Virtual Account H2H (SNAP)
Introduction
💡 Tip: Please watch this video tutorial for the complete integration workflow.
Definition of SNAP Virtual Account
SNAP Virtual Account (SNAP VA) is an API-based service that allows partners to programmatically create, check status, and delete Virtual Accounts. It enables structured payment processes aligned with the national system.
Purpose of the Integration
The purpose of integrating with YUKK SNAP VA is to generate Virtual Account (VA) numbers that can be used by end-users as a payment channel. Through this integration, partners can:
- Provide customers with unique Virtual Account numbers for making seamless payments.
- Ensure Virtual Account creation, query, and deletion follow standardized SNAP BI specifications.
- Guarantee that Virtual Account payment statuses (such as paid, unpaid, expired, or canceled) are fully synchronized with the payment system.
- Streamline reconciliation and financial settlement processes with YUKK as the acquirer.
Key Parties Involved
- Merchant/Partner: Integrates SNAP VA APIs to create, inquire, and delete Virtual Accounts, while also managing financial reconciliation and the end-user payment experience.
- Acquirer/YUKK: Provides the payment gateway backend to manage Virtual Accounts, perform real-time status checks, route payments, and ensure secure and reliable transactions.
Main API Functions
| API Name | Description |
|---|---|
| Create VA | Generate a new Virtual Account for payment, with necessary details such as VA number, merchant info, validity period, etc. |
| Inquiry VA Status | Checks the real-time status of a Virtual Account to determine if it has been paid, is still active, invalid, or expired. |
| Delete / Cancel VA | Used to programmatically cancel or delete an active Virtual Account that is still in a pending/unpaid status. |
Pre-Integration Steps
Here are the steps before you access Yukk Payment Gateway API collection:
- Get your company information registered to our system by our Activation Team.
- Receive your client credentials (
Client ID,Client Secret, andMIDfrom our Activation Team). - Use your issued credentials to request a B2B
Access_Tokenfrom our Authentication API. This activeAccess_Token, alongside yourMID, will be used to authorize and gain secure access to all subsequent transaction APIs within this collection.
Flow Process
Integration Process
This section details the steps to go live, the functional use cases, and the technical sequence flow of the Virtual Account SNAP

Use Case Diagram
The following use case diagram illustrates the interaction between the main actors (Merchant and End User/Customer) with the YUKK system.
- Merchant integrates with YUKK to create, inquire, and cancel VAs, and receive payment notifications.
- End User (Customer) receives a VA number from the merchant and makes payment through available channels.
This diagram provides a high-level view of how the actors and YUKK system components communicate during the Virtual Account payment process.

Sequence Diagram
To provide a clearer understanding of the interaction flow within the SNAP Virtual Account integration, the following Sequence Diagram illustrates the end-to-end process from creating a Virtual Account to cancellation.

Sequence Diagram Process Description
| No | Process Name | Description |
|---|---|---|
| 1 | Request Create VA | The merchant sends a request to create a Virtual Account to YUKK. |
| 2 | Return VA Number | YUKK returns the Virtual Account number that has been successfully created to the merchant. |
| 3 | Initiate Payment to VA | The user makes a payment to the provided Virtual Account number. |
| 4 | Send Payment Notification | YUKK sends the payment status notification to the merchant after receiving the transaction result from the internal system.The merchant receives the payment status (success/failed) from YUKK. |
| 5 | Notify Payment Status | The merchant receives the payment status (success/failed) from YUKK. |
| 6 | Request Cancel VA | The merchant submits a request to cancel the VA to YUKK (only if the VA status is still waiting/pending). |
| 7 | Confirm Cancellation Success | YUKK provides confirmation that the Virtual Account has been successfully canceled. |
Base URL
YUKK Virtual Account SNAP provides two distinct environments to facilitate a secure development lifecycle. These include Staging for testing and Production for live commercial transactions. Please ensure that you configure the correct Base URL corresponding to your current integration phase to prevent connection and compatibility issues.
💡 YUKK VA SNAP Staging Base URL
https://sandbox.yukk.co
💡 YUKK VA SNAP Production Base URL
https://api.yukk.co
Format Type
This section provides explanations of the supported field requirement levels and data types along with their descriptions and examples. Each field in the API specification is associated with a specific format type to ensure consistency and proper validation.
