Accept payments

Tokenized Payment enables you to build an online automatic deduction feature on your website or application. After the buyer completes authorization during the first payment, subsequent payments can be made with just one click or directly deducted by your system without buyer's action. It is suitable for the following business scenarios:
  • Recurring payments: For example, subscription or membership services, where the payment deduction cycle is managed by you.
  • Small-amount, high-frequency payments or high repurchase-rate scenarios: For example, gaming and e-commerce, where you can provide your buyers with a convenient and seamless payment experience.
The Tokenized Payment product supports integration on various terminal types (Web/WAP/App), and requires only a single integration to connect with multiple payment methods, such as e-wallets and bank transfers.
Web/WAP
iOS
Android

Step 4: Apply for payment token
Server-side

After obtaining the authorization code (authCode), you must call the applyToken API within one minute to request a payment token (accessToken). Otherwise, the authCode will expire and become invalid. Only after obtaining accessToken can subsequent tokenized payments be made from the buyer's account.
When calling the applyToken API, ensure the following parameters are correctly passed in the request:
Parameter name
Required
Description
grantType
Yes
Pass in the fixed value
AUTHORIZATION_CODE
.
customerBelongsTo
Yes
Specify the target payment method for which you are requesting authorization.
authCode
Yes
Pass in the value of authcode that you obtained in Step 3.
The following code is a sample of calling the applyToken API:
public static void applyToken() {
  String authCode = "yourAuthCode";
  AlipayAuthApplyTokenRequest alipayPayRequest = new AlipayAuthApplyTokenRequest();

  // set grantType
  alipayPayRequest.setGrantType(GrantType.AUTHORIZATION_CODE);
  // set the target payment method for which you are requesting authorization
  alipayPayRequest.setCustomerBelongsTo(CustomerBelongsTo.GCASH);
  // set authCode
  alipayPayRequest.setAuthCode(authCode);

  // apply for the token
  AlipayAuthApplyTokenResponse authApplyTokenResponse;
  try {
      authApplyTokenResponse = CLIENT.execute(alipayPayRequest);
  } catch (AlipayApiException e) {
      String errorMsg = e.getMessage();
      // handle error condition
  }
}
The following sample code shows a request message of applying for the payment token:
{
"authCode": "663A8FA9D83648EE8AA11FF68298XXXX",
"customerBelongsTo": "GCASH",
"grantType": "AUTHORIZATION_CODE"
}
The following sample code shows a response message of applying for the payment token:
{ 
"accessToken": "281011030220200914TLsu9RhgUv87Lf1111****",
"accessTokenExpiryTime": "2022-09-14T17:14:16+08:00",
"extendInfo": "{"userId":"100000111111****","userLoginId":"6017271****"}",
"result": {
  "resultCode": "SUCCESS",
  "resultMessage": "Success",
  "resultStatus": "S"
},
"userLoginId": "6017271****"
}
The following table shows the possible values of result.resultStatus in the response message for applying for the payment token. Please handle the result according to the guidance provided:
result.resultStatus
Message
Further action
S
The request was successful.
Successfully obtained accessToken, and the following fields are returned:
  • accessToken: The tokenized payment ID generated by Antom for subsequent payments.
  • accessTokenExpiryTime: For the specific expiry time of accessToken, refer to Validity period of accessToken. If the accessToken expires, you need to guide the buyer to authorize again.
  • userLoginId: The login ID used by the buyer when registering for the payment method. You can store this account information for display during subsequent payments. Note that not all payment methods will return this information, refer to Features of payment methods for details.
U
​
Unknown error.
Please call the API again with the same parameters. If the issue persists, contact Antom Technical Support.
F
The request failed.
Please handle the relevant issues based on result.resultCode message.
Note: If no response is received, it may indicate a network timeout. Please call the API again with the same parameters. If the issue persists, contact Antom Technical Support.
Common questions
Q: Can authCode be reused?
A: No. authCode can only be used once.
​
Q: How long is the validity period of authCode?
A: 1 minute for common scenarios. Ensure the payment token is requested within 1 minute.
​
Q: Can I obtain the payment token through asynchronous notifications?
A: No. The payment token can only be applied for by calling the applyToken API.

