Description
The Secure3D Notification delivers the result of a challenged 3DS authentication directly to the merchant, server-to-server, independently of the cardholder's browser.
After a challenge, the authentication result normally returns through the cardholder's browser as a post to the merchant's TermUrl.
The Secure3D Notification delivers the same result over a separate server-to-server channel, so the outcome is still available if the browser does not return.
Merchants can decide to proceed to Authorize or Payment once they've received the post to their TermURL or the Secure3D notification, or which ever is received first.
Where the merchant receives the post to their TermUrl first, they can continue to Authorize or Payment.
- The merchant will include the PreviousTransactionID from the Secure3DLookup request and the received PAResPayload/Cres.
Where the merchant receives the Secure3D notification first, they can continue to Authorize or Payment.
- The merchant will include the PreviousTransactionID from the Secure3DLookup request and the leave PAResPayload/Cres blank.
Where the merchant receives both a Secure3D notification and post to their TermUrl for the same Secure3Dlookup, the merchant should act on which ever response was recevied first, not both, to send their Authorize or Payment request.
Merchant Enablement
- Merchants must be enabled for notifications.
- Merchants must explicitly request the Secure3D notification to be enabled.
- The notification will be sent to the merchants existing configured notification Url/endpoint
Sample Message
Secure 3D example - Authenticated
{
"RequestType": "Secure3D",
"MerchantID": "8B67BF88-BB8D-4EB5-ADFC-0F5C97C7ED67",
"CardAcceptorID": "1738194",
"TransactionID": "c96bafea-4303-4a1b-a1ad-62d66620741a",
"TransactionDateTime": "2024-11-07T14:02:48.787",
"ReconID": "MR747891457",
"Amount": "50",
"CurrencyCode": "ZAR",
"OrderNumber": "MR22165670",
"PaymentService": "CardNotPresent",
"ResponseSource": "3Dsecure",
"AuthenticationStatus": "Y",
"ECI": "02",
"MdStatus": "1",
"TransStatus": "Y",
"TransStatusReason": "",
"MaskedCardNumber": "541333******1429",
"ExpiryMonth": "12",
"ExpiryYear": "20",
"SaleReconID": "MR43851259",
"NetworkToken":"555555******1111",
"CommProtocol": "REST",
}Secure 3D example - Not Authenticated
{
"RequestType": "Secure3D",
"MerchantID": "8B67BF88-BB8D-4EB5-ADFC-0F5C97C7ED67",
"CardAcceptorID": "1738194",
"TransactionID": "c96bafea-4303-4a1b-a1ad-62d66620741a",
"TransactionDateTime": "2024-11-07T14:02:48.787",
"ReconID": "MR747891457",
"Amount": "50",
"CurrencyCode": "ZAR",
"OrderNumber": "MR22165670",
"PaymentService": "CardNotPresent",
"ResponseSource": "3Dsecure",
"AuthenticationStatus": "N",
"ECI": "07",
"MdStatus": "0",
"TransStatus": "N",
"TransStatusReason": "01",
"MaskedCardNumber": "541333******1429",
"ExpiryMonth": "12",
"ExpiryYear": "20",
"SaleReconID": "MR43851259",
"NetworkToken":"555555******1111",
"CommProtocol": "REST"
}New Secure3D Notification fields.
The following fields have been added to the Secure3D Notification and can be used to determine the result of the Challenge authentication.
AuthenticationStatus
| AuthenticationStatus | Description | Liability Shift to the merchant |
|---|---|---|
| Y | Authenticated | No |
| N | Not Authenticated | Yes |
| U | Could not be performed | Yes |
| A | Attempted processing performed | Yes |
| R | Rejected | Yes |
ECI
| ECI | Description | Liability Shift to the merchant |
|---|---|---|
| 02 | 3DS authentication was successful (MasterCard) | No |
| 05 | 3DS authentication was successful (Visa) | No |
| 01 | 3DS was attempted | Yes |
| 06 | Not Participating/Attempted | Yes |
| 07 | Authentication failed/cancelled | Yes |
MdStatus
| MDStatus | Description | Liability Shift to the merchant |
|---|---|---|
| 0 - Not Authenticated | Cardholder did not finish the 3DSecure procedure successfully | Yes |
| 1 - Authenticated | Cardholder successfully authenticated. | No |
| 2,3 - Not participating | Cardholder not enrolled in 3DSecure or issuer of the card is not participating in 3DSecure | Yes |
| 4 - Attempt | 3DSecure attempt recognized by card issuer. | No |
| 5 - Authentication unavailable | Issuer is unable to process 3DSecure request. Merchant can decide to continue with transaction if merchant considers risk as low. | Yes |
| 6 - 3DSecure error | Invalid field in 3-D Secure message generation, error message received or directory server fails to validate the merchant. | Yes |
| 7 - MPI/Our error | Error occured on MPI side, this may happen when the input data is invalid, this may also be returned if the MPI does not support 3DSecure for the particular card brand. | Yes |
| 8 - Fraud score block | 3DS attempt was blocked by MPI | Yes |
| 9 - Pending | MdStatus in enrollment response when merchant should start 3DSecure procedure. | N/A |
| 50 - In 3DS Method | An extra authentication step is required before 3DSecure procedure is started. | N/A |
| 83 - Proxy script error | The proxy script encountered an error. | Yes |
| 91 - Network error | Network error, connection to directory server times out. | Yes |
| 92 - Directory error | Directory response read timeout or other failure. | Yes |
| 93 - Configuration error | Service is disabled, invalid configuration, etc. | Yes |
| 94 - Input error | Merchant request had errors | Yes |
| 95 - No directory error | No directory server found configured for PAN/card type. | Yes |
| 97 - Unable to locate live transaction | Unable to locate live transaction, too late or already processed. | Yes |
| 96 - No directory error | No version 2 directory server found configured for PAN/card type and flow requires version 2 processing. | Yes |
| 99 - System error | System error | Yes |
TransStatus
| TransStatus | Description | Liability Shift to the merchant |
|---|---|---|
| Y | Authentication successful | No |
| N | Not authenticated | Yes |
| U | Authentication could not be performed | Yes |
| A | Attempted | Yes |
| C | Challenge/Additional authentication is required | Yes |
| R | Authentication rejected | Yes |
| I | Informational only | Yes |
TransStatusReason
NoteWhen the Challenge is successsfully authenticated the TransStatusReason will be blank.
TransStatusReason will only be populated when the challenge is not successfully authenticated.
| TransStatusReason | Description |
|---|---|
| 01 | Card authentication failed |
| 02 | Unknown device |
| 03 | Unsupported device |
| 04 | Exceeds authentication frequency limit |
| 05 | Expired card |
| 06 | Invalid card number |
| 07 | Invalid transaction |
| 08 | No card record |
| 09 | Security failure |
| 10 | Stolen card |
| 11 | Suspected fraud |
| 12 | Transaction not permitted to cardholder |
| 13 | Cardholder not enrolled in service |
| 14 | Transaction timed out at the ACS |
| 15 | Low confidence |
| 16 | Medium confidence |
| 17 | High confidence |
| 18 | Very high confidence |
| 19 | Exceeds ACS maximum challenges |
| 20 | Non-payment transaction not supported |
| 21 | Merchant-initiated transaction (3RI) not supported |
| 22 | ACS technical issue |
| 23 | Decoupled authentication required by ACS |
| 24 | 3DS requestor decoupled maximum expiry time exceeded |
| 25 | Decoupled authentication was provided insufficient time to authenticate cardholder. ACS will not make attempt |
| 26 | Authentication attempted, but not performed by the cardholder |