Field Requirement Levels
Each field may be classified as Mandatory, Optional, or Conditional depending on the use case.
| Type | Name | Description |
|---|---|---|
| (M) | Mandatory | The field must always be provided. |
| (O) | Optional | May or may not be provided. |
| (C) | Conditional | Required only in specific cases. |
Data Types
Each request and response field is also assigned a data type that defines the expected input format.
| Type | Description | Example |
|---|---|---|
| String | Alphanumeric | "Yukk Indonesia" |
| Integer | Whole numbers | 100 |
| Decimal | Numeric values with decimal | 99.99 |
| Boolean | Logical values | true / false |
| DateTime | Timestamp in ISO 8601 format | 2023-09-15T10:30:00 |
Integration Guides & Resources
To support the SNAP VA integration process, YUKK provides the following materials to help partners and developers understand the integration flow, API implementation, testing procedures, and troubleshooting guidelines for functionality and developer site testing.
💡 Link Guidebook SNAP QRIS:
Authentication for VA SNAP
To ensure secure and authorized access, YUKK utilizes digital signatures to validate every API request. These signatures are divided into two types based on their request function:
Used to secure the initial client credential exchange process to obtain a B2B Access Token. This digital signature is generated using your private key and validated by YUKK using your registered public key.
🔗 Visit our Asymmetric Signature Guide ↗
Used to sign and access all API services. This digital signature secures your payloads by hashing transaction data using your client secret and active access token.
🔗 Visit our Symmetric Signature Guide ↗
Virtual Account SNAP
Virtual Account SNAP is an API service for Virtual Accounts. This API helps partners create Virtual Accounts, inquiry status, and delete Virtual Accounts directly from the system.
POST Access Token
Get Access Token (B2B)
🌐 Endpoint URL to obtain the B2B Access Token
{{authBaseUrl}}/auth/openapi/v1.0/access-token/b2b
Use this API to obtain B2B accessToken, which should be included in all headers of Virtual Account API Collection.
| Service code | 73 |
|---|---|
| API Name | API Access Token B2B |
| Version | 1.0 |
| HTTP Method | POST |
| Path | ../{version}/access-token/b2b |
| Content Type | application/json |
Request Header
| Field | Type | Description |
|---|---|---|
| Content-Type | String (M) | Content type, value always “application/json” |
| User-Agent | String (M) | User-Agent is determined by the client environment/library |
| X-TIMESTAMP | String (M) | Transaction date time, in format YYYY-MM-DDTHH:mm:ss+07:00. Time must be in GMT+7 (Jakarta time) format ISO8601 without milliseconds. |
| X-CLIENT- KEY | String (M) | Use client_id was generated by YUKK |
| X-SIGNATURE | String (M) | Asymmetric signature generated automatically using SHA256withRSA with your Private_Key as the key. Formula: stringToSign = client_ID + “I” + XTIMESTAMP |
Request Body
| Field | Attribute (MOC) | Type | Description |
|---|---|---|---|
| grantType | (M) | String | “client_credentials” |
| additionalInfo | (M) | Object | |
| scope | (M) | String | "yukk.payment-gateway" |
Response Headers
| Accept | application/json |
| Content-Tye | application/json |
| X-CLIENT-KEY | 583733826598333528123456 |
