Prerequisites: Authentication
3-D Secure is a security feature that helps to verify the cardholder’s identity during e-commerce transactions.
Each time the merchant runs a transaction, the issuing bank assesses the transaction. If the risk of fraud is high, the issuing bank uses 3-D Secure to challenge the cardholder to verify their identity.
How it works
The following diagram shows how 3-D Secure works with your integration.
Mermaid source
sequenceDiagram
participant YI as Your integration
participant GW as Gateway
participant MPI as MPI service
participant IB as Issuing bank
rect rgba(0, 81, 194, 0.4)
Note over YI,GW: 1. Tokenize the payment details
YI->>GW: Convert card details to a single-use token
GW-->>YI: singleUseToken
end
rect rgba(0, 224, 184, 0.3)
Note over YI,IB: 2. Run the 3-D Secure check
YI->>MPI: GET /merchant/mpi<br />(processingTerminalId, singleUseToken, amount, currency, orderId, email)
MPI->>IB: Send payment details for authentication
Note over IB: Assess risk and, if needed,<br />challenge the cardholder
IB-->>MPI: Authentication result
MPI-->>YI: GET your MPI receipt URL<br />(result, mpiReference, status, eci)
Note right of YI: We send the result in a separate<br />request to your MPI receipt URL
end
rect rgba(0, 224, 184, 0.3)
Note over YI,GW: 3. Run the sale
YI->>GW: POST /v1/payments<br />(threeDSecure.serviceProvider = gateway,<br />threeDSecure.mpiReference)
GW-->>YI: Payment response
end
- Your integration converts the cardholder's payment details into a single-use token.
- Your integration sends the single-use token and the transaction details to our merchant plug-in (MPI) service.
- The MPI service sends the details to the cardholder's issuing bank, which assesses the risk of fraud and, if needed, challenges the cardholder to verify their identity.
- We send the result and the MPI reference to your MPI receipt URL.
- Your integration sends a payment request with the MPI reference to our gateway. Our gateway returns the transaction result.
Guides
Run a sale with 3-D Secure
Use 3-D Secure to verify a cardholder's identity before you run a sale.