Skip to main content
PUT

3DS Authentication Guide

Store and manage 3D Secure authentication data
Stores a 3D Secure authentication result on an existing token. Use it when the cardholder was authenticated by another 3DS provider, so that PCI Booking can pass the authentication data (CAVV, ECI, transaction IDs) on with the card, for example in a Universal Payment Gateway charge or through the $~ThreeDS_*~$ token replacement placeholders. Store two kinds of result:
  • Successful authentication, for example ECI 05 (Visa) or 02 (Mastercard).
  • Attempted authentication, where authentication could not be completed but the attempt is proven and a CAVV was issued, for example ECI 06 (Visa) or 01 (Mastercard). It usually carries a liability shift, depending on the card scheme and region.
In both cases send ThreeDSecIndication as Authenticated, and send the ECI and CAVV exactly as you received them. The ECI tells the payment gateway which kind of result it is. There is no reason to store a failed or unavailable authentication, because it has no CAVV to pass on.

Error Responses

Parameter Constraints

  • ThreeDSecIndication is required. Send Authenticated.
  • AuthenticationValue is required and has a max length of 256 characters.
  • Eci has a max length of 2 characters.
  • Version, if sent, must start with “1.” or “2.”.

Parameters

Authentication

API key only. This endpoint does not accept access tokens or session tokens.
string
required
Your API key prefixed with APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.

Path Parameters

string
required
The token ID as returned by one of the tokenization methods. For example, 2821a46d80e14d1b96a7f18f1b81926d.

Request Body

string
required
Send Authenticated, for both a successful and an attempted authentication. PCI Booking stores every result as Authenticated; the ECI identifies which kind it is.
string
required
The authentication value (CAVV or AAV) returned by the 3DS provider, exactly as received. Max 256 characters.
string
The Electronic Commerce Indicator returned by the 3DS provider, for example 05. Max 2 characters.
string
The 3DS protocol version, for example 2.2.0. Must start with “1.” or “2.”.
string
The 3DS transaction ID: the XID for 3DS version 1, or the 3DS Server transaction ID for version 2.
string
The transaction ID assigned by the issuer’s Access Control Server (ACS).
string
The universal transaction ID, if your 3DS provider returns one.
string
The merchant name used in the authentication.
string
The Security Level Indicator, if your 3DS provider returns one.

Response

200 - 3D Secure data stored successfully.