| X-TIMESTAMP | 2025-02-25T15:25:31+07:00 |
| X-SIGNATURE | vp74/K7mrRVLjOEDB |
| Scope | yukk.payment-gateway |
Response Body
{
"grantType": "client_credentials",
"additionalInfo": {
"scope": "yukk.payment-gateway"
}
}
Request Sample
//Get Access Token (B2B)
curl --location -g '{{authBaseUrl}}/auth/openapi/v1.0/access-token/b2b' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--header 'X-CLIENT-KEY: {{clientId}}' \
--header 'X-TIMESTAMP;' \
--header 'X-SIGNATURE;' \
--header 'scope: yukk.payment-gateway' \
--data '{
"grantType": "client_credentials",
"additionalInfo": {
"scope": "yukk.payment-gateway"
}
}'
Response Sample
- Body
- Header (16)
//200 OK
{
"responseCode": "2007300",
"responseMessage": "Successful",
"accessToken": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiI5NTExZDY2My1kOGU3LTQzNWQtYWZiNC00YmNmMzA0N2I1YmciLCJqdGkiOiI4ZTNmMTcwMWM2NTRhNzc5ZTJlMjkwMWE4M2FhOTFmYmQ0ZDE2M2JhYWRkZmE2NGFmYzQyYTQyZmVjNGRjNzBhN2E1ZDViMjFkZjJjY2EwMCIsImlhdCI6MTc3NjI0NjU2Ny41MDk1MDksIm5iZiI6MTc3NjI0NjU2Ny41MDk1MTQsImV4cCI6MTc3NjI0NzQ2Ny40OTMyOTIsInN1YiI6IiIsInNjb3BlcyI6WyJ5dWtrLnBheW1lbnQtZ2F0ZXdheSJdfQ.nJAGBVEMuRr5GzXe4Qb3gqYAb_okHX_UUe8RUd6RvNTcdevpUJ6otCgozafV7EJOP9-3LhSrQBIhRWDK1AVT-pzbU4Becu5hdaD9XDYB6yYKy8y5jVHMQW9ybkY0hg4iaMT8Fx3129G1ozjXPM-hN7MeHlROfFEGO4DjzLLXtPEjacL9qI6viBiLJtRZOkuS7bsF3T7U0c7lttIXHIRO058HSkMyKZ-IoPjN8Z9eI_9Ie4IHY5yLO06kygUxUoUkQBkg-k_L6Y38PBncGIabQypqIwseBqdJlPx_8f75oyi9x9_8mAUg945wOMxH7qkCZiO-h5mxb9OcqR3wCSmuofKkaGSnQUcRpNve_r9XIM0ZO1jQEX-cEtZW8ePaS_yINcJzieA1dswEpiLWGMr2vMHkhwAtH-aiwhaiWe4bbZdWgCEmHjgao0pl6JvNTW6I6iwL_X6EUqyUGLZlQc3G8tDiMN6pGzTsQwGm0UEoSsY_tJ85tefcOEZJVvVkaP1wR3UxZON6iQ4377rlCArqj-lfmwD-dl9EG7Ru5GKTr_bSgVfDQJTuoNeCYrAF0BVGfrP9IKx8u5gVAHXMsNWxb7nWgbvWWpJH3OpuUFr3Ydyt4IXvkbKDk3rUzmxrCCSDxawc1laxBFRJRyuAGuBxTY8Ay8gvUkEEAu7DTUlBpRQ",
"tokenType": "Bearer",
"expiresIn": "900",
"additionalInfo": {
"scope": "yukk.payment-gateway"
}
}
| Server | nginx |
| Date | Wed, 15 Apr 2026 09:49:27 GMT |
| Content-Type | application/json |
| Transfer-Encoding | chunked |
| Connection | keep-alive |
| X-Powered-By | PHP/8.3.8 |
| X-TIMESTAMP | 2026-04-15T09:49:23+07:00 |
| X-CLIENT-KEY | 9511d663-d8e7-435d-afb4-4bcf3047b5bg |
| Cache-Control | private, must-revalidate |
| pragma | no-cache |
| expires | 1 |
| X-RateLimit-Limit | 60 |
| X-RateLimit-Remaining | 58 |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| X-XSS-Protection | 1; mode=block |
POST Create Virtual Account
The Virtual Account type (Fixed or Dynamic) is configured during onboarding. The system automatically applies the configured type, so no additional request parameter is required to specify the type.
🌐 Endpoint URL to generate a Virtual Account
{{baseUrl}}/payment-gateway/openapi/v1.0/transfer-va/create-va
This API allows you to create/generate the Virtual Account number. There are two types of Virtual Accounts available under this API:
- Fixed Type: A fixed 16 digit virtual account number where the first 5 digit is bank code, the next 3 digit is YUKK code, and the last 8 digit is your merchant code (customable). Use a Fixed VA if you require a predefined, reusable Virtual Account number for a specific customer.

- Dynamic Type: A Virtual Account number automatically generated by system. Use a Dynamic VA if the account number should be generated dynamically per transaction.
