/pay/omg/createtoken: <user-login-token>@Anonymous + project @Auth@RequestHeader String token.POST /pay/omg/create
Content-Type: application/json
token: <login-token>
{
"orderId": "991786433092835"
}
Rules:
orderId.@RequestBody(required = false).orderId is trimmed, non-empty and at most 64 characters.Outer response keeps the project AjaxResult format. data is:
{
"status": "CREATED",
"gatewayUrl": "https://payment-stage.funpoint.com.tw/Cashier/AioCheckOut/V5",
"formFields": {
"MerchantID": "1000031",
"MerchantTradeNo": "OMGR8K3P7W2M9C4X6A1B",
"MerchantTradeDate": "2026/08/13 15:30:23",
"PaymentType": "aio",
"TotalAmount": "100",
"TradeDesc": "Foodie order 991786433092835",
"ItemName": "Order 991786433092835",
"ReturnURL": "https://foodieapi.waimai-paotui.com/pay/omg/notify",
"ChoosePayment": "ALL",
"EncryptType": "1",
"InvoiceMark": "N",
"NeedExtraPaidInfo": "Y",
"ExpireDate": "1",
"StoreExpireDate": "30",
"BarcodeATMExpireDate": "1",
"CheckMacValue": "<64 uppercase hexadecimal characters>"
}
}
The client must submit every formFields entry in the current page as an application/x-www-form-urlencoded POST to gatewayUrl. It must not use iframe, a new window or a GET link.
{
"code": 500,
"msg": "<localized message>",
"data": {
"status": "PAYMENT_ATTEMPT_EXISTS"
}
}
Stable statuses:
| Status | Meaning |
|---|---|
AUTH_REQUIRED |
No usable user identity reached the new Controller |
ORDER_REQUIRED |
Request or orderId is missing/invalid |
ORDER_NOT_AVAILABLE |
Order does not exist or is not owned by this user |
MULTI_STORE_ORDER_NOT_SUPPORTED |
Matched row is a multi-store child order |
ORDER_STATE_NOT_PAYABLE |
State is not 0, 1 or 2 |
ORDER_ALREADY_PAID |
pay_status is not 0 |
ORDER_AMOUNT_INVALID |
Amount is null or not positive |
PAYMENT_TYPE_INVALID |
pay_type is not "2" |
STORE_CREDENTIAL_UNAVAILABLE |
No enabled credential exists for the order store |
PAYMENT_ATTEMPT_EXISTS |
The order already has an active CREATED attempt |
PAYMENT_CONFIGURATION_INVALID |
Stage/ReturnURL safety validation failed |
PAYMENT_CREATION_FAILED |
Controlled generation/insert attempts could not complete |
No error response includes token, HashKey, HashIV, CheckMacValue, form fields, SQL or stack trace.
POST /pay/omg/notify remains the ReturnURL value sent to OMG, but this phase intentionally registers no handler. The old handler must not receive this route. Callback implementation requires a later independent specification.