Credit Card Approval API (Deferred Capture)

A credit card payment API that processes authentication and capture separately. After authentication is completed, the capture request is submitted as a separate step.

Test Key Information


Important Notes

Deferred Capture Method

You must use the merchant order number (mchtTrdNo) created during the authentication request, and authTrdNo must be the transaction number received upon successful authentication.
  • This API performs only the capture step separately after authentication is completed.
  • The merchant order number used during authentication and the authentication transaction number are required.
  • Billkey issuance requires a separate service activation.

API Information

POST/spay/APIService.do
Content-Typeapplication/json
테스트https://tbgw.settlebank.co.kr/spay/APIService.do
운영https://gw.settlebank.co.kr/spay/APIService.do

Request Parameters

타입 표기법
N숫자A영문H한글AN영문+숫자AHN영문+한글+숫자
예: AN(10) = 영문+숫자, 최대 10byte

params Object

mchtIdAN(12)Alphanumeric, up to 12 bytes*
Unique merchant ID assigned by Hecto Financial
verAN(4)Alphanumeric, up to 4 bytes*
Message version
*Fixed value
methodA(2)Alphabetic, up to 2 bytes*
Payment method
*Fixed value
bizTypeAN(2)Alphanumeric, up to 2 bytes*
Business type code
*Fixed value (for capture)
encCdN(2)Numeric, up to 2 bytes*
Encryption type code
*Fixed value
mchtTrdNoAN(100)Alphanumeric, up to 100 bytes*
Merchant order number (must use the number created during the authentication request)
trdDtN(8)Numeric, up to 8 bytes*
Request date (YYYYMMDD)
trdTmN(6)Numeric, up to 6 bytes*
Request time (HHMMSS)
mobileYnA(1)Alphabetic, up to 1 bytes
Mobile indicator
Y: Mobile web/app N: PC or other
osTypeA(1)Alphabetic, up to 1 bytes
OS type
A: Android I: IOS W: Windows M: Mac E: Other

data Object

pktHashAN(64)Alphanumeric, up to 64 bytes*SHA-256(실시간 생성)
Hash value generated using SHA256
NOTE

Hash Generation Combination

trdDt + trdTm + mchtId + mchtTrdNo + trdAmt (plaintext) + hashKey
trdAmtN(12)Numeric, up to 12 bytes*AES-256AES-256/ECB/PKCS5Padding + Base64
Transaction amount
authTrdNoAN(40)Alphanumeric, up to 40 bytes*
Authentication transaction number (transaction number received upon successful authentication)

Response Parameters

타입 표기법
N숫자A영문H한글AN영문+숫자AHN영문+한글+숫자
예: AN(10) = 영문+숫자, 최대 10byte

params Object

mchtIdAN(12)Alphanumeric, up to 12 bytes*nxca_jt_hd
Unique merchant ID assigned by Hecto Financial
verAN(4)Alphanumeric, up to 4 bytes*0A19
Message version
*Fixed value
methodA(2)Alphabetic, up to 2 bytes*CA
Payment method
*Fixed value
bizTypeAN(2)Alphanumeric, up to 2 bytes*B2
Business type code
*Fixed value for capture
encCdN(2)Numeric, up to 2 bytes*23
Encryption type code
*Fixed value
mchtTrdNoAN(100)Alphanumeric, up to 100 bytes*ORDER20211231100000
Merchant order number
trdNoAN(40)Alphanumeric, up to 40 bytes*SOFP_PGMPnxhp_sb_hd0211021111808M1234567
Unique transaction number issued by Hecto Financial
trdDtN(8)Numeric, up to 8 bytes*20211231
Request date (YYYYMMDD)
trdTmN(6)Numeric, up to 6 bytes*100000
Request time (HHMMSS)
outStatCdN(4)Numeric, up to 4 bytes*0061
Transaction status code
0061: Authentication success (authentication step) 0021: Capture success (capture step) 0031: Failure
*In the deferred capture method, 0061 is returned at the authentication step and 0021 at the capture step.
outRsltCdN(4)Numeric, up to 4 bytes*0000
Result code. Detailed code provided when transaction status is '0031'
*Refer to the decline code table
outRsltMsgAHN(200)Alphanumeric + Korean, up to 200 bytes*Processed successfully.
Result message (URL Encoding, UTF-8)