Specification Request
The following table is a specification of this API:
| Service code | 73 |
|---|---|
| API Name | API Create Virtual Account |
| Version | 1.0 |
| HTTP Method | POST |
| Path | ../openapi/{version}/transfer-va/create-va |
| Content Type | application/json |
Request Header
The following table is a header of request parameter:
| Field | Type | Description |
|---|---|---|
| Content-Type | String (M) | Content type, value always “application/json” |
| User-Agent | String (M) | User-Agent depend on library |
| Authorization | String (M) | Bearer “accessToken” |
| X-TIMESTAMP | String (M) | Transaction date time, in format YYYY-MM-DDTHH:mm:ss+07:00. Time must be in GMT+7 (Jakarta time) format ISO8601 without milliseconds. |
| X-SIGNATURE | String (M) | Symmetric signature generated automatically using HMAC_SHA512 with your clientSecret as the key. Formula: stringToSign = HTTPMethod+”:“+ EndpointUrl +":"+ AccessToken +":“+ Lowercase(HexEncode(SHA256(minify(RequestBody))))+ ":“ +TimeStamp |
| X-PARTNER-ID | String (36) (M) | Using client ID |
| X-EXTERNAL-ID | String (36) (M) | Reference ID that is self-generated by the merchant, unique for each transaction (numeric string). Numeric string, must be unique per day. |
| CHANNEL-ID | String (5) (M) | 00003 |
Request Body
The following table is a body of request parameter:
| Field | Type | Description |
|---|---|---|
| partnerServiceId | String (8) (M) | Derivative of X-PARTNER-ID, similar to company code |
| customerNo | String (8) (M) | Unique number (up to 20 digits). |
| virtualAccountNo | String (28) (C) | Virtual Account Number ex: 9772269408126292 Mandatory for Fixed Type Optional for Dynamic Type |
| virtualAccountName | String (100) (M) | Name of Virtual Account |
| virtualAccountEmail | String (100) (M) | Email for Virtual Account |
| virtualAccountPhone | String (20) (M) | Virtual Account Phone Number |
| trxId | String (64) (M) | Transaction ID |
| totalAmount | Object | |
| value | String (ISO4217) (M) | Number of amount |
| currency | String (3) (M) | IDR |
| expiredDate | String (25) (O) | Format: ISO-8601 (ex: 2020-12- 31T23:59:59 -07:00) Ref: expires_in |
| additionalInfo | Object | |
| mid | String (500) (M) | Merchant ID |
| requestTime | Timestamp (M) | Payment request time |
| paymentChannelCode | String (50) (M) | Payment channel code of choice (ex: VA_BCA) |
| notificationUrl | String (255) (M) | The secure endpoint (webhook) URL registered by the Partner to receive payment notifications from YUKK. For detailed payload structures and specifications, please refer to the Webhook Payment Notification ↗ |
| shippingFee | String (ISO4217) (O) | Shipping fee amount |
| notes | String (255) (O) | Additional notes |
| billing | Object | |
| name | String (100) (O) | Billing name |
| phone | String (20) (O) | Billing phone |
| String (100) (O) | Billing email | |
| address | String (255) (O) | Billing address |
| city | String (100) (O) | Billing city |
| state | String (100) (O) | Billing state |
| country | String (100) (O) | Billing country |
| postal code | String (5) (O) | Billing postal code |
Request Sample
//Create Response
curl --location -g '{{baseUrl}}/payment-gateway/openapi/v1.0/transfer-va/create-va' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer {{accessToken}}' \
--header 'X-TIMESTAMP:' \
--header 'X-SIGNATURE:' \
--header 'X-PARTNER-ID: {{clientId}}' \
--header 'X-EXTERNAL-ID: 1777455656' \
--header 'CHANNEL-ID: 00003' \
--data-raw '{
"partnerServiceId": "12345",
"customerNo": "10011212",
"virtualAccountNo": "9912304000008328",
"virtualAccountName": "Mutia",
"virtualAccountEmail": "mutia.azizah@yukk.me",
"virtualAccountPhone": "621313131313",
"trxId": "SNAP-TEST238",
"totalAmount": {
"value": "5000.00",
"currency": "IDR"
},
"expiredDate": "",
"additionalInfo": {
"mid": "{{mid}}",
"requestTime": "",
"paymentChannelCode": "VA_BRI",
"notificationUrl": "https://webhook.site/0f1f8408-cde7-45c2-bc24-956416c0f6ea",
"notes": "",
"shippingFee": "",
"billing": {
"name": "",
"phone": "",
"email": "",
"address": "",
"city": "",
"state": "",
"country": "",
"postalCode": ""
}
}
}'
Sample Response
- Body
- Header (16)
//200 OK
{
"responseCode": "2002700",
"responseMessage": "Successful",
"virtualAccountData": {
"partnerServiceId": "1234565591099775",
"customerNo": "10011212",
"virtualAccountNo": "1234565591099775",
"virtualAccountName": "Mutia",
"virtualAccountEmail": "mutia.azizah@yukk.me",
"virtualAccountPhone": "621313131313",
"trxId": "SNAP-TEST238",
"totalAmount": {
"value": "5000.00",
"currency": "IDR"
},
"expiredDate": "2026-04-16T16:52:48+07:00",
"additionalInfo": {
"transactionCode": "PGWTS20260415226292607",
"requestTime": "2026-04-15T16:52:46+07:00",
"paymentChannelCode": "VA_BRI"
}
}
}
| Server | nginx |
| Date | Wed, 15 Apr 2026 09:52:49 GMT |
| Content-Type | application/json |
| Transfer-Encoding | chunked |
| Connection | keep-alive |
| X-Powered-By | PHP/8.3.8 |
| Cache-Control | private, must-revalidate |
| pragma | no-cache |
| expires | 1 |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| Content-Security-Policy-Report-Only | default-src 'self'; report-uri /csp-report-endpoint; |
| Referrer-Policy | strict-origin-when-cross-origin |
| Set-Cookie | Path=/; HttpOnly; Secure |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload |
| X-XSS-Protection | 1; mode=block |
Webhook Payment Notification
Upon successful payment, YUKK will automatically send a secure, signed HTTP POST notification to the Partner's Webhook URL, which must be explicitly provided via the notificationUrl parameter in the request payload during Virtual Account creation.
