(Optional) Handle Callback URL for payment status updates
Once the customer completes the payment, PayWay will send the transaction details and other important information to the
return_url.
If return_url is not provided in the request, PayWay will use the default return_url configured in the API Settings.
If you provide a custom return_url, make sure the domain is whitelisted in your merchant profile.
Your return_url endpoint must:Accept the HTTP POST method
Accept Content-Type: application/json
We highly recommend securing this URL to ensure that only ABA PayWay has access to it.
{
"tran_id": "9065703303",
"apv": "544415",
"status": "0",
"return_params": "{\"order_id\":\"123\",\"amount\":100,\"client_id\":\"1234567890\"}",
"original_amount": 0.01,
"original_currency": "USD",
"payment_amount": 0.01,
"payment_currency": "USD",
"total_amount": 0.01,
"discount_amount": 0,
"transaction_date": "2026-08-03 13:57:20",
"first_name": "",
"last_name": "",
"email": "",
"phone": "",
"bank_ref": "100FT40074059022",
"payment_type": "ABA Pay",
"payer_account": "003471222",
"bank_name": "",
"card_source": ""
}
tran_id string
Payment transaction ID generated by the payment gateway.
Max. Length: 20
apv string
Transaction approval code.
Length: 6
status string
Request status code.
Value: 0
return_params string
Additional return parameters encoded as a string containing order details and metadata.
original_amount number
Original transaction amount before discount.
original_currency string
Original transaction currency.eg. USD or KHR
payment_amount number
Amount that the customer has paid.
payment_currency string
Payment currency that the customer used to pay.
eg. USD or KHR
total_amount number
Amount that customer suppose to pay after discount.
discount_amount number
Discounted amount and its currency follow original currency.
transaction_date string
Created date of the transaction in payment gateway database.
Format: YYYY-MM-DD HH:MM:SS
first_name string
Payer's first name.
last_name string
Payer's last name.
email string
Payer's email.
phone string
Payer's phone number.
bank_ref string
Unique booking entry reference number from ABA Core banking system.
payment_type string
Payment method that the customer used to make payment. Possible values:ABA Pay — Transaction made with ABA Account (ABA Mobile)
Alipay — Transaction made with Alipay
Wechat — Transaction made with WeChat pay
KHQR — Transaction made with KHQR
VISA — Transaction made with Visa card
MC — Transaction made with Mastercard
JCB — Transaction made with JCB card
CUP — Transaction made with UPI card
payer_account string
Masked ABA Account Number or Masked Card PAN. For other payment options, it will be blank.
bank_name string
If payment is made with ABA PAY, it will show ABA Bank and if payment made using KHQR it will show issuer bank name.
card_source string
Possible values:ONUS — Transaction is made with ABA bank card
OFFUS_DOMESTIC — Transaction is made with other local bank card
OFFUS_INTERNATIONAL — Transaction is made with other international bank card
Verify Callback SignatureFor security purposes, PayWay includes a hash signature in the request header.
You should verify this signature to confirm that the callback was sent by PayWay and that the data has not been modified.Below is an example in PHP demonstrating how to:3.
Compare it with the signature received in the header
// Read request body
$response = json_decode(file_get_contents('php://input'), true);
$secretKey = "YOUR_SECRET_KEY";
// 1. Sort fields by key (ascending)
ksort($response);
// 2. Concatenate all values
$b4hash = '';
foreach ($response as $value) {
if (is_array($value)) {
$value = json_encode($value);
}
$b4hash .= $value;
}
// 3. Generate HMAC-SHA512 signature
$signature = base64_encode(
hash_hmac('sha512', $b4hash, $secretKey, true)
);
// 4. Get signature from request header
$receivedSignature = $_SERVER['HTTP_X_PAYWAY_HMAC_SHA512'] ?? '';
// 5. Compare signatures
if (hash_equals($signature, $receivedSignature)) {
// Valid request – process the notification
} else {
// Invalid request
http_response_code(401);
exit('Invalid signature');
}