POST /api/webhook/payment-notification menerima payment status dari DazoApp lalu mengirim notifikasi WhatsApp ke customer.
POST /api/webhook/payment-notification
Handler: controllers/webhookController.js — handlePaymentNotification
Auth: JWT Bearer wajib (atau IP allowlist bypass) — route saat ini protected oleh middleware JWT/IP umum
Request
| Field | Wajib | Fungsi |
|---|---|---|
order_number | Ya | Order ID |
payment_status | Ya | Status: paid, expired, failed |
customer_phone | Ya | Nomor WhatsApp customer |
customer_name | Tidak | Nama customer |
total_amount | Tidak | Total pembayaran |
device_id | Ya | Device WhatsApp |
store_id | Ya | Tenant scope |
Contoh request
{
"order_number": "ORD-001",
"payment_status": "paid",
"customer_phone": "628123456789",
"customer_name": "Budi",
"total_amount": 150000,
"device_id": "device-1",
"store_id": "store-1"
}Valid status
| Status | Behavior |
|---|---|
paid | Batalkan follow-up tertunda, load order/store, kirim ringkasan dan link digital bila tersedia |
expired | Kirim pesan link kedaluwarsa |
failed | Kirim pesan pembayaran gagal |
Response
WhatsApp delivery failure tetap menghasilkan HTTP 200 agar webhook dianggap diterima oleh DazoApp.
Kontrak dengan DazoApp
DazoApp update database
-> DazoApp callback Engine Bot
-> POST /api/webhook/payment-notification
-> Engine Bot cancel follow-up
-> Engine Bot load order/store/device
-> Engine Bot send WhatsApp notificationSecurity requirements (belum diterapkan)
Sebelum production-hardening dianggap selesai:
- Gunakan signature atau dedicated credential untuk callback DazoApp ke Engine Bot
- Cocokkan
store_id, order, device, amount, dan customer dengan record database - Tambahkan idempotency key/event ID
- Jangan mempercayai callback payload untuk link digital tanpa order lookup terverifikasi
- Tambahkan retry/outbox untuk notification delivery
Kembali ke
- API Reference Index — daftar semua grup
- Instant Payment — detail DazoApp endpoints
- Order Flow — paid flow lengkap