Validity period of payment token

Regarding the payment methods supported by Tokenized Payment, the validity period of payment token (accessToken) is shown in the following table:
Payment method
Validity period of accessToken
92 years
100 years
100 years
100 years
100 years
100 years
100 years
1 yearNote
2 years
100 years
76 years
76 years
10 years
10 years
100 years
100 years
100 years
14 years
10 years
Note: After successfully completing the initial authorization with PayPay, the token is valid for one year. If any successful transaction occurs within the validity period, the token's validity will automatically extend by an additional year, starting from the date of the successful transaction.

Step 5: Initiate a payment
Server-side

With a successful authorization, you can provide the buyer with tokenization services. Funds will be automatically deducted for subsequent purchases without requiring the buyer to re-enter payment information.
Specify the following parameters when initiating a payment:
Parameter name
Required
Description
productCode
Yes
The payment product that is being used. For Tokenized Payment, the value is fixed as
AGREEMENT_PAYMENT
.
paymentRequestId
Yes
The unique ID generated by the merchant for each payment request.
paymentAmount
Yes
The payment amount in the smallest currency unit. For example,
CNY
in cents,
KRW
in won.
paymentMethod
Yes
The payment method that is used.
paymentMethod.paymentMethodId
Yes
The payment token (accessToken) obtained from the applyToken API.
paymentNotifyUrl
No
The address for receiving payment result notifications. It can be set through the API or or set as a fixed value through Antom Dashboard.
settlementStrategy
No
The settlement strategy for the payment request.
order
Yes
Order information, including order amount, order ID, and order description.
env
Yes
Terminal type where the transaction was initiated. For example, when the transaction is initiated from the merchant's PC browser, the value of env.terminalType is
WEB
.
The above parameters are the basic parameters for initiating a payment, refer to pay (Tokenized Payment) for full parameters and additional requirements for certain payment methods.
The following code is a sample of calling the pay (Tokenized Payment) API:
public static void pay() {
  AlipayPayRequest alipayPayRequest = new AlipayPayRequest();
  alipayPayRequest.setProductCode(ProductCodeType.AGREEMENT_PAYMENT);

  // replace with your paymentRequestId
  String paymentRequestId = UUID.randomUUID().toString();
  alipayPayRequest.setPaymentRequestId(paymentRequestId);

  // set amount
  // you should convert amount unit(in practice, amount should be calculated on your serverside)
  Amount amount = Amount.builder().currency("SGD").value("550000").build();
  alipayPayRequest.setPaymentAmount(amount);

  // set paymentMethod
  PaymentMethod paymentMethod = PaymentMethod.builder().paymentMethodType("GCASH").
  paymentMethodId("2828XXX77801726307481000Iba1Pm20IU171000179").build();
  alipayPayRequest.setPaymentMethod(paymentMethod);

  // set buyer info
  Buyer buyer = Buyer.builder().referenceBuyerId("yourBuyerId").build();

  // replace with your orderId
  String orderId = UUID.randomUUID().toString();
  // set order Info
  Order order = Order.builder().referenceOrderId(orderId).
  orderDescription("antom api testing order").orderAmount(amount).buyer(buyer).build();
  alipayPayRequest.setOrder(order);

  // set env info
  Env env = Env.builder().terminalType(TerminalType.WEB).clientIp("114.121.121.01").build();
  alipayPayRequest.setEnv(env);

  // replace with your notify url
  alipayPayRequest.setPaymentNotifyUrl("http://www.yourNotifyUrl.com");

