D
API Reference

Payment Webhook

POST /api/webhook/payment-notification — menerima payment status dari DazoApp, kirim WhatsApp. Route protected JWT/IP umum, belum ada signature atau idempotency key.

POST /api/webhook/payment-notification menerima payment status dari DazoApp lalu mengirim notifikasi WhatsApp ke customer.

POST /api/webhook/payment-notification

Handler: controllers/webhookController.js — handlePaymentNotification

Auth: JWT Bearer wajib (atau IP allowlist bypass) — route saat ini protected oleh middleware JWT/IP umum

Request

FieldWajibFungsi
order_numberYaOrder ID
payment_statusYaStatus: paid, expired, failed
customer_phoneYaNomor WhatsApp customer
customer_nameTidakNama customer
total_amountTidakTotal pembayaran
device_idYaDevice WhatsApp
store_idYaTenant scope

Contoh request

json
{
  "order_number": "ORD-001",
  "payment_status": "paid",
  "customer_phone": "628123456789",
  "customer_name": "Budi",
  "total_amount": 150000,
  "device_id": "device-1",
  "store_id": "store-1"
}

Valid status

StatusBehavior
paidBatalkan follow-up tertunda, load order/store, kirim ringkasan dan link digital bila tersedia
expiredKirim pesan link kedaluwarsa
failedKirim pesan pembayaran gagal

Response

WhatsApp delivery failure tetap menghasilkan HTTP 200 agar webhook dianggap diterima oleh DazoApp.

Kontrak dengan DazoApp

text
DazoApp update database
  -> DazoApp callback Engine Bot
  -> POST /api/webhook/payment-notification
  -> Engine Bot cancel follow-up
  -> Engine Bot load order/store/device
  -> Engine Bot send WhatsApp notification

Security requirements (belum diterapkan)

Sebelum production-hardening dianggap selesai:

  • Gunakan signature atau dedicated credential untuk callback DazoApp ke Engine Bot
  • Cocokkan store_id, order, device, amount, dan customer dengan record database
  • Tambahkan idempotency key/event ID
  • Jangan mempercayai callback payload untuk link digital tanpa order lookup terverifikasi
  • Tambahkan retry/outbox untuk notification delivery

Kembali ke