Request Header
| Field | Type | Description |
|---|---|---|
| Content-Type | String (M) | Content type, value always “application/json” |
| Signature | String (M) | openssl_digest(client_secret+order_id+pmt_channel_code+amount+status, ‘sha512’) |
Request Body
| Field | Type | Description |
|---|---|---|
| code | String | Yukk transaction code |
| order_id | String | Partner transaction code |
| grand_total | Integer | Total amount to be paid |
| customer_name | String | Customer full name |
| customer_phone | String | Customer phone number |
| customer_email | String | Customer email |
| request_at | Datetime | Payment request time Format: YYYY-MM-DD hh:mm:ss |
| paid_at | Datetime | Payment paid time Format: YYYY-MM-DD hh:mm:ss |
| notes | String | Other notes if necessary |
| status | String | Payment status that will be sent to notification url SUCCESS/FAILED |
| merchant_branch | Object | |
| name | String | Merchant name |
| payment_channel | Object | |
| code | String | Payment channel code |
| name | String | Payment channel code |
| image_url | String | |
| category | Object | |
| code | String | Payment category code |
| name | String | Payment category name |
| va | Object | |
| type | String | Type of VA (Fixed/Dymanic) |
| expired_in | String | Timeout session in seconds |
| account_id | String | ID account |
Request Sample
{
"code": "PGWTS20251203391946875",
"order_id": "Testing-1764738424",
"grand_total": 10000,
"customer_name": "Mutia test",
"customer_phone": "6287881253722",
"customer_email": "tiiaazizah@gmail.com",
"request_at": "2025-12-03 12:07:04",
"paid_at": null,
"notes": null,
"status": "EXPIRED",
"merchant_branch": {
"name": "PG Activation 13a branch"
},
"payment_channel": {
"code": "VA_BCA",
"name": "Virtual Account BCA",
"image_url": "http://localhost/storage/images/payment-channels/va-bca.png",
"category": {
"code": "VIRTUAL_ACCOUNT",
"name": "Virtual Account"
}
},
"va": {
"type": "FIXED_OPEN",
"expires_in": 86400,
"account_id": "01101234"
}
}
Headers
| Accept | application/json |
| Authorization | Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiJ9.eyJhdWQiOiI5NTExZDY2My1kOGU3LTQzNWQtYWZiNC00YmNmMzA0N2I1YmciLCJqdGkiOiI5OWNhOGY3NTg4NzQ4NzhhOWQ4ZGZkMmU1YmJhNmRiNWZjYTgwMzc2OGZiNTkzMGI2MWRlMjAzMzFmNmMxMWRkNGIyNjVkZWUxNmFjM2I1OSIsImlhdCI6MTc3NjA0OTE3My40Mjc5MjUsIm5iZiI6MTc3NjA0OTE3My40Mjc5MywiZXhwIjoxNzc2MDUwMDczLjQxMzU5NCwic3ViIjoiIiwic2NvcGVzIjpbInl1a2sucGF5bWVudC1nYXRld2F5Il19.zgSkBUmY6S22jBRTAUJQdFVjA3MsHU5h2hu_WBRPMFHdTTk05Ic0N5jcs1x2DrEQEOlPLE01Vae99hEgQG4ipA5EYI7PzwCPpY_RVgfeACsMCV4OVztKg3I8uK1AuYxEBj5KpqpkGbgogvLv8NbwjOmjx4n5spgPw4cfTxTLlI1WCL4XGIMgGN_6ictpaRaqLA11EaMJDGGhHKDwcY1od4YSqjkQpJmkF7n88mVv31a-DSu1W430LRb4QE-biuHmozzxzh-MvNGbmpQR3HVeKXlX76lsUqQrNX0507oK3hBUMhqXEFOr98jRwtyLBrdYL2w6vr6MNC-bOH3GUEVvMA_CaDnZ7rS0sWc4W8HsYPOyNqGErO2IyPnKWQfIGaqwCh5UefjvPDcup_5tZZ5LJiFa33GxXMeydfl5F_I5D0qh1c0Hjk2Nv25gobisMfp1naD9_t-vZZ5qduImfuE-lQGahddoy6ThVvXi0tn6E2MupaE4CLH7rvzF1uauW7MvmLLl8kC3sjwopkTPbPx8PzhPYmPpSMcPXPzcKrLYHljci4v4mAaeag82iL1zLzoi34ii65j0WSCq92a0mpWbcx5ldO7Dqh0O216y6EB8vZYncMqWjgKSWCzCWfXWOyUS7YAaYflVIDXzgbWPhoSfNb-TUcf0SeSSy0JxSCkYb3A |
| X-TIMESTAMP | 2026-04-13T10:04:43+07:00 2025-03-21T14:00:00+07:00 |
