Skip to content

Get Proof Link ​

Get a proof page access link by merchant order number.

Endpoint ​

GET /proof/link

Authentication ​

Merchant Credential. See Authentication.

Background ​

Availability: This API is an external contract pending integration; its actual availability is subject to release confirmation.

Using the merchant order number merchantOrderNo, the merchant obtains the proof page access link linkUrl for its own cashout order. The proof type is specified by proofType; currently only APS (cashout order) is supported.

Retrieval Rules ​

  • Only the authenticated merchant's own orders can be queried; merchantOrderNo must match the merchant order number used when placing the payout order, and proofType must match the actual type of that order.
  • The payment proof must already exist. This API only generates an access link; it does not create proofs or change the order status.
  • If the order or proof does not exist, no usable link is returned. Failure to obtain a proof does not mean the payment failed; confirm the transaction result via Query cashout by Order SN.
  • Use the complete linkUrl as-is and preserve its key query parameter. The link should be kept as an access credential and shared only with the intended recipient; the example domain and key are for illustration only, and the complete URL actually returned takes precedence.

Request Fields ​

FieldLocationTypeLengthRequiredDescription
X-Merchant-IdHeaderstring64YesMerchant ID, read from the request header; used to isolate order data across merchants.
X-TimestampHeaderint19YesUnix request timestamp in seconds, used for request freshness validation.
X-NonceHeaderstring64YesRandom string for request anti-replay protection.
DigestHeaderstring52YesRequest digest. Format: SHA-256=<Base64Digest>; this API has no request body, so the digest is computed over an empty byte string.
AuthorizationHeaderstringVariableYesES256 request signature, where keyId is the merchant key version.
merchantOrderNoQuerystring64YesMerchant order number used when placing the payout order; must not be blank and must not exceed 64 bytes.
proofTypeQuerystring16YesProof type; currently only APS (cashout order) is supported.

Request Example ​

http
GET /proof/link?merchantOrderNo=CASHOUT202608160001&proofType=APS HTTP/1.1
X-Merchant-Id: 92315566000120
X-Timestamp: 1786845600
X-Nonce: 550e8400-e29b-41d4-a716-446655440000
Digest: SHA-256=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=
Authorization: Signature keyId="v1",alg="ES256",headers="(request-target) x-timestamp x-nonce digest",signature="<ES256_SIGNATURE_BASE64>"

GET requests carry no request body. In actual calls, use the current timestamp and a new random string, and compute the signature from the actual request path and the full query string; see Request Signing for details.

Response Fields ​

The API uses a unified status, msg, data response structure. The proof link is retrieved successfully only when status = 200 and data.linkUrl is non-empty.

FieldTypeLengthReturnedDescription
statusint4YesResponse code; 200 means the request was processed successfully.
msgstring128YesCorresponds to status; "sucesso" on success.
dataobjectN/ANoProof link result; may be absent or null when the request processing fails.
data.merchantOrderNostring64On successMerchant order number.
data.platOrderNostring64On successPlatform order number.
data.linkUrlstring128On successComplete payment proof page access link, including the key query parameter; non-empty on success, and not the proof JSON or file content.

When business processing fails, status is not 200 and the reason is given in msg; the link fields must not be used in that case. Failures before business processing, such as signature verification or protocol parsing, may result in data being absent.

Response Example ​

json
{
  "status": 200,
  "msg": "sucesso",
  "data": {
    "merchantOrderNo": "CASHOUT202608160001",
    "platOrderNo": "APS202608160000000001",
    "linkUrl": "https://proof.example.com/payment?key=PROOF_KEY"
  }
}