data Object

pktHashAN(64)Alphanumeric, up to 64 bytes*
Hash value from request returned as-is
trdAmtN(12)Numeric, up to 12 bytes*AES-256AES-256/ECB/PKCS5Padding1000
Transaction amount
*실제 응답값은 AES-256 암호화된 값입니다. 복호화 후 사용하세요.
mchtParamAHN(4000)Alphanumeric + Korean, up to 4000 bytesname=HongGilDong&age=25
Request value returned as-is in response
apprNoN(15)Numeric, up to 15 bytes30001234
Credit card approval number
intMonN(2)Numeric, up to 2 bytes00
Credit card installment months
fnNmAH(20)Alpha + Korean, up to 20 bytesWoori Card
Credit card company name
fnCdAN(4)Alphanumeric, up to 4 bytesLTC
Credit card company code
pointTrdNoAN(40)Alphanumeric, up to 40 bytesSTFP_PGCAnxca_jt_il0211129135810M1494620
Point transaction number (for Point Damoa combined payment)
pointTrdAmtN(12)Numeric, up to 12 bytesAES-256AES-256/ECB/PKCS5Padding1000
Point transaction amount (for Point Damoa combined payment)
*실제 응답값은 AES-256 암호화된 값입니다. 복호화 후 사용하세요.
cardTrdAmtN(12)Numeric, up to 12 bytesAES-256AES-256/ECB/PKCS5Padding4000
Credit card payment amount excluding discounts/points
*실제 응답값은 AES-256 암호화된 값입니다. 복호화 후 사용하세요.
billKeyAN(50)Alphanumeric, up to 50 bytesSBILL_0123456789
Billkey (recurring payment token)
*Requires separate service activation. Contact your account manager.
dcTrdAmtN(12)Numeric, up to 12 bytes*AES-256AES-256/ECB/PKCS5Padding1000
Discount transaction amount
*실제 응답값은 AES-256 암호화된 값입니다. 복호화 후 사용하세요.
dcYnA(1)Alphabetic, up to 1 bytes*Y
Discount indicator
Y: Discount amount exists N: No discount amount
ninstmtTypeCdA(1)Alphabetic, up to 1 bytesY
Interest-free installment type
Y: Interest-free N: Regular installment/full payment
cardNoAN(20)Alphanumeric, up to 20 bytesAES-256AES-256/ECB/PKCS5Padding123456******7890
Card number (masked, optional based on merchant settings)
*실제 응답값은 AES-256 암호화된 값입니다. 복호화 후 사용하세요.
ornPntUseYnA(1)Alphabetic, up to 1 bytesY
Card company points usage indicator
Y: Used N: Not used
ornPntAmtA(12)Alphabetic, up to 12 bytesAES-256AES-256/ECB/PKCS5Padding1000
Card company points usage amount
*실제 응답값은 AES-256 암호화된 값입니다. 복호화 후 사용하세요.

Request Example

{
  "params": {
    "mchtId": "nxca_jt_hd",
    "ver": "0A19",
    "method": "CA",
    "bizType": "B2",
    "encCd": "23",
    "mchtTrdNo": "ORDER20211231100000",
    "trdDt": "20211231",
    "trdTm": "100000",
    "mobileYn": "N",
    "osType": "W"
  },
  "data": {
    "pktHash": "980f95d9b059dd15394eeb39e9d7bc8b3500f9afa4a38bea10877cd46a42caf6",
    "trdAmt": "AES-encrypted amount",
    "authTrdNo": "SOFP_PGMPnxhp_sb_hd0211021111808M1234567"
  }
}

