generated: '2026-07-19' method: searched source: https://miniprogram.gcash.com/docs/miniprogram_gcash/mpdev/call_api docs: - https://miniprogram.gcash.com/docs/miniprogram_gcash/mpdev/call_api - https://miniprogram.gcash.com/docs/miniprogram_gcash/mpdev/v1_pay authentication: style: request signature (Client-Id + Request-Time + Signature headers) + OAuth2 user authorization ref: authentication/gcash-authentication.yml idempotency: supported: true mechanism: request-scoped idempotency key in the request body field: paymentRequestId scope: unique per merchant/partner; identifies and de-duplicates a payment order documented_as: >- "A unique ID generated by a merchant to identify a payment request. This field is used for idempotence control." (v1/payments/pay). The same pattern (a merchant-generated request id) governs refund via refundRequestId. fields: - operation: /v1/payments/pay key: paymentRequestId - operation: /v1/payments/refund key: refundRequestId source: https://miniprogram.gcash.com/docs/miniprogram_gcash/mpdev/v1_pay error_envelope: shape: >- Every response carries a `result` object with resultCode, resultStatus and resultMessage. resultStatus is one of S (success), A (accept / next action required), F (failed), U (unknown — inquire or await notification). fields: [result.resultStatus, result.resultCode, result.resultMessage] ref: errors/gcash-problem-types.yml request_tracing: request_time_header: Request-Time (ISO 8601, millisecond precision) client_id_header: Client-Id versioning: scheme: uri-path observed: [v1, v2] example: POST /v2/payments/pay, POST /v1/authorizations/applyToken rate_limit_signaling: documented: false note: not published on the public mini-program docs (partner-gated) webhooks: supported: true mechanism: merchant-supplied paymentNotifyUrl receives asynchronous payment notifications (notifyPayment) ref: asyncapi/gcash-payments-webhooks.yml