Skip to content

Challenge Complete
internal

Request

Verify the results of a challenged authentication.

Security
BasicAuth
Path
keystringrequired

Unique short lived value generated by us and used as part of the redirect url path.

Headers
WP-Api-Versionstringrequired

The API version.

Value:"2026-10-01"
Example:2026-10-01
curl -i -X POST \
  -u '<username>:<password>' \
  'https://try.access.worldpay.com/3ds/challenges/{key}/complete' \
  -H 'WP-Api-Version: 2026-10-01'

Responses

The challenge was successful - obtain the authentication data for onward use.

Bodyapplication/json
outcomestringrequired

The outcome of the challenge complete request

Enum ValueDescription
3dsAuthenticated

Cardholder successfully authenticated by card issuer

3dsChallengeFailed

Failed cardholder challenge

3dsUnavailable

Authentication unavailable at this current time

Discriminator
versionstring, [ 1 .. 10 ] characters

The version of 3DS used to process the transaction.

ecistring, [ 1 .. 2 ] characters

Commerce Indicator (ECI). Indicates the outcome of the 3DS authentication.

ECIMeaning
02 or 05Fully Authenticated Transaction
01 or 06Attempted Authentication Transaction
00 or 07Non 3-D Secure Transaction
SchemeValue
Mastercard02, 01, 00
Visa05, 06, 07
Amex05, 06, 07
JCB05, 06, 07
Diners05, 06, 07
authenticationValuestring, [ 1 .. 64 ] characters

A cryptographic value that provides evidence of the outcome of a 3DS verification.

  • Visa - Cardholder Authentication Verification Value (CAVV)
  • Mastercard - Universal Cardholder Authentication Field (UCAF)
dsTransactionIdstring, [ 1 .. 64 ] characters

Directory server transaction ID, if provided should be used in the payment authorization authentication object.

cryptogramAlgorithmstring, [ 1 .. 99999 ] characters

Indicates the algorithm used to generate the cryptogram. Returned for Cartes Bancaires authentications only and must be applied in the following authorization request.

challengePreferencestring, [ 1 .. 64 ] characters

Indicates the preferred challenge behavior. Returned for Cartes Bancaires authentications only and must be applied in the following authorization request.

  • noPreference
  • noChallengeRequested
  • challengeRequested
  • challengeMandated
authenticationFlowstring, [ 1 .. 64 ] characters

Indicates which flow the customer has been directed to. Returned for Cartes Bancaires authentications only and must be applied in the following authorization request.

Enum:"challenge""frictionless"
statusReasonstring, [ 1 .. 2 ] characters

Provides further information relating to the outcome of the authentication. Returned for failed authentications only. Returned for Cartes Bancaires authentications only.

cancellationIndicatorstring, [ 0 .. 2 ] characters

An indicator as to why the authentication was cancelled. Returned for Cartes Bancaires authentications only.

  • 01 - Cardholder selected cancel
  • 02 - Reserved for future use
  • 03 - Authentication timed out
  • 04 and 05 - Authentication timed out at ACS provider
  • 06 - Transaction error
  • 07 - Unknown
  • 08 - Transaction timed out at SDK
networkScorestring, [ 0 .. 2 ] characters

The global score calculated by the Cartes Bancaires scoring platform. Returned for Cartes Bancaires authentications only.

brandstring, [ 0 .. 64 ] characters

The card brand used in the authentication. Returned for Cartes Bancaires authentications only and must be applied in the following authorization.

Response

Successful frictionless authentication

{ "outcome": "3dsAuthenticated", "status": "Y", "enrolled": "Y", "version": "2.2.0", "authenticationValue": "MAAAAAAAAAAAAAAAAAAAAAAAAAA=", "eci": "05", "dsTransactionId": "c5b808e7-1de1-4069-a17b-f70d3b3b1645", "acsTransactionId": "fe007a6e-315f-4cdf-98ca-28a9e40e3581", "_links": { "self": { "href": "https://try.access.worldpay.com/3ds/authentications/LfC-Tuhv7J2nEw2m9ca_e" } } }