1. 3DS 2.0
Merchant Warrior API 2.0
  • API
    • Getting Started
    • Guides
      • Xero Connection
      • Xero Custom URL
      • wooCommerce PayID
      • Middleware
      • Hostaway
    • Direct API
      • getAccessToken
      • processCard
      • processAuth
      • processCapture
      • processBatch
      • retrieveBatch (CSV)
      • retrieveBatch (JSON Response)
      • retrieveBatch (JSON Notify)
      • refundCard
      • queryCard
      • processDDebit
      • processDDebitAuth
      • processVoid
      • verifyCard
      • queryDD
      • queryBIN
      • getSettlement
      • checkEnrollment
      • checkPARes
      • addBlacklistedCard
      • removeBlacklistedCard
      • queryBlacklistedCard
      • simulateNotify
      • getSurcharge
    • 3DS 2.0
      • Introduction
      • 3DS 2 Authentication Flows
      • Step 3 - 3DS Method Data
      • Step 5 - Challenge
      • Step 1 - getAccessToken
        POST
      • Step 2 - checkEnrollment
        POST
      • Step 4 - checkTDSAuth
        POST
      • Step 6 - checkPARes
        POST
      • Step 7 - processCard
        POST
      • Authorization Only processCard
        POST
    • PayLink
      • Introduction
      • Generate PayLink
    • PayID
      • Introduction
      • Create
      • Transaction
      • Get
      • Update
      • Status
      • List
      • Refund
    • PayTo
      • Introduction
      • Simulator
      • Certification
      • Actions and Statuses
      • Agreements
        • Agreements
        • Notifications
        • Create Agreement
        • Get Agreement
        • Amend Agreement
        • Amend Agreement Status
        • Recall Agreement Action
      • Payments
        • Payments
        • Notifications
        • Create Payment
        • Get Payment
        • Get Payment Status
        • Search Payments
    • Confirmation of Payee
      • Introduction
      • Sandbox Simulations
      • Validate
    • POS
      • Introduction
      • processPOS
      • refundPOS
      • voidPOS
      • deregisterPOS
    • Web SDK
      • Introduction
      • Usage
      • getAccessToken
      • Options
      • Initiate
      • Payframe Functionality
      • Middleware
      • addCard
    • Payframe
      • Introduction
      • Usage
      • Constructor
      • tdsCheck
      • Additional Functions
      • Styling
      • processCard
      • processAuth
    • Digital Wallets
      • Apple Pay Prerequisites
      • Google Pay Prerequisites
      • Web SDK
      • Manual Integration
      • processCard
      • addCard
      • getMerchantSession
      • decryptApplePayToken
    • Token Payments
      • Introduction
      • Key Management
      • addCard
      • removeCard
      • cardInfo
      • changeExpiry
      • processCard
      • processAuth
    • Batch
      • Introduction
      • Card Batches
      • Token Batches
      • Direct Debit Batches
    • Forter
      • Introduction
      • Testing
    • Payouts
      • Introduction
      • Sandbox Simulations
      • Notifications
      • Create Payouts
      • Get Payout Status
      • Resend Notifications
      • Get Payout Transaction Status
      • Get Payout Transaction Notify
    • Partner API
      • Introduction
      • addMerchant
      • updateMerchant
      • checkMerchant
    • Notifications
      • Notifications
  • Hosted Payment Page
    • processCard
  1. 3DS 2.0

Step 5 - Challenge

If the issuer has opted for a challenge flow, you will need to present the authentication experience (two-factor authentication) to the customer.
Example
Add an iframe to the users browser, either statically or using JavaScript.
Add a form containing the appropriate input elements:
<form class="" id="challengeForm">
  <input type="hidden" name="creq" id="creq"/>
  <!-- This input can carry up to 1024 Base64-URL encoded characters -->
  <input type="hidden" name="threeDSSessionData" id="threeDSSessionData"/>
</form>
Fill out the form inputs and submit them to the acsURL in the iframe.
The acsURL will respond with the cres which will be submitted via POST to your notifyURL that was specified in Step 1.
{"cres": "eyJhY3NUcmFuc0lEIjoiZTg5YzNmNzQtNTlkOS00N2QxLTg3Y2EtZGZlMTQyMmI4MWMwIiwiY2hhbGxlbmdlQ29tcGxldGlvbkluZCI6IlkiLCJtZXNzYWdlVHlwZSI6IkNSZXMiLCJtZXNzYWdlVmVyc2lvbiI6IjIuMS4wIiwidGhyZWVEU1NlcnZlclRyYW5zSUQiOiI5ZDE2MzUwZC1mZDdhLTRjODItYTYwOC1lMjgzZjdlNDNmNmUiLCJ0cmFuc1N0YXR1cyI6IlkifQ=="}
You may want to communicate with your frontend after performing a challenge. If this is the case see postMessage Notifications for further information.
Modified at 2026-07-16 12:48:15
Previous
Step 3 - 3DS Method Data
Next
Step 1 - getAccessToken
Built with