Skip to main content
To configure your notification URL, please send your endpoint address along with your merchant and store information to technical.support@qfpay.com.
QFPay supports asynchronous notifications for:
  • Payments ("notify_type": "payment")
  • Refunds ("notify_type": "refund")
These notifications allow merchants to receive real-time updates on transaction results. Since parameters may expand in future versions, your integration should be able to gracefully handle unknown fields.

Overview

When a payment or refund is completed, QFPay will POST a JSON-formatted notification to the merchant-defined callback URL.
It is strongly recommended to verify the status of a transaction using the Transaction Enquiry API in addition to handling the callback.

Notification Rules

  1. Only successful payments and refunds will trigger a notification.
  2. Please register your notification endpoint via email to technical.support@qfpay.com. Our team will configure it for you.
  3. Merchants must validate the notification using the signature verification process below. After successful verification, return:
    • HTTP Status Code: 200 OK
    • Response Body: SUCCESS
  4. If the expected response is not received, QFPay will retry the callback at the following intervals:
    • 2 minutes → 10 minutes → 10 minutes → 60 minutes → 2 hours → 6 hours → 15 hours
    • Retry stops after receiving 200 OK and SUCCESS
  5. One app_code + client_key pair can only be bound to one notification URL. Agents should use a shared endpoint for sub-merchants.
  6. Method: POST
    Content-Type: application/json
    Allowed Ports: 80 and 443 only (for security)

Signature Verification

The verification process differs from regular API requests.

Steps

  1. Extract the value from the X-QF-SIGN header.
  2. Concatenate the raw request body (JSON string) + your client_key.
  3. Generate an MD5 hash of this combined string.
  4. If the hash matches the X-QF-SIGN value, the message is valid. Return 200 OK with body SUCCESS.

Signature Example

Python
Sample Signature Output:

Notification Response Example


Response Field Reference


Cancel Field Definitions


Notification IP Addresses

Ensure your server allows POST requests from:
  • 13.228.112.115
  • 18.138.115.47
  • 18.166.202.92