                        description: token 的认证方式：`true` 为 `CRYPTOGRAM_3DS`，已含 3DS 凭证；`false` 为
                          `PAN_ONLY`，需补采 CVC 后才能扣款。
                        x-onerway-constraints:
                          - kind: rule
                            text: "`checkResult=false` 时，可自行向用户采集 CVC，创建直连交易时通过 `cardInfo.cvv` 与同一个
                              `tokenInfo` 一起提交；也可只提交同一个 `tokenInfo`，不传
                              `cardInfo.cvv`，此时交易响应返回 `data.status=R` 和
                              `data.redirectUrl`。商户需引导用户跳转至 `data.redirectUrl`，在
                              Onerway 托管页面输入 CVC。"
                          - kind: rule
                            text: "`checkResult=true` 时，通过同一个 `tokenInfo` 创建直连交易，无需提交 `cardInfo`。"
                    description: 提交的 Google Pay token 的检查结果。
                    x-onerway-value:
                      nullable: true
                      when:
                        en: Has a value only when `respCode=20000`.
                        zh: 仅当 `respCode=20000` 时有值。
              examples:
                pan-only:
                  summary: PAN_ONLY token，需采集 CVC
                  value:
                    respCode: "20000"
                    respMsg: Success
                    data:
                      cardNum: 411111******1111
                      checkResult: false
                cryptogram-3ds:
                  summary: CRYPTOGRAM_3DS token，无需 CVC
                  value:
                    respCode: "20000"
                    respMsg: Success
                    data:
                      cardNum: 411111******1111
                      checkResult: true
```