  AlipayPayResponse alipayPayResponse;
  try {
      alipayPayResponse = CLIENT.execute(alipayPayRequest);
  } catch (AlipayApiException e) {
      String errorMsg = e.getMessage();
      // handle error condition
  }
}
The following code shows a sample of the request message:
{
"env": {
  "clientIp": "114.121.121.01",
  "terminalType": "WEB"
},
"order": {
  "buyer": {
    "referenceBuyerId": "yourBuyerId"
  },
  "orderAmount": {
    "currency": "SGD",
    "value": "550000"
  },
  "orderDescription": "antom api testing order",
  "referenceOrderId": "f69cb774-8d47-4da9-bf91-08c656581cdf"
},
"paymentAmount": {
  "currency": "SGD",
  "value": "550000"
},
"paymentMethod": {
  "paymentMethodId": "2828XXX77801726307481000Iba1Pm20IU171000179",
  "paymentMethodType": "GCASH"
},
"paymentNotifyUrl": "http://www.yourNotifyUrl.com",
"paymentRequestId": "AGREEMENT_PAYMENT_REQUEST_2020070316170XXXX",
"productCode": "AGREEMENT_PAYMENT"
}
The following code shows a sample of the response message:
{
"paymentAmount": {
  "currency": "SGD",
  "value": "550000"
},
"paymentCreateTime": "2020-07-03T01:17:50-07:00",
"paymentId": "2020070311401080010018840027964XXXX",
"paymentRequestId": "AGREEMENT_PAYMENT_REQUEST_2020070316170XXXX",
"result": {
  "resultCode": "SUCCESS",
  "resultMessage": "Success",
  "resultStatus": "S"
}
}
The following table shows the possible values of result.resultStatus in the response message. Please handle the result according to the guidance provided:
result.resultStatus
Message
Further action
S
Payment was successful.
No further action is needed.
U
​
Payment is being processed.
Please poll the inquiryPayment API or wait for the asynchronous notification from notifyPayment for the payment result.
F
Payment failed.
  • In the scenario where the buyer clicks to pay, handle the relevant issues based on the message from result.resultCode.
  • In the scenario of recurring payments, if the deduction initiated from the merchant side fails, handle it based on the return value of result.resultCode:
    • USER_BALANCE_NOT_ENOUGH
      : If you need to call the API again, please note that you can retry up to 2 times within 24 hours. Frequent retries may result in rate limiting on the Antom side.
    • INVALID_ACCESS_TOKEN
      : Please guide the buyer to re-authorize.
    • USER_NOT_EXIST
      : Please guide the buyer to re-authorize.
    • Other error codes: Please handle or retry after confirming the specific reason.
Note: If no response is received, it may indicate a network timeout. Please use the same paymentRequestId and call the API again. If the issue persists, contact Antom Technical Support.
Common questions
Q: How to set terminalType?
A: The valid values of terminalType are:
  • If the buyer initiates a transaction from a PC browser, the terminalType needs to be specified as
    WEB
    .
  • If the buyer initiates a transaction from the mobile browser, the terminalType needs to be specified as
    WAP
    . Add the osType parameter and fill in the corresponding system parameters
    ANDROID
    or
    IOS
    according to the buyer's mobile device.

Q: Can I use Chinese characters in the value of the request parameters?
A: To avoid incompatibility of certain payment methods, do not use Chinese characters for fields in the request.

Q: How to set the address to receive payment notification?
A: Specify paymentNotifyUrl in the pay (Tokenized Payment) API to receive the asynchronous notification about the payment result (notifyPayment), or configure the receiving URL in Antom Dashboard. If the URL is specified in both the request and Antom Dashboard, the value specified in the request takes precedence.

Obtain payment result

You can obtain the payment result using one of the following methods:
  • Receive asynchronous notifications from Antom
  • Inquire about the payment result
Receive asynchronous notifications
Inquire about the result

After payments

After completing the payment, you can perform the following actions:

Cancel a transaction

After the buyer places an order, you can close the transaction within a certain period by using the cancel API. For detailed instructions, refer to Cancel.

Revoke authorization

Once the buyer completes the authorization process, you are required to grant your buyer the ability to revoke authorization for the following reasons:
  • To empower the buyer with full control over their authorized agreements, enabling them to terminate the authorization relationship at any time based on their account security strategy or service usage requirements.
  • Certain payment methods impose system-level restrictions, which may limit a single e-wallet account to only one or a small number of valid authorization credentials with the same merchant.
For detailed instructions on implementing the authorization revocation, refer to Revoke authorization.

Refund

Different payment methods have varying refund capabilities. To learn about Antom refund rules and how to initiate a refund for a successful transaction, refer to Refund.

Reconciliation

After the transaction is completed, use the financial reports provided by Antom for reconciliation. For more information on how to reconcile and the settlement rules of Antom, refer to Reconciliation.

Best practices

Antom provides you with best practice solutions such as agreement-signing QR code optimization, client experience optimization, the display of payment results, payment-retry solution, and API timeout settings. For more details, refer to Best practices.

Features of payment methods

The table below shows which payment method returns the buyer login ID (userLoginId) after buyer authorization, and the example returned ID:
Payment method
Whether userLoginID is returned
Example
Yes
n_c***@hotmail.com
186XXXXXX21
Yes
852-66****37
Yes
63-********90
Yes
62-**********06
Yes
601*******32
Yes
gm****ina@naver.com
Yes
+66*****4713
Yes
T1mNO****yDYJf
Yes
gksd******@naver.com
Yes
+4420****5666
Yes
+6394******9412
Yes
***ันทร์
No
TOSS
Yes
****7396