const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/3dToken',
{
method: 'PUT',
headers: {
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
body: JSON.stringify({
AuthenticationValue: 'AJkBAoEREQAAAAB4hABwcAAAAAA=',
Version: '2.1.0',
Eci: '05',
ThreeDSecIndication: 'Authenticated',
XID: '861433f4-abff-4c40-b2fd-fea208856a33',
AcsTransactionId: 'e7a46959-9630-413e-ab56-4e399b96244a'
})
}
);
console.log(response.status);
import requests
response = requests.put(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/3dToken',
headers={
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
json={
'AuthenticationValue': 'AJkBAoEREQAAAAB4hABwcAAAAAA=',
'Version': '2.1.0',
'Eci': '05',
'ThreeDSecIndication': 'Authenticated',
'XID': '861433f4-abff-4c40-b2fd-fea208856a33',
'AcsTransactionId': 'e7a46959-9630-413e-ab56-4e399b96244a'
}
)
print(response.status_code)
Empty response body. 3D Secure data stored successfully.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
3D Secure
Store 3D Secure Data
Store 3D Secure authentication data on a token.
PUT
/
api
/
payments
/
paycard
/
{cardToken}
/
3dToken
const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/3dToken',
{
method: 'PUT',
headers: {
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
body: JSON.stringify({
AuthenticationValue: 'AJkBAoEREQAAAAB4hABwcAAAAAA=',
Version: '2.1.0',
Eci: '05',
ThreeDSecIndication: 'Authenticated',
XID: '861433f4-abff-4c40-b2fd-fea208856a33',
AcsTransactionId: 'e7a46959-9630-413e-ab56-4e399b96244a'
})
}
);
console.log(response.status);
import requests
response = requests.put(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/3dToken',
headers={
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
json={
'AuthenticationValue': 'AJkBAoEREQAAAAB4hABwcAAAAAA=',
'Version': '2.1.0',
'Eci': '05',
'ThreeDSecIndication': 'Authenticated',
'XID': '861433f4-abff-4c40-b2fd-fea208856a33',
'AcsTransactionId': 'e7a46959-9630-413e-ab56-4e399b96244a'
}
)
print(response.status_code)
Empty response body. 3D Secure data stored successfully.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.
3DS Authentication Guide
Store and manage 3D Secure authentication data
$~ThreeDS_*~$ token replacement placeholders.
Store two kinds of result:
- Successful authentication, for example ECI
05(Visa) or02(Mastercard). - Attempted authentication, where authentication could not be completed but the attempt is proven and a CAVV was issued, for example ECI
06(Visa) or01(Mastercard). It usually carries a liability shift, depending on the card scheme and region.
ThreeDSecIndication as Authenticated, and send the ECI and CAVV exactly as you received them. The ECI tells the payment gateway which kind of result it is. There is no reason to store a failed or unavailable authentication, because it has no CAVV to pass on.
Error Responses
| Code | HTTP Status | Condition |
|---|---|---|
| -179 | 400 | The body is missing, ThreeDSecIndication is missing, AuthenticationValue is missing or longer than 256 characters, Eci is longer than 2 characters, or Version does not start with “1.” or “2.” |
| -1003 | 401 | User is not the owner |
| -150 | 500 | Failed to store 3DS data |
Parameter Constraints
- ThreeDSecIndication is required. Send
Authenticated. - AuthenticationValue is required and has a max length of 256 characters.
- Eci has a max length of 2 characters.
- Version, if sent, must start with “1.” or “2.”.
Parameters
Authentication
API key only. This endpoint does not accept access tokens or session tokens.string
required
Your API key prefixed with
APIKEY. Example: APIKEY your-api-key. The x-pcibooking-api-key header is also accepted. See the Authentication guide.Path Parameters
string
required
The token ID as returned by one of the tokenization methods. For example,
2821a46d80e14d1b96a7f18f1b81926d.Request Body
string
required
Send
Authenticated, for both a successful and an attempted authentication. PCI Booking stores every result as Authenticated; the ECI identifies which kind it is.string
required
The authentication value (CAVV or AAV) returned by the 3DS provider, exactly as received. Max 256 characters.
string
The Electronic Commerce Indicator returned by the 3DS provider, for example
05. Max 2 characters.string
The 3DS protocol version, for example
2.2.0. Must start with “1.” or “2.”.string
The 3DS transaction ID: the
XID for 3DS version 1, or the 3DS Server transaction ID for version 2.string
The transaction ID assigned by the issuer’s Access Control Server (ACS).
string
The universal transaction ID, if your 3DS provider returns one.
string
The merchant name used in the authentication.
string
The Security Level Indicator, if your 3DS provider returns one.
const response = await fetch(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/3dToken',
{
method: 'PUT',
headers: {
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
body: JSON.stringify({
AuthenticationValue: 'AJkBAoEREQAAAAB4hABwcAAAAAA=',
Version: '2.1.0',
Eci: '05',
ThreeDSecIndication: 'Authenticated',
XID: '861433f4-abff-4c40-b2fd-fea208856a33',
AcsTransactionId: 'e7a46959-9630-413e-ab56-4e399b96244a'
})
}
);
console.log(response.status);
import requests
response = requests.put(
'https://service.pcibooking.net/api/payments/paycard/2821a46d80e14d1b96a7f18f1b81926d/3dToken',
headers={
'Authorization': 'APIKEY your-api-key',
'Content-Type': 'application/json'
},
json={
'AuthenticationValue': 'AJkBAoEREQAAAAB4hABwcAAAAAA=',
'Version': '2.1.0',
'Eci': '05',
'ThreeDSecIndication': 'Authenticated',
'XID': '861433f4-abff-4c40-b2fd-fea208856a33',
'AcsTransactionId': 'e7a46959-9630-413e-ab56-4e399b96244a'
}
)
print(response.status_code)
Response
200 - 3D Secure data stored successfully.Empty response body. 3D Secure data stored successfully.
Empty response body.
Authentication failed: the API key, session token or access token is missing or was not accepted.
See "Authentication and Permission Failures" on the Error Handling page.

