Skip to content

Verify the 3DS challenge response

Request

Verify the results of a challenged authentication.

Security
BasicAuth
Headers
Content-Typestring
Example:application/vnd.worldpay.verifications.customers-v3.hal+json
Acceptstring
Example:application/vnd.worldpay.verifications.customers-v3.hal+json
Bodyapplication/vnd.worldpay.verifications.customers-v3.hal+json
transactionReferencestring, [ 1 .. 64 ] characters^[-A-Za-z0-9_!@#$%()*=.:;?\[\]{}~`/+]*$required

A unique reference for authentication. For example, e-commerce order code. Use the same transactionReference across all 3 potential request types (deviceDataInitialization, authentication, verification).

merchantobjectrequired

An object that contains information about the merchant and API level configuration.

challengeobjectrequired

Object containing challenge related information in case of a "challenged" flow

An example of a verification request to return the 3DS authentication data

{ "transactionReference": "Memory265-13/08/1876", "merchant": { "entity": "default" }, "challenge": { "reference": "1xoKSqTvmLvhRYBsaE60" } }

Responses

The challenge was successful - obtain the authentication data for onward use

Bodyapplication/vnd.worldpay.verifications.customers-v3.hal+json
Any of:
outcomestring

Outcome of the previously posted authentication request.

Enum:"authenticated""authenticationFailed""unavailable""signatureFailed"
acsTransactionIdstring, [ 1 .. 36 ] characters

An identifier assigned by the Access Control Server (ACS) to identify a single transaction. Used primarily for Mastercard 3RI subsequent transactions to link the subsequent transaction back to a previous cardholder authentication. Can be disregarded unless otherwise needed.

enrolledstring, = 1 characters

Status of authentication eligibility.

  • Y - Bank is participating in 3DS
  • N - Bank is not participating in 3DS
  • U - The Directory Server (DS) or Access Control Server (ACS) were not available at the time of the request
  • B - Merchant authentication rule is triggered to bypass authentication (3DS premium only)
authenticationobject

Object that contains authentication related information.

transactionReferencestring, [ 1 .. 64 ] characters

A unique reference for authentication that was passed in the request.

Response

An example of a verification request to return the 3DS authentication data

{ "outcome": "authenticated", "transactionReference": "Memory265-13/08/1876", "acsTransactionId": "fe007a6e-315f-4cdf-98ca-28a9e40e3581", "enrolled": "Y", "authentication": { "version": "2.1.0", "authenticationValue": "MAAAAAAAAAAAAAAAAAAAAAAAAAA=", "eci": "05", "transactionId": "c5b808e7-1de1-4069" } }