Skip to content
payrocdevelopers

3-D Secure

Explains how 3-D Secure verifies a cardholder's identity during online transactions and how it fits into your integration

Prerequisites: Authentication

3-D Secure is a security feature that helps to verify the cardholder’s identity during e-commerce transactions.

Each time the merchant runs a transaction, the issuing bank assesses the transaction. If the risk of fraud is high, the issuing bank uses 3-D Secure to challenge the cardholder to verify their identity.

How it works

The following diagram shows how 3-D Secure works with your integration.

Mermaid diagram
Mermaid source
sequenceDiagram
    participant YI as Your integration
    participant GW as Gateway
    participant MPI as MPI service
    participant IB as Issuing bank

    rect rgba(0, 81, 194, 0.4)
        Note over YI,GW: 1. Tokenize the payment details
        YI->>GW: Convert card details to a single-use token
        GW-->>YI: singleUseToken
    end

    rect rgba(0, 224, 184, 0.3)
        Note over YI,IB: 2. Run the 3-D Secure check
        YI->>MPI: GET /merchant/mpi<br />(processingTerminalId, singleUseToken, amount, currency, orderId, email)
        MPI->>IB: Send payment details for authentication
        Note over IB: Assess risk and, if needed,<br />challenge the cardholder
        IB-->>MPI: Authentication result
        MPI-->>YI: GET your MPI receipt URL<br />(result, mpiReference, status, eci)
        Note right of YI: We send the result in a separate<br />request to your MPI receipt URL
    end

    rect rgba(0, 224, 184, 0.3)
        Note over YI,GW: 3. Run the sale
        YI->>GW: POST /v1/payments<br />(threeDSecure.serviceProvider = gateway,<br />threeDSecure.mpiReference)
        GW-->>YI: Payment response
    end
  1. Your integration converts the cardholder's payment details into a single-use token.
  2. Your integration sends the single-use token and the transaction details to our merchant plug-in (MPI) service.
  3. The MPI service sends the details to the cardholder's issuing bank, which assesses the risk of fraud and, if needed, challenges the cardholder to verify their identity.
  4. We send the result and the MPI reference to your MPI receipt URL.
  5. Your integration sends a payment request with the MPI reference to our gateway. Our gateway returns the transaction result.

Guides

Run a sale with 3-D Secure

Use 3-D Secure to verify a cardholder's identity before you run a sale.

Browse guides

Search documentation

API reference169
Guides118
Knowledge38
legal1
Solutions32
Workflows74
↑↓highlight↵openView all search results

Menu

Theme

Sign out

Your saved plans remain in your organization. This browser’s private draft and account view will be cleared.

Talk to an engineer