Secure3D Notification

Description

The Secure3D Notification delivers the result of a challenged 3DS authentication directly to the merchant, server-to-server, independently of the cardholder's browser.

After a challenge, the authentication result normally returns through the cardholder's browser as a post to the merchant's TermUrl.

The Secure3D Notification delivers the same result over a separate server-to-server channel, so the outcome is still available if the browser does not return.

Merchants can decide to proceed to Authorize or Payment once they've received the post to their TermURL or the Secure3D notification, or which ever is received first.

Where the merchant receives the post to their TermUrl first, they can continue to Authorize or Payment.

  • The merchant will include the PreviousTransactionID from the Secure3DLookup request and the received PAResPayload/Cres.

Where the merchant receives the Secure3D notification first, they can continue to Authorize or Payment.

  • The merchant will include the PreviousTransactionID from the Secure3DLookup request and the leave PAResPayload/Cres blank.

Where the merchant receives both a Secure3D notification and post to their TermUrl for the same Secure3Dlookup, the merchant should act on which ever response was recevied first, not both, to send their Authorize or Payment request.

Merchant Enablement

  • Merchants must be enabled for notifications.
  • Merchants must explicitly request the Secure3D notification to be enabled.
    • The notification will be sent to the merchants existing configured notification Url/endpoint

Sample Message

Secure 3D example - Authenticated

{
"RequestType": "Secure3D",
"MerchantID": "8B67BF88-BB8D-4EB5-ADFC-0F5C97C7ED67",
"CardAcceptorID": "1738194",
"TransactionID": "c96bafea-4303-4a1b-a1ad-62d66620741a",
"TransactionDateTime": "2024-11-07T14:02:48.787",
"ReconID": "MR747891457",
"Amount": "50",
"CurrencyCode": "ZAR",
"OrderNumber": "MR22165670",
"PaymentService": "CardNotPresent",
"ResponseSource": "3Dsecure",
"AuthenticationStatus": "Y",
"ECI": "02",
"MdStatus": "1",
"TransStatus": "Y",
"TransStatusReason": "",
"MaskedCardNumber": "541333******1429",
"ExpiryMonth": "12",
"ExpiryYear": "20",
"SaleReconID": "MR43851259",
"NetworkToken":"555555******1111",
"CommProtocol": "REST",
}

Secure 3D example - Not Authenticated

{
"RequestType": "Secure3D",
"MerchantID": "8B67BF88-BB8D-4EB5-ADFC-0F5C97C7ED67",
"CardAcceptorID": "1738194",
"TransactionID": "c96bafea-4303-4a1b-a1ad-62d66620741a",
"TransactionDateTime": "2024-11-07T14:02:48.787",
"ReconID": "MR747891457",
"Amount": "50",
"CurrencyCode": "ZAR",
"OrderNumber": "MR22165670",
"PaymentService": "CardNotPresent",
"ResponseSource": "3Dsecure",
"AuthenticationStatus": "N",
"ECI": "07",
"MdStatus": "0",
"TransStatus": "N",
"TransStatusReason": "01",
"MaskedCardNumber": "541333******1429",
"ExpiryMonth": "12",
"ExpiryYear": "20",
"SaleReconID": "MR43851259",
"NetworkToken":"555555******1111",
"CommProtocol": "REST"
}

New Secure3D Notification fields.


The following fields have been added to the Secure3D Notification and can be used to determine the result of the Challenge authentication.

📘

Note

Only an AuthenticationStatus of "Y" indicates succesful authentication.

AuthenticationStatus

AuthenticationStatusDescriptionLiability Shift to the merchant
YAuthenticatedNo
NNot AuthenticatedYes
UCould not be performedYes
AAttempted processing performedYes
RRejectedYes

ECI

ECIDescriptionLiability Shift to the merchant
023DS authentication was successful (MasterCard)No
053DS authentication was successful (Visa)No
013DS was attemptedYes
06Not Participating/AttemptedYes
07Authentication failed/cancelledYes

MdStatus

MDStatusDescriptionLiability Shift to the merchant
0 - Not AuthenticatedCardholder did not finish the 3DSecure procedure successfullyYes
1 - AuthenticatedCardholder successfully authenticated.No
2,3 - Not participatingCardholder not enrolled in 3DSecure or issuer of the card is not participating in 3DSecureYes
4 - Attempt3DSecure attempt recognized by card issuer.No
5 - Authentication unavailableIssuer is unable to process 3DSecure request. Merchant can decide to continue with transaction if merchant considers risk as low. Yes
6 - 3DSecure errorInvalid field in 3-D Secure message generation, error message received or directory server fails to validate the merchant.Yes
7 - MPI/Our errorError occured on MPI side, this may happen when the input data is invalid, this may also be returned if the MPI does not support 3DSecure for the particular card brand.Yes
8 - Fraud score block3DS attempt was blocked by MPIYes
9 - PendingMdStatus in enrollment response when merchant should start 3DSecure procedure.N/A
50 - In 3DS MethodAn extra authentication step is required before 3DSecure procedure is started.N/A
83 - Proxy script errorThe proxy script encountered an error.Yes
91 - Network errorNetwork error, connection to directory server times out.Yes
92 - Directory errorDirectory response read timeout or other failure.Yes
93 - Configuration errorService is disabled, invalid configuration, etc.Yes
94 - Input errorMerchant request had errorsYes
95 - No directory errorNo directory server found configured for PAN/card type.Yes
97 - Unable to locate live transactionUnable to locate live transaction, too late or already processed.Yes
96 - No directory errorNo version 2 directory server found configured for PAN/card type and flow requires version 2 processing.Yes
99 - System errorSystem errorYes

TransStatus

TransStatusDescriptionLiability Shift to the merchant
YAuthentication successfulNo
NNot authenticatedYes
UAuthentication could not be performedYes
AAttemptedYes
CChallenge/Additional authentication is requiredYes
RAuthentication rejectedYes
IInformational onlyYes

TransStatusReason

📘

Note

When the Challenge is successsfully authenticated the TransStatusReason will be blank.

TransStatusReason will only be populated when the challenge is not successfully authenticated.

TransStatusReasonDescription
01Card authentication failed
02Unknown device
03Unsupported device
04Exceeds authentication frequency limit
05Expired card
06Invalid card number
07Invalid transaction
08No card record
09Security failure
10Stolen card
11Suspected fraud
12Transaction not permitted to cardholder
13Cardholder not enrolled in service
14Transaction timed out at the ACS
15Low confidence
16Medium confidence
17High confidence
18Very high confidence
19Exceeds ACS maximum challenges
20Non-payment transaction not supported
21Merchant-initiated transaction (3RI) not supported
22ACS technical issue
23Decoupled authentication required by ACS
243DS requestor decoupled maximum expiry time exceeded
25Decoupled authentication was provided insufficient time to authenticate cardholder. ACS will not make attempt
26Authentication attempted, but not performed by the cardholder