1. 3DS 2.0
Merchant Warrior API 2.0
  • API
    • Getting Started
    • Guides
      • Xero Connection
      • Xero Custom URL
      • wooCommerce PayID
      • Middleware
      • Hostaway
    • Direct API
      • getAccessToken
      • processCard
      • processAuth
      • processCapture
      • processBatch
      • retrieveBatch (CSV)
      • retrieveBatch (JSON Response)
      • retrieveBatch (JSON Notify)
      • refundCard
      • queryCard
      • processDDebit
      • processDDebitAuth
      • processVoid
      • verifyCard
      • queryDD
      • queryBIN
      • getSettlement
      • checkEnrollment
      • checkPARes
      • addBlacklistedCard
      • removeBlacklistedCard
      • queryBlacklistedCard
      • simulateNotify
      • getSurcharge
    • 3DS 2.0
      • Introduction
      • 3DS 2 Authentication Flows
      • Step 3 - 3DS Method Data
      • Step 5 - Challenge
      • Step 1 - getAccessToken
        POST
      • Step 2 - checkEnrollment
        POST
      • Step 4 - checkTDSAuth
        POST
      • Step 6 - checkPARes
        POST
      • Step 7 - processCard
        POST
      • Authorization Only processCard
        POST
    • PayLink
      • Introduction
      • Generate PayLink
    • PayID
      • Introduction
      • Create
      • Transaction
      • Get
      • Update
      • Status
      • List
      • Refund
    • PayTo
      • Introduction
      • Simulator
      • Certification
      • Actions and Statuses
      • Agreements
        • Agreements
        • Notifications
        • Create Agreement
        • Get Agreement
        • Amend Agreement
        • Amend Agreement Status
        • Recall Agreement Action
      • Payments
        • Payments
        • Notifications
        • Create Payment
        • Get Payment
        • Get Payment Status
        • Search Payments
    • Confirmation of Payee
      • Introduction
      • Sandbox Simulations
      • Validate
    • POS
      • Introduction
      • processPOS
      • refundPOS
      • voidPOS
      • deregisterPOS
    • Web SDK
      • Introduction
      • Usage
      • getAccessToken
      • Options
      • Initiate
      • Payframe Functionality
      • Middleware
      • addCard
    • Payframe
      • Introduction
      • Usage
      • Constructor
      • tdsCheck
      • Additional Functions
      • Styling
      • processCard
      • processAuth
    • Digital Wallets
      • Apple Pay Prerequisites
      • Google Pay Prerequisites
      • Web SDK
      • Manual Integration
      • processCard
      • addCard
      • getMerchantSession
      • decryptApplePayToken
    • Token Payments
      • Introduction
      • Key Management
      • addCard
      • removeCard
      • cardInfo
      • changeExpiry
      • processCard
      • processAuth
    • Batch
      • Introduction
      • Card Batches
      • Token Batches
      • Direct Debit Batches
    • Forter
      • Introduction
      • Testing
    • Payouts
      • Introduction
      • Sandbox Simulations
      • Notifications
      • Create Payouts
      • Get Payout Status
      • Resend Notifications
      • Get Payout Transaction Status
      • Get Payout Transaction Notify
    • Partner API
      • Introduction
      • addMerchant
      • updateMerchant
      • checkMerchant
    • Notifications
      • Notifications
  • Hosted Payment Page
    • processCard
  1. 3DS 2.0

Step 3 - 3DS Method Data

The 3DS Method Data is used by issuers to gather a device fingerprint from your customer directly.
1.
Render a hidden HTML iframe in the cardholder's browser
2.
Create a form with an input field named threeDSMethodData
3.
This field must contain the paReq (retrieved from Step2 ) and be Base64-URL encoded
4.
Post the form to the acsURL (retrieved from Step2 ), with the HTML iframe as a target
Example
Add an iframe to the user's browser using JavaScript
Resulting in the following html
 <iframe name="threeDSMethodIframe" class="hidden"/> 
Create a HTML form that contains the input field:
<form class="" id="threeDSMethodForm"> 
  <input type="hidden" name="threeDSMethodData" id="threeDSMethodData"/> 
</form>
This form can be submitted using the following JavaScript:
The acsURL will respond with the threeDSServerTransID which will be submitted via POST to the notifyURL you specified in your Step 1 - getAccessToken request.
If the callback from the acsURL is not received by your notifyURL within 10 seconds from the POST call above, it is deemed to have failed. In this situation you should proceed to Step 4 and set the 3DS Completion Indicator (threeDSCompInd) to N.
{"threeDSServerTransID": "eyJ0aHJlZURTU2VydmVyVHJhbnNJRCI6ImY3OGYyM2ZlLTEzNzAtNDYyNC1iNDI5LThhYjhkODQ1NWJkYyJ9"}
If your notifyURL receives a threeDSServerTransID you can proceed to Step 4 and set the 3DS Completion Indicator (threeDSCompInd) to Y. You may want to communicate with your frontend after gathering a device fingerprint using the 3DS Method Data above. If this is the case see postMessage Notifications for further information.
Modified at 2026-07-31 05:38:45
Previous
3DS 2 Authentication Flows
Next
Step 5 - Challenge
Built with