| X-SIGNATURE | QDCcLcq0f0SDbvJF32smt0eBps5Ljx5iQjTX8cGjLmRxyiO/Z42YHprg7u48wX0mFM2l56DA0Qv3srGfb6JEEg== 8IHImeSBlzdRKjQw11Y+2hZYRmiY/hIALnN1O8ykTIot123456lnzeNmwnl5+O9Qro5eEyRCEt+3MwjW7TeA3A== |
| X-PARTNER-ID | 6723d663-d8e7-435d-afb4-4bcf3047b5bg 1234d85b65bc3c437ffead1e28123466 |
| X-EXTERNAL-ID | 20260413T1004430700 |
| CHANNEL-ID | 00003 |
Body raw (json)
//200 OK
{
"partnerServiceId": "12345",
"customerNo": "10011212",
"virtualAccountNo": "9912304000008328",
"virtualAccountName": "Mutia",
"virtualAccountEmail": "mutia.azizah@yukk.me",
"virtualAccountPhone": "621313131313",
"trxId": "SNAP-TEST238",
"totalAmount": {
"value": "5000.00",
"currency": "IDR"
},
"expiredDate": "",
"additionalInfo": {
"mid": "{{mid}}",
"requestTime": "",
"paymentChannelCode": "VA_BRI",
"notificationUrl": "https://webhook.site/0f1f8408-cde7-45c2-bc24-956416c0f6ea",
"notes": "",
"shippingFee": "",
"billing": {
"name": "",
"phone": "",
"email": "",
"address": "",
"city": "",
"state": "",
"country": "",
"postalCode": ""
}
}
}
POST Inquiry Status Virtual Account
🌐 Endpoint URL to check Virtual Account status
{{baseUrl}}/payment-gateway/openapi/v1.0/transfer-va/status
This API is used to check the real-time transaction status of a Virtual Account by providing the unique transaction identifiers in the request body. Below is the mapping of transaction status codes returned in the response:
| Code | Status | Notes |
|---|---|---|
| 00 | SUCCESS | Transaction Success |
| 03 | PENDING | Payment initiated but not yet settled |
| 05 | CANCELED | Cancel transaction when status PENDING/WAITING |
| 06 | FAILED | Transaction rejected |
| 08 | EXPIRED | Transaction has exceeded valid time limit. |
Specification Request
The following table is a specification of this API:
| Service code | 26 |
|---|---|
| API Name | API Inquiry Status Virtual Account |
| Version | 1.0 |
| HTTP Method | POST |
| Path | ../openapi/{version}/transfer-va/status |
| Content Type | application/json |
Request Headers
| Field | Type | Description |
|---|---|---|
| Content-Type | String (M) | Content type, value always “application/json” |
| User-Agent | String (M) | User-Agent depend on library |
| Authorization | String (M) | Bearer “accessToken” |
| X-TIMESTAMP | String (M) | Transaction date time, in format YYYY-MM-DDTHH:mm:ss+07:00. Time must be in GMT+7 (Jakarta time) format ISO8601 without milliseconds. |
| X-SIGNATURE | String (M) | Symmetric signature generated automatically using HMAC_SHA512 with your clientSecret as the key. Formula: stringToSign = HTTPMethod+”:“+ EndpointUrl +":"+ AccessToken +":“+ Lowercase(HexEncode(SHA256(minify(RequestBody))))+ ":“ +TimeStamp |
| X-PARTNER-ID | String (M) | Using client ID |
| X-EXTERNAL-ID | String (M) | Reference ID that is self-generated by the merchant, unique for each transaction (numeric string). Numeric strings must be unique per day. |
| CHANNEL-ID | String (M) | 00003 |
Request Body
| Field | Type | Description |
|---|---|---|
| partnerServiceId | String (8) (M) | Derivative of X-PARTNER-ID, similar to company code |
| customerNo | String (8) (M) | Unique number (up to 20 digits). |
| virtualAccountNo | String (28) (M) | Virtual Account Number ex: 9772269408126292 |
| inquiryRequestId | String (64) (C) | Required if TransactionCode not fill |
