# Apple Pay 商户验证

> 由 Onerway 代为报备 Apple Pay 域名时，通过 Onerway 向 Apple 获取 merchant session，完成 Apple Pay 会话的商户验证。

```yaml
openapi: 3.1.0
info:
  title: Apple Pay 商户验证
  version: 1.0.0
  description: 由 Onerway 代为报备 Apple Pay 域名时，通过 Onerway 向 Apple 获取 merchant
    session，完成 Apple Pay 会话的商户验证。
paths:
  /txn/apiCheckApplePay:
    post:
      summary: Apple Pay 商户验证
      description: 由 Onerway 代为报备 Apple Pay 域名时，通过 Onerway 向 Apple 获取 merchant
        session，完成 Apple Pay 会话的商户验证。
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                merchantNo:
                  type: string
                  description: Onerway 分配的商户号；获取方式参见[接入准备](/zh/payments/get-started/setup#获取凭证)。
                appId:
                  type: string
                  description: Onerway 分配给商户应用或站点的标识，用于识别展示 Apple Pay 按钮的应用。
                requestId:
                  type: string
                  description: 商户生成的请求唯一标识，用于链路追踪。
                verifyUrl:
                  type: string
                  description: Apple 商户验证 URL，Onerway 代商户向该地址请求 merchant session。
                  x-onerway-constraints:
                    - kind: rule
                      text: 原样透传 `onvalidatemerchant` 事件中的 `validationURL`；转发前在服务端确认其主机是 Apple Pay
                        网关域名，其他 URL 一律拒绝。
                website:
                  type: string
                  description: 展示 Apple Pay 按钮的商户域名，不含协议前缀。
                  x-onerway-constraints:
                    - kind: rule
                      text: 必须是 Onerway 已为该商户报备且通过 Apple 域名验证的域名，并与发起 Apple Pay 会话的页面所在域名一致；对应 Apple 的
                        `initiativeContext`。
                sign:
                  type: string
                  description: 请求签名字符串；生成方式详见[请求签名](/zh/payments/get-started/request-signing)。
              required:
                - merchantNo
                - appId
                - requestId
                - verifyUrl
                - website
                - sign
            examples:
              validate-apple-pay-merchant:
                summary: Apple Pay 商户验证
                value:
                  merchantNo: replace_with_merchant_no
                  appId: replace_with_app_id
                  requestId: req_demo_apple_pay_202609090001
                  verifyUrl: https://apple-pay-gateway.apple.com/paymentservices/startSession
                  website: example.com
                  sign: "{{SIGN}}"
      responses:
        "200":
          description: 已取得 merchant session
          content:
            application/json:
              schema:
                type: object
                properties:
                  respCode:
                    type: string
                    description: Onerway 返回的请求处理结果代码；`20000` 表示已取得 merchant
                      session，其他代码表示失败。完整码表见[响应码](/zh/payments/api-reference/response-codes)。
                  respMsg:
                    type: string
                    description: 请求处理结果的可读说明。
                  data:
                    type:
                      - string
                      - "null"
                    description: Apple 针对本次验证请求返回的 merchant session。
                    x-onerway-constraints:
                      - kind: rule
                        text: 值为 JSON 字符串。前端解析后把得到的对象原样传给
                          `session.completeMerchantValidation()`，不要检查、修改、缓存或复用；Apple
                          merchant session 有时效，只在 `onvalidatemerchant`
                          事件内请求并立即完成验证。
                    x-onerway-value:
                      nullable: true
                      when:
                        en: Has a value only when `respCode=20000`.
                        zh: 仅当 `respCode=20000` 时有值。
              examples:
                merchant-session-obtained:
                  summary: 已取得 merchant session
                  value:
                    respCode: "20000"
                    respMsg: Success
                    data: '{"epochTimestamp":1757400000000,"expiresAt":1757400300000,"merchantSessionIdentifier":"replace_with_merchant_session_identifier","nonce":"replace_with_nonce","merchantIdentifier":"replace_with_merchant_identifier","domainName":"example.com","displayName":"Example
                      Store","signature":"replace_with_signature"}'
```
