3D Secure 2 provides a framework for merchants to benefit from Strong Customer Authentication (SCA) exemptions under certain conditions, such as payments below a certain threshold. An exemption from authentication for these "low-risk" transactions means a customer can avoid an extra step in the payment process. Merchants can also seek exemptions for other low-risk transaction scenarios (for example, recurring fixed-amount subscriptions) in coordination with their Acquirer.

With our Exemption Optimization Service (EOS) solution, Global Payments can perform real-time Transaction Risk Analysis (TRA) and respond with an outcome on exemption eligibility. If the response indicates eligibility, we ensure that the exemption request is flagged appropriately in the authentication message to the customer’s card Issuer.

 

Tabs
HPP

When a merchant requests an exemption (whether via authentication or directly in authorization) and it's successfully applied, they'll no longer be able to avail of a liability shift if a fraud-related chargeback occurs.

info

TRA outcomes

Global Payments TRA responds to exemption requests with one of four outcomes:

Outcome Description
APPLY_EXEMPTION The transaction was approved for an exemption. Global Payments 3D Secure 2 EOS solution will include the appropriate exemption flag in the authentication message that is sent, via the card scheme’s Directory Server, to the Issuer’s Access Control Server.
CONTINUE The transaction was not approved for an exemption but was deemed to be relatively low risk. Global Payments will process the transaction as a standard 3D Secure authentication. In this scenario, the Issuer can still choose to apply the exemption.
FORCE_SECURE The transaction was not approved for an exemption and was deemed to be high risk. Global Payments will process the transaction as a challenge-mandated 3D Secure authentication (that is, the Challenge Request Indicator field is set to CHALLENGE_MANDATED). In this scenario, the Issuer should always apply an SCA challenge to authenticate the cardholder.
BLOCK The transaction was identified as very high risk or known fraud. Global Payments will not proceed with 3D Secure 2 authentication and recommends that this transaction not be processed further.

In the event that the TRA result is BLOCK, authentication will not be performed. In this scenario, your application or website will receive a 110 response, indicating that, although the request was valid, the authentication and authorization requests were not sent. 

[RESULT=110,
 AUTHCODE=,
 MESSAGE= Blocked by Transaction Risk Analysis,
 PASREF=,
 AVSPOSTCODERESULT=,
 AVSADDRESSRESULT=,
 CVNRESULT=,
 ACCOUNT=internet,
 MERCHANT_ID=MerchantId,
 ORDER_ID=N6qsk4kYRZihmPrTXWYS6g,
 TIMESTAMP=20180613113227,
 AMOUNT=1001,
 BATCHID=-1,
 CARD_PAYMENT_BUTTON=Pay Invoice,
 MERCHANT_RESPONSE_URL=https://www.example.com/responseUrl,
 HPP_LANG=GB,
 ECI=
 AUTHENTICATION_VALUE=,
 DS_TRANS_ID=,
 MESSAGE_VERSION=,
HPP_BILLING_STREET1=Flat 123,
 HPP_BILLING_CITY=Halifax,
 HPP_BILLING_COUNTRY=826,
 HPP_BILLING_POSTALCODE=W5 9HR,
HPP_CUSTOMER_FIRSTNAME=CardHolderFirstName, 
HPP_CUSTOMER_LASTNAME=CardHolderLastName, 
 HPP_CUSTOMER_EMAIL=CardHolderFirstName@domain.com,  HPP_CHALLENGE_REQUEST_INDICATOR=NO_CHALLENGE_REQUESTED, HPP_ENABLE_EXEMPTION_OPTIMIZATION=TRUE
 SHA1HASH=8ab81d4437e24a88a08cffb51c15151846bd7b61]

Request an exemption 

After you enable our EOS solution through your account manager or support agent, Global Payments will automatically perform TRA on every 3D Secure 2 authentication request you process. If you prefer to control whether TRA is performed for a given transaction, you can use the applicable field value below in the HPP additional fields to either enable or disable EOS.

Field Description
HPP_ENABLE_EXEMPTION_OPTIMIZATION True - Enables Global Payments to perform risk analysis for this transaction to determine if an SCA exemption can be applied.
 

False - Disables Global Payments risk analysis for this transaction.

 

Interpret the response 

For an exemption sought through the HPP request, the response code indicates whether the Issuer approved the authorization. 

You can identify if the authorization used an exemption by referring to the ECI and AUTHENTICATION_VALUE fields in the HPP response. 