Response Examples

Success Response

{
  "params": {
    "mchtId": "nxca_jt_hd",
    "ver": "0A19",
    "method": "CA",
    "bizType": "B2",
    "encCd": "23",
    "mchtTrdNo": "ORDER20211231100000",
    "trdNo": "SOFP_PGMPnxhp_sb_hd0211021111808M1234567",
    "trdDt": "20211231",
    "trdTm": "100000",
    "outStatCd": "0021",
    "outRsltCd": "0000",
    "outRsltMsg": "Processed successfully."
  },
  "data": {
    "pktHash": "980f95d9b059dd15394eeb39e9d7bc8b3500f9afa4a38bea10877cd46a42caf6",
    "trdAmt": "AES-encrypted amount",
    "apprNo": "30001234",
    "intMon": "00",
    "fnNm": "Woori Card",
    "fnCd": "LTC",
    "billKey": "SBILL_0123456789",
    "dcTrdAmt": "AES-encrypted discount amount",
    "dcYn": "Y",
    "ninstmtTypeCd": "N"
  }
}

Failure Response

{
  "params": {
    "mchtId": "nxca_jt_hd",
    "ver": "0A19",
    "method": "CA",
    "bizType": "B2",
    "encCd": "23",
    "mchtTrdNo": "ORDER20211231100000",
    "trdNo": "",
    "trdDt": "20211231",
    "trdTm": "100000",
    "outStatCd": "0031",
    "outRsltCd": "1001",
    "outRsltMsg": "Missing payment request information"
  },
  "data": {
    "pktHash": "980f95d9b059dd15394eeb39e9d7bc8b3500f9afa4a38bea10877cd46a42caf6"
  }
}

Response Codes

Transaction Status Codes (outStatCd)

CodeDescriptionNote
0061Authentication successAuthentication step of deferred capture method
0021Capture successCapture step of deferred capture method
0031FailureSee outRsltCd for details
0051Virtual account number issuedVirtual account issuance

PG Common Response Codes (outRsltCd)

CodeDescription
0000Processed successfully
0009User cancelled
1001Missing required payment information (merchant ID)
1002Missing required payment information (version)
1003Missing required payment information (payment method)
1004Missing required payment information (business type code)
1005Missing required payment information (merchant order number)
1006Missing required payment information (request date)
1007Missing required payment information (request time)
1008Missing required payment information (hash value)
1009Missing required payment information (transaction amount)
1010Missing required payment information (encryption type code)
1011Missing required payment information (transaction number)
1012Missing required payment information (cancellation amount)
1013Missing required payment information (refund amount)
1101Payment request information length error (merchant ID)
1102Payment request information length error (version)
1103Payment request information length error (payment method)
1104Payment request information length error (business type code)
1105Payment request information length error (merchant order number)
1106Payment request information length error (request date)
1107Payment request information length error (request time)
1108Payment request information length error (hash value)
1109Payment request information length error (transaction amount)
1110Payment request information length error (encryption type code)
1111Payment request information length error (transaction number)
1112Payment request information length error (cancellation amount)
1113Payment request information length error (refund amount)
1901Hash value mismatch error
1902Encrypted field not processed error
2001Security number mismatch
2002Security number input timeout
2003Security number input attempts exceeded
5001Invalid access path (merchant information not found)
5002Invalid access path (merchant inactive)
5003Invalid access path (payment method not contracted)
5004Invalid access path (payment method inactive)
5005Invalid access path (business type not supported)
5006Invalid access path (IP blocked)
9001Gateway internal error
9002Gateway communication error
9003Gateway database error
9004Gateway timeout
9901Issuer system maintenance
9902Issuer system failure
9903Issuer communication error
9904Issuer timeout
9905Issuer response error

Credit Card Specific Response Codes (outRsltCd)

CodeDescription
CA01Issuer under maintenance
CA02Issuer system failure
CA20Invalid card expiration date
CA65Merchant not contracted for authenticated transactions
CA82Please call card company
CA83This transaction cannot be cancelled
💬

Need technical support?