Mobile Payment Webhook

When a transaction is successfully completed, Hecto Financial sends a webhook to your server. For details, see the notiUrl guide.

NOTE

What is notiUrl?

notiUrl is a server-to-server webhook endpoint that receives the payment result directly from the Hecto Financial server. It does not go through the browser, allowing stable and reliable receipt of results.

Communication Specification

ItemDescription
MethodPOST
Content-Typeapplication/x-www-form-urlencoded; charset=UTF-8
Response FormatPlain Text (OK or FAIL)

Cancellation Webhook Notice

Cancellation webhook is not provided by default

Mobile payment cancellation results are confirmed via API response, so cancellation webhooks are not sent by default. If you need cancellation webhooks, contact your sales representative or technical support (pgsupport@hecto.co.kr).

Webhook Parameters

타입 표기법
N숫자A영문H한글AN영문+숫자AHN영문+한글+숫자
예: AN(10) = 영문+숫자, 최대 10byte
outStatCdN(4)Numeric, up to 4 bytes*0021
Transaction status
0021: Success
trdNoAN(40)Alphanumeric, up to 40 bytes*STFP_PGMPnxhp_sb_il00210806075210M1853381
Unique transaction number assigned by Hecto Financial
methodA(2)Alphabetic, up to 2 bytes*MP
Payment method
MP: Mobile Payment
bizTypeAN(2)Alphanumeric, up to 2 bytes*B0
Business type
B0: Payment C0: Cancellation B1: Recurring renewal B2: Hecto Financial original payment C1: Refund
mchtIdAN(12)Alphanumeric, up to 12 bytes*nxhp_sb_il
Merchant ID assigned by Hecto Financial
mchtTrdNoAN(100)Alphanumeric, up to 100 bytes*ORDER20211231100000
Unique order number generated by the merchant
mchtCustNmAHN(30)Alphanumeric + Korean, up to 30 bytesHong Gil-dong
The name of the customer who completed this payment
mchtNameAHN(20)Alphanumeric + Korean, up to 20 bytesHecto Financial
Actual seller name. If not provided during the transaction request, the merchant name registered with Hecto Financial is used.
pmtprdNmAHN(128)Alphanumeric + Korean, up to 128 bytesTest Product
Product name ordered by the customer
trdDtmN(14)Numeric, up to 14 bytes*20211231010101
Transaction datetime. For approvals: approval datetime. For cancellations: cancellation datetime. Format: YYYYMMDDhhmmss
trdAmtN(12)Numeric, up to 12 bytes1000
Transaction amount
billKeyAN(40)Alphanumeric, up to 40 bytesMO0123456789
Bill key issued for recurring payment subsequent charges
billKeyExpireDtN(4)Numeric, up to 4 bytes1231
Recurring payment key expiration date (YYMM)
telecomCdA(10)Alphabetic, up to 10 bytesSKT
Carrier code
SKT: SK Telecom KTF: KT LGT: LG U+ CJH: CJ Hello Mobile KCT: Korea Cable Telecom SKL: SK 7Mobile
telecomNmAHN(10)Alphanumeric + Korean, up to 10 bytesSK Telecom
Carrier name
emailAN(60)Alphanumeric, up to 60 bytesHongGilDong@example.com
Merchant customer email
mchtCustIdAN(50)Alphanumeric, up to 50 bytesHongGilDong
Merchant customer ID
phoneNoEncN(11)Numeric, up to 11 bytesAES-256AES-256/ECB/PKCS5Padding01012345678
Customer mobile phone number
*실제 응답값은 AES-256 암호화된 값입니다. 복호화 후 사용하세요.
orgTrdNoAN(40)Alphanumeric, up to 40 bytesSTFP_PGMPnxhp_sb_il00210806075210M1853381
Original transaction number for cancellations
orgTrdDtN(8)Numeric, up to 8 bytes20211231
Original transaction date for cancellations
cnclTypeN(2)Numeric, up to 2 bytes00
Cancellation type
00: Full cancellation 10: Partial cancellation
mchtParamAHN(4000)Alphanumeric + Korean, up to 4000 bytesname=HongGilDong&age=25
Additional merchant information field. The value passed in the request is returned as-is.
pktHashAN(64)Alphanumeric, up to 64 bytes*a2d6d597d55d7c9b689baa2e08c1ddf0ce71f4248c5b9b59fe61bfbf949543e1
SHA256 hash value
NOTE

Hash Generation Combination

outStatCd + transaction date (first 8 digits of trdDtm) + transaction time (last 6 digits of trdDtm) + mchtId + mchtTrdNo + trdAmt (plaintext) + hashKey

Webhook Response (Merchant → Hecto Financial)

Your server must respond to Hecto Financial after receiving the webhook.

ResponseDescription
OKSuccess (uppercase). Processed as webhook received.
FAIL or othersRecognized as failure; resent up to the configured number of times per merchant. Sending stops after exceeding the resend deadline.

Response format note

The response must be plain text 'OK' only. If spaces or other characters are included, it will be considered a failure and resending will occur.

Hash Verification

Hash verification required

To check for data tampering, you must verify the hash data received via notiUrl. Only provide the service when the hash matches.
ItemCombination Fields
pktHashTransaction status code + transaction date (first 8 digits of trdDtm) + transaction time (last 6 digits of trdDtm) + merchant ID + merchant order number + transaction amount + hash key

Webhook Example

Payment Webhook (Hecto Financial → Merchant)

POST /your-noti-url HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=UTF-8

outStatCd=0021
&trdNo=STFP_PGMPnxhp_sb_il0211231100000M1234567
&method=MP
&bizType=B0
&mchtId=nxhp_sb_il
&mchtTrdNo=ORDER20211231100000
&mchtCustNm=HongGilDong
&mchtName=HectoFinancial
&pmtprdNm=Test Product
&trdDtm=20211231100000
&trdAmt=10000
&telecomCd=SKT
&telecomNm=SK Telecom
&email=test@example.com
&mchtCustId=customer123
&mchtParam=
&pktHash=a2d6d597d55d7c9b689baa2e08c1ddf0ce71f4248c5b9b59fe61bfbf949543e1

Response (Merchant → Hecto Financial)

OK
💬

Need technical support?