Skip to content

Device Data Complete
internal

Request

Provide the sessionId or consumerSessionId from device data collection to continue the 3DS authentication.

This endpoint is not used for the redirect flow.

Security
BasicAuth
Path
keystringrequired

Unique short lived value generated by us and used as part of the redirect url path.

Headers
WP-Api-Versionstringrequired

The API version.

Value:"2026-10-01"
Example:2026-10-01
Bodyapplication/json
collectionReferencestring

Add the sessionId provided in the postMessage for the device data collection form (web) or for native (iOS/Android), returned as consumerSessionId as part of SDK initialization.

Note: If device data collection fails you can attempt the payment without this value, but you will see an increased number of challenged and even authenticationFailure outcomes, if this happens for a lot of requests.

Example:"0_3XXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXX6b5"
deviceDataobject

Object containing device data information.

{ "collectionReference": "0_3XXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXX6b5", "deviceData": { "acceptHeader": "string", "userAgentHeader": "string", "browserLanguage": "string", "ipAddress": "string", "browserJavaEnabled": true, "browserColorDepth": 1, "browserScreenHeight": 0, "browserScreenWidth": 0, "timeZone": "string", "browserJavascriptEnabled": true, "channel": "browser" } }

Responses

The authentication has been created.

Bodyapplication/json
outcomestringrequired

The outcome of the device data complete request

Enum ValueDescription
3dsAuthenticated

Cardholder successfully authenticated by card issuer

3dsAttempted

3DS attempted but card issuer not participating. Stand-in authentication by the scheme.

3dsChallenged

Issuer requests an identity check using the challenge screen

3dsRejected

Issuer rejects the authentication, do not proceed with payment

3dsNotAuthenticated

Authentication failure by card issuer (system issue)

3dsUnavailable

Authentication unavailable at this current time

3dsOutage

Issuer recognized outage. Can attempt authentication outage exemption

3dsBypassed

3DS bypassed based on rules or recommendation from authentication optimization service

3dsExempted

Successful exemption in 3DS authentication

Discriminator
versionstring, [ 1 .. 10 ] characters

The version of 3DS used to process the transaction.

ecistring, [ 1 .. 2 ] characters

Commerce Indicator (ECI). Indicates the outcome of the 3DS authentication.

ECIMeaning
02 or 05Fully Authenticated Transaction
01 or 06Attempted Authentication Transaction
00 or 07Non 3-D Secure Transaction
SchemeValue
Mastercard02, 01, 00
Visa05, 06, 07
Amex05, 06, 07
JCB05, 06, 07
Diners05, 06, 07
authenticationValuestring, [ 1 .. 64 ] characters

A cryptographic value that provides evidence of the outcome of a 3DS verification.

  • Visa - Cardholder Authentication Verification Value (CAVV)
  • Mastercard - Universal Cardholder Authentication Field (UCAF)
dsTransactionIdstring, [ 1 .. 64 ] characters

Directory server transaction ID, if provided should be used in the payment authorization authentication object.

cryptogramAlgorithmstring, [ 1 .. 99999 ] characters

Indicates the algorithm used to generate the cryptogram. Returned for Cartes Bancaires authentications only and must be applied in the following authorization request.

challengePreferencestring, [ 1 .. 64 ] characters

Indicates the preferred challenge behavior. Returned for Cartes Bancaires authentications only and must be applied in the following authorization request.

  • noPreference
  • noChallengeRequested
  • challengeRequested
  • challengeMandated
authenticationFlowstring, [ 1 .. 64 ] characters

Indicates which flow the customer has been directed to. Returned for Cartes Bancaires authentications only and must be applied in the following authorization request.

Enum:"challenge""frictionless"
statusReasonstring, [ 1 .. 2 ] characters

Provides further information relating to the outcome of the authentication. Returned for failed authentications only. Returned for Cartes Bancaires authentications only.

cancellationIndicatorstring, [ 0 .. 2 ] characters

An indicator as to why the authentication was cancelled. Returned for Cartes Bancaires authentications only.

  • 01 - Cardholder selected cancel
  • 02 - Reserved for future use
  • 03 - Authentication timed out
  • 04 and 05 - Authentication timed out at ACS provider
  • 06 - Transaction error
  • 07 - Unknown
  • 08 - Transaction timed out at SDK
networkScorestring, [ 0 .. 2 ] characters

The global score calculated by the Cartes Bancaires scoring platform. Returned for Cartes Bancaires authentications only.

brandstring, [ 0 .. 64 ] characters

The card brand used in the authentication. Returned for Cartes Bancaires authentications only and must be applied in the following authorization.

Response

Successful frictionless authentication

{ "outcome": "3dsAuthenticated", "status": "Y", "enrolled": "Y", "version": "2.2.0", "authenticationValue": "MAAAAAAAAAAAAAAAAAAAAAAAAAA=", "eci": "05", "dsTransactionId": "c5b808e7-1de1-4069-a17b-f70d3b3b1645", "acsTransactionId": "fe007a6e-315f-4cdf-98ca-28a9e40e3581", "_links": { "self": { "href": "https://try.access.worldpay-bsh.securedataplatform.com/3ds/authentications/LfC-Tuhv7J2nEw2m9ca_e" } } }