Callback penerimaan

The merchant server is called only after a pay-in completes successfully; the callback status is always completed.

Only final payment results are sent. Any HTTP 2xx response stops delivery immediately. After the first failure, the platform retries in 1 minute; after another failure, it makes a final retry in 5 minutes, for up to 3 attempts total. Callback business times use Beijing time in YYYY/MM/DD HH:mm:ss format.

POSTnotifyUrl dari permintaan pembuatan pesanan pembayaran body

Header

KolomTipeWajibDeskripsi
content-typeapplication/jsonYaSelalu aplikasi/json.
x-callback-timestampstringYaPanggilan balik timestamp dalam milidetik.
x-callback-noncestringYaPanggilan balik nonce.
x-callback-signaturestringYaHMAC-SHA256(apiKey, timestamp + "." + nonce + "." + rawBody)。
x-callback-signature-algorithmstringYaSelalu HMAC-SHA256.
x-callback-signature-versionstringYaSelalu v1.

Parameter

KolomTipeWajibDeskripsi
merchantUidstringYaMerchant UID.
orderNostringYaNomor pesanan platform.
merchantOrderNostring | nullYaNomor pesanan pedagang.
bindKeystring | nullYaKunci pengikatan untuk isi ulang anggota. Biasanya kosong untuk pesanan pembayaran bersama.
expectedAmountstringYaJumlah pesanan.
paidAmountstringYaJumlah pembayaran sebenarnya.
chainCodestringYaKode rantai.
tokenSymbolstringYaSimbol token.
txHashstringYaHash transaksi on-chain.
fromAddressstring | nullYaAlamat pengirim.
statusstringYaFinal successful pay-in status; always completed.

Contoh permintaan

{
  "merchantUid": "880001",
  "orderNo": "PI1776193200123ABCD1234",
  "merchantOrderNo": "M202604150001",
  "bindKey": "USER_90001",
  "expectedAmount": "100.000000",
  "paidAmount": "100.000000",
  "chainCode": "TRON",
  "tokenSymbol": "USDT",
  "txHash": "f7f17891f52c35d0c93170f0d12bb347ac16ab34853b4bc8dcf7fd0a8c9aa321",
  "fromAddress": "TS7b7iD8G2PaPqK1TqSmLJ9nrrYH4oKX1S",
  "status": "completed"
}

Kolom respons

KolomTipeWajibDeskripsi
HTTP Status200-299YaSetiap respons 2xx dianggap sukses.
Response Bodystring | jsonTIDAKRespons body dapat disesuaikan.

Contoh respons

HTTP/1.1 200 OK
Content-Type: application/json

{
  "ok": true
}

Contoh kode

Node.js Contoh Verifikasi Panggilan Balik
import express from 'express';
import { verifyCallbackSignature } from 'uugate-openapi-sdk';

const app = express();
app.use(express.json({
  verify: (req, _res, buffer) => {
    req.rawBody = buffer.toString('utf8');
  },
}));

app.post('/merchant/callback', (req, res) => {
  const valid = verifyCallbackSignature({
    apiKey: process.env.UUGATE_API_KEY,
    timestamp: req.header('x-callback-timestamp'),
    nonce: req.header('x-callback-nonce'),
    signature: req.header('x-callback-signature'),
    rawBody: req.rawBody || '',
  });

  if (!valid) {
    return res.status(401).json({ ok: false });
  }

  return res.status(200).json({ ok: true });
});

Catatan

  • Verifikasi panggilan balik menggunakan apiKey, bukan header permintaan tanda tangan x OpenAPI.
  • Setelah verifikasi, cocokkan merchant, pesanan, aset, jaringan, dan jumlah. Simpan pembayaran serta hasil secara transaksional dan idempoten berdasarkan nomor platform sebelum merespons 2xx; notifikasi berulang tidak boleh menggandakan kredit atau pengiriman.
  • Untuk isi ulang anggota, gunakan bindKey secara langsung sebagai pengenal anggota sehingga Anda tidak memerlukan tabel pemetaan orderNo-ke-anggota tambahan.