Notification - API Convenience Store
About API Convenience Store Notification
NICEPAY provides push notifications via dbProcessUrl Merchant. The Merchant needs to reassure there is no Blacklist NICEPAY IP and should Whitelist NICEPAY IP to get the push notification only from NICEPAY's server.
Request Method | POST |
|---|---|
Merchant Token | SHA256 ( iMid+ tXid + amt+ merchantKey) |
IP | IP Public environtment Production: 103.20.51.34 103.20.51.33 18.98.96.50 IP Public environtment Dev: 103.20.51.39 103.20.51.40 18.98.96.54 |
User-Agent | User-Agent: Jakarta Commons-HttpClient/3.1 |
Notification Parameter Convenience Store
When your dbProcessUrl received a notification, NICEPAY strongly recommend Merchant to verify the notification using the Status Inquiry - API Convenience Store.
Parameter | Type | Size | Description | Example / Notes |
|---|---|---|---|---|
tXid | N | 30 | Transaction ID | TNICECV03103202212141459041632 |
merchantToken | AN | 255 | Merchant Token | 8b5565e793731a1a1c8817c9e42bcbbdc3f5fb6a2785a6e0b19a2d5e3a41a51b |
referenceNo | ANS | 40 | Merchant Order Number | ord0123456 |
mitraCd | A | 4 | ALMA | |
payMethod | N | 2 | 04 | |
payNo | N | 20 | Payment Number | 504100002539 |
payValidTm | N | 6 | CVS Expiry Time (HH24MISS) | null |
payValidDt | N | 8 | CVS Expiry Date (YYYYMMDD) (CVS) | null |
amt | N | 12 | Payment Amount | 5000 |
clientUserKey Mandatory if tokenize | AN | 100 | User key, must be unique for each Customer | 1134431 |
userToken | ANS | | User Token | 12345eea9-6234-6789-12r3-123re3456tt5 |
tokenizeUser | N | 1 | Transaction Tokenize Type | 1 |
transDt | N | 8 | Transaction Date | 20221214 |
transTm | N | 6 | Transaction Time | 150229 |
currency | A | 3 | Currency | IDR |
goodsNm | AN | 100 | Goods Name | Testing |
billingNm | A | 100 | Billing Name | John-Doe |
matchCl | N | 1 | Payment Flag: Notification Match Amount Indicator | 1 |
status | A | 1 | 0 | |
instmntType | N | 2 | 1 | |
instmntMon | N | 2 | Installment Month | 1 |
The Merchant Token received by the Notification Endpoint must compare internally to prevent fake/invalid notifications.
💡Example Case:
For example, you have a merchantKey that is used to generate a token, which is 1234. When the merchantToken generated by the Merchant is known, it is abcd, while the merchantToken obtained in the notification is abdd. Then the notification is considered fake/invalid.
Sample for Convenience Store Notification
merchantToken=8b5565e793731a1a1c8817c9e42bcbbdc3f5fb6a2785a6e0b19a2d5e3a41a51b
goodsNm=Testing
referenceNo=ord0123456
mitraCd=ALMA
transTm=150229
tXid=TNICECV03103202212141459041632
amt=5000
instmntType=1
billingNm=John-Doe
matchCl=1
payNo=504100002539
payValidTm=null
payMethod=03
currency=IDR
instmntMon=1
payValidDt=null
transDt=20221214
status=0