| additionaInfo | Object | |
| mid | String (500) (M) | Merchant ID |
| transactionCode | String (100) (C) | Code of the transaction Required if InquiryRequestId not fill |
Specification Response
The following part will be describe about parameter of response in this API:
Response Headers
| Accept | application/json |
| Authorization | Bearer {{accessToken}} |
| X-TIMESTAMP | 2025-02-25T15:25:31+07:00 |
| X-SIGNATURE | vp74/K7mrRVLjOEDB |
| X-PARTNER-ID | 583733826598333528123456 |
| X-EXTERNAL-ID | 1777455656 |
| CHANNEL-ID | 00003 |
Body raw (json)
{
"partnerServiceId": "12345",
"customerNo": "10011212",
"virtualAccountNo": "",
"inquiryRequestId": "",
"additionalInfo": {
"mid": "{{mid}}",
"transactionCode": ""
}
}
Sample Request
//Status Response
curl --location -g '{{baseUrl}}/payment-gateway/openapi/v1.0/transfer-va/status' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer {{accessToken}}' \
--header 'X-TIMESTAMP: 2025-02-25T15:25:31+07:00' \
--header 'X-SIGNATURE: vp74/K7mrRVLjOEDB' \
--header 'X-PARTNER-ID: 583733826598333528123456' \
--header 'X-EXTERNAL-ID: 1778126014' \
--header 'CHANNEL-ID: 00003' \
--data '{
"partnerServiceId": "12345",
"customerNo": "10011212",
"virtualAccountNo": "9772269408126292",
"inquiryRequestId": "",
"additionalInfo": {
"mid": "eyJpdiI6IkNydnBWcVR0akJjZlA3Z2Q3bUVuUWc9PSIsInZhbHVlIjoiRU1FSkJRRXNCcE1Vek5Hd1pTcUVoQVNwNE15Mk5Wemo4ZTR1UExLU1FiNWU5amNxbUwrUk9tWnBiTnkzbGI3cEpzNHNhUU9idFJabisyR1hmOTY5UmRtMVVrN3RNNUwzOWVQOGQ5YnpYTjQ9IiwibWFjIjoiODI1Yjg3OGQ3OTAzYTZhMGRlNmYwNjY0NzA1ZTlhOTQyM2M5NmZlYTA4MTg2MGJiNTk3YjAxOTI0M2UwZTM0ZCIsInRhZy123456",
"transactionCode": "MU165-99991"
}
}'
Sample Response
- Body
- Headers
//200 OK
{
"responseCode": "2002600",
"responseMessage": "Successful",
"virtualAccountData": {
"partnerServiceId": "1234565591099775",
"customerNo": "10011212",
"virtualAccountNo": "1234565591099775",
"inquiryRequestId": "SNAP-TEST238",
"totalAmount": {
"value": "5000.00",
"currency": "IDR"
},
"trxDateTime": "2026-04-15T16:52:48+07:00",
"transactionDate": ""
},
"additionalInfo": {
"transactionCode": "PGWTS20260415226292607",
"requestTime": "2026-04-15T16:52:46+07:00",
"paymentChannelCode": "VA_BRI",
"latestTransactionStatus": "03",
"transactionStatusDesc": "pending"
}
}
| Server | nginx |
| Date | Wed, 15 Apr 2026 09:53:29 GMT |
| Content-Type | application/json |
| Transfer-Encoding | chunked |
| Connection | keep-alive |
| X-Powered-By | PHP/8.3.8 |
| Cache-Control | private, must-revalidate |
| pragma | no-cache |
| expires | -1 |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| Content-Security-Policy-Report-Only | default-src 'self'; report-uri /csp-report-endpoint; |
| Referrer-Policy | strict-origin-when-cross-origin |
| Set-Cookie | Path=/; HttpOnly; Secure |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload |
| X-XSS-Protection | 1; mode=block |
POST Delete Virtual Account
🌐 Endpoint URL to delete a Virtual Account
{{baseUrl}}/payment-gateway/openapi/v1.0/transfer-va/delete-va
This endpoint is used to cancel the virtual account transaction that still on waiting/pendingstatus. The HTTP DELETE request is sent to the specified URL with the required parameters in the request body.
