Bank Transfer Webhook

When a transaction is successfully completed, Hecto Financial sends a webhook to your server. For details, see the notiUrl guide.

NOTE

What is notiUrl?

notiUrl is a server-to-server webhook endpoint that receives the payment result directly from the Hecto Financial server. It does not go through the browser, allowing stable and reliable receipt of results.

Communication Specification

ItemDescription
MethodPOST
Content-Typeapplication/x-www-form-urlencoded; charset=UTF-8
Response FormatPlain Text (OK or FAIL)

Cancellation Webhook Notice

Cancellation webhook is not provided by default

Bank transfer cancellation results are confirmed via API response, so cancellation webhooks are not sent by default. If you need cancellation webhooks, contact your sales representative or technical support (pgsupport@hecto.co.kr).

Webhook Parameters

타입 표기법
N숫자A영문H한글AN영문+숫자AHN영문+한글+숫자
예: AN(10) = 영문+숫자, 최대 10byte
└outStatCdN(4)Numeric, up to 4 bytes*0021
Transaction status
0021: Success
└trdNoAN(40)Alphanumeric, up to 40 bytes*STFP_PGRAnxra_jt_il0211129135810M1494620
Unique transaction number assigned by Hecto Financial
└methodA(2)Alphabetic, up to 2 bytes*RA
Payment method
RA: Bank Transfer
└bizTypeAN(2)Alphanumeric, up to 2 bytes*B0
Business type
B0: Approval C0: Cancellation
└mchtIdAN(12)Alphanumeric, up to 12 bytes*nx_mid_il
Merchant ID assigned by Hecto Financial
└mchtTrdNoAN(100)Alphanumeric, up to 100 bytes*ORDER20211231100000
Unique order number generated by the merchant
└mchtCustNmAHN(30)Alphanumeric + Korean, up to 30 bytesHong Gil-dong
The name of the customer who completed this payment
└mchtNameAHN(20)Alphanumeric + Korean, up to 20 bytesHecto Financial
Actual seller name. If not provided at the time of transaction request, the merchant name registered with Hecto Financial is used.
└pmtprdNmAHN(128)Alphanumeric + Korean, up to 128 bytesTest Product
Product name ordered by the customer
└trdDtmN(14)Numeric, up to 14 bytes*20211231100000
Transaction datetime. For approvals: approval datetime. For cancellations: cancellation datetime. Format: YYYYMMDDhhmmss
└trdAmtN(12)Numeric, up to 12 bytes1000
Transaction amount
└bankCdAN(10)Alphanumeric, up to 10 bytes011
Bank code
└bankNmAHN(10)Alphanumeric + Korean, up to 10 bytesNH NongHyup
Bank name
└acntPrintNmAHN(12)Alphanumeric + Korean, up to 12 bytesHecto Financial
Statement description to appear on the customer's bank account. The value sent at the time of payment request is used. If no value is provided, the merchant name registered with Hecto Financial is used.
└emailAN(60)Alphanumeric, up to 60 bytesHongGilDong@example.com
Merchant customer email
└mchtCustIdAN(50)Alphanumeric, up to 50 bytesHongGilDong
Merchant customer ID
└orgTrdNoAN(40)Alphanumeric, up to 40 bytesSTFP_PGRAnxra_jt_il0211129135810M1494620
Original transaction number for cancellations
└orgTrdDtN(8)Numeric, up to 8 bytes20211231
Original transaction date for cancellations
└csrcIssNoAN(9)Alphanumeric, up to 9 bytes0123456789
Cash receipt approval number
└cnclTypeN(2)Numeric, up to 2 bytes00
Cancellation type
00: Full cancellation 10: Partial cancellation
└mchtParamAHN(4000)Alphanumeric + Korean, up to 4000 bytesname=HongGilDong&age=25
Additional merchant information field. The value passed in the request is returned as-is.
└pktHashAN(64)Alphanumeric, up to 64 bytes*a2d6d597d55d7c9b689baa2e08c1ddf0ce71f4248c5b9b59fe61bfbf949543e1
SHA256 hash value
NOTE

Hash Generation Combination

outStatCd + trdDt + trdTm + mchtId + mchtTrdNo + trdAmt (plaintext) + hashKey (trdDt: first 8 digits of trdDtm, trdTm: last 6 digits of trdDtm)

Webhook Response (Merchant → Hecto Financial)

Your server must respond to Hecto Financial after receiving the webhook.

ResponseDescription
OKSuccess (uppercase). Processed as webhook received.
FAIL or othersRecognized as failure; resent up to the configured number of times per merchant. Sending stops after exceeding the resend deadline.

Response format note

The response must be plain text 'OK' only. If spaces or other characters are included, it will be considered a failure and resending will occur.

Hash Verification

Hash verification required

To check for data tampering, you must verify the hash data received via notiUrl. Only provide the service when the hash matches.
ItemCombination Fields
pktHashTransaction status code (outStatCd) + Transaction date (first 8 digits of trdDtm) + Transaction time (last 6 digits of trdDtm) + Merchant ID + Merchant order number + Transaction amount + Hash key

Webhook Example

Payment Webhook (Hecto Financial → Merchant)

POST /your-noti-url HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=UTF-8

outStatCd=0021
&trdNo=STFP_PGRAnxra_sb_il0211231100000M1234567
&method=RA
&bizType=B0
&mchtId=nx_mid_il
&mchtTrdNo=ORDER20211231100000
&mchtCustNm=HongGilDong
&mchtName=HectoFinancial
&pmtprdNm=Test Product
&trdDtm=20211231100000
&trdAmt=50000
&bankCd=011
&bankNm=NH NongHyup
&csrcIssNo=
&email=test@example.com
&mchtCustId=customer123
&mchtParam=
&pktHash=a2d6d597d55d7c9b689baa2e08c1ddf0ce71f4248c5b9b59fe61bfbf949543e1

Response (Merchant → Hecto Financial)

OK
💬

Need technical support?

무엇이든 물어보세요