Specification Request
The following table is a specification of this API:
| Service code | 31 |
|---|---|
| API Name | API Delete Virtual Account |
| Version | 1.0 |
| HTTP Method | DELETE |
| Path | ../openapi/{version}/transfer-va/delete-va |
| Content Type | application/json |
Request Header
The following table is a header of request parameter:
| Field | Type | Description |
|---|---|---|
| Content-Type | String (M) | Content type, value always “application/json” |
| User-Agent | String (M) | User-Agent depend on library |
| Authorization | String (M) | Bearer “accessToken” |
| X-TIMESTAMP | String (M) | Transaction date time, in format YYYY-MM-DDTHH:mm:ss+07:00. Time must be in GMT+7 (Jakarta time) format ISO8601 without milliseconds. |
| X-SIGNATURE | String (M) | Symmetric signature generated automatically using HMAC_SHA512 with your clientSecret as the key. Formula: stringToSign = HTTPMethod+”:“+ EndpointUrl +":"+ AccessToken +":“+ Lowercase(HexEncode(SHA256(minify(RequestBody))))+ ":“ +TimeStamp |
| X-PARTNER-ID | String (M) | Using client ID |
| X-EXTERNAL-ID | String (M) | Reference ID that is self-generated by the merchant, unique for each transaction (numeric string). Numeric string, must be unique per day. |
| CHANNEL-ID | String (M) | 00003 |
Request Body
The following table is a body of request parameter:
| Field | Type | Description |
|---|---|---|
| partnerServiceId | String (8) (M) | Derivative of X-PARTNER-ID, similar to company code |
| customerNo | String (8) (M) | Unique number (up to 20 digits). |
| virtualAccountNo | String (28) (M) | Virtual Account Number ex: 9772269408126292 |
| trxId | String (64) (M) | Transaction ID |
| additionalInfo | Object (O) | |
| mid | String (500) (M) | Merchant ID |
| transactionCode / trxId | String (100) (C) | Use either trxId (provider) or transactionCode (Yukk) as the reference. |
Specification Response
The following part will be describe about parameter of response in this API:
Response Header
| Accept | application/json |
| Authorization | Bearer {{accessToken}} |
| X-TIMESTAMP | 2025-02-25T15:25:31+07:00 |
| X-SIGNATURE | vp74/K7mrRVLjOEDB |
| X-PARTNER-ID | 583733826598333528123456 |
| X-EXTERNAL-ID | 1777455656 |
| CHANNEL-ID | 00003 |
Body raw (json)
{
"partnerServiceId": "12345",
"customerNo": "10011212",
"virtualAccountNo": "",
"trxId": "",
"additionalInfo": {
"mid": "{{mid}}",
"transactionCode": ""
}
}
Sample Request
//Delete Response
curl --location -g --request DELETE '{{baseUrl}}/payment-gateway/openapi/v1.0/transfer-va/delete-va' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer {{accessToken}}' \
--header 'X-TIMESTAMP: 2025-02-25T15:25:31+07:00' \
--header 'X-SIGNATURE: vp74/K7mrRVLjOEDB' \
--header 'X-PARTNER-ID: 583733826598333528123456' \
--header 'X-EXTERNAL-ID: 1778126014' \
--header 'CHANNEL-ID: 00003' \
--data '{
"partnerServiceId": "12345",
"customerNo": "10011212",
"virtualAccountNo": "1234565591099775",
"trxId": "SNAP-TEST238",
"additionalInfo": {
"mid": "{{mid}}",
"transactionCode": "PGWTS20260415226292607"
}
}'
Sample Response
- Body
- Headers [18]
//200 OK
{
"responseCode": "2003100",
"responseMessage": "Successful",
"virtualAccountData": {
"partnerServiceId": "1234565591099775",
"customerNo": "10011212",
"virtualAccountNo": "1234565591099775",
"trxId": "SNAP-TEST238"
},
"additionalInfo": {
"transactionCode": "PGWTS20260415226292607",
"requestTime": "2026-04-15T16:52:46+07:00",
"paymentChannelCode": "VA_BRI",
"latestTransactionStatus": "05",
"transactionStatusDesc": "canceled"
}
}
| Server | nginx |
| Date | Wed, 15 Apr 2026 09:55:43 GMT |
| Content-Type | application/json |
| Transfer-Encoding | chunked |
| Connection | keep-alive |
| X-Powered-By | PHP/8.3.8 |
| Cache-Control | private, must-revalidate |
| pragma | no-cache |
| expires | -1 |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| Content-Security-Policy-Report-Only | default-src 'self'; report-uri /csp-report-endpoint; |
| Referrer-Policy | strict-origin-when-cross-origin |
| Set-Cookie | Path=/; HttpOnly; Secure |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload |
| X-XSS-Protection | 1; mode=block |