Exemption Accepted response: Visa 

Exemption Name ECI Authentication Value
Transaction Risk Analysis (TRA) 07
or blank
Present

Exemption Accepted response: Mastercard 

Exemption Name ECI Authentication Value
Transaction Risk Analysis (TRA) 06 Leading indicator is kN

Only Issuers supporting 3DS 2.2 (for Visa and Mastercard) and 3DS 2.1 + Message Extensions (for Mastercard) can support merchant exemption requests.

info

Test in Sandbox 

In the Production environment, the TRA outcome is determined by the overall analysis of the provided transaction data. However, for Sandbox testing, you need to trigger an outcome by setting the transaction amount value within a specific range, as indicated below.

Outcome Trigger Notes
APPLY_EXEMPTION Amount is less than or equal to 250 EUR (or converted equivalent) The 3D Secure service will populate the outbound authentication message with the appropriate exemption flag.
CONTINUE Amount is above 250 EUR and less than or equal to 500 EUR (or converted equivalent) The 3D Secure service will populate the outbound authentication as normal.
FORCE_SECURE Amount is above 500 EUR and less than or equal to 750 EUR (or converted equivalent) The 3D Secure service will populate the outbound authentication message indicating a challenge is mandated. This will always force a challenge to be applied, regardless of test card used.
BLOCK Amount is above 750 EUR (or converted equivalent) The transaction will be blocked, and a 110 response will be returned.

In Sandbox, the Access Control Server simulator will not accept the exemption request and will process the authentication as standard. The Electronic Commerce Indicator and Transaction Status values will remain as described in our Test Cards article.

info
Unavailable
Off
API

When a merchant requests an exemption (whether via authentication or directly in authorization) and it's successfully applied, they'll no longer be able to avail of a liability shift if a fraud-related chargeback occurs.

info

TRA outcomes

Global Payments TRA responds to exemption requests with one of four outcomes:


In the event that the TRA result is BLOCK, authentication will not be performed. In this scenario, your application or website will receive the HTTP response code 202 Accepted, indicating that, although the request was valid, the authentication request was not sent. The response code will also indicate the outcome:

{
   "eos_reason": "Blocked by Transaction Risk Analysis"  
}

Request an exemption

After you enable our EOS solution through your account manager or support agent, Global Payments will automatically perform TRA on every 3D Secure 2 authentication request you process. If you prefer to control whether TRA is performed for a given transaction, you can use the applicable field value below in your Initiate Authentication request to either enable or disable EOS.

curl https://api.sandbox.globalpay-ecommerce.com/3ds2/authentications
-H "Content-type: application/json"
-H "X-GP-VERSION: 2.2.0"
-H "Authorization: securehash abafc599cfa60c94b8f41d0668dac5ed6b0a21f7"
-X POST
-d '{
   "request_timestamp": "2019-07-30T08:52:44.991911",
   "authentication_source": "BROWSER",
   "authentication_request_type": "PAYMENT_TRANSACTION",
   "message_category": "PAYMENT_AUTHENTICATION",
   "message_version": "2.2.0",
   "challenge_request_indicator":"NO_PREFERENCE",
   "enable_exemption_optimization":"true"
   "server_trans_id": "ad0fffeb-bfff-44d0-881f-b857fe77c5a2",
   "merchant_id": "MerchantId",
   "account_id": "internet",
   "card_detail": {
      "number": "4263970000005262",
      "scheme": "VISA",
      "expiry_month": "10",
      "expiry_year": "25",
      "full_name": "James Mason"
   },
   "order": {
      "date_time_created": "2019-04-26T10:19:32.552327Z",
      "amount": "1001",
      "currency": "EUR",
      "id": "3400dd37-101d-4940-be15-3c963b6109b3",
      "address_match_indicator": "false",
      "shipping_address": {
         "line1": "Apartment 852",
         "line2": "Complex 741",
         "line3": "House 963",
         "city": "Chicago",
         "postal_code": "50001",
         "state": "IL",
         "country": "840"
      }
   },
   "payer": {
      "email": "james.mason@example.com",
      "billing_address": {
         "line1": "Flat 456",
         "line2": "House 456",
         "line3": "Unit 4",
         "city": "Halifax",
         "postal_code": "W5 9HR",
         "country": "826"
      },
      "mobile_phone": {
         "country_code": "44",
         "subscriber_number": "7123456789"
      }
   },
   "challenge_notification_url": "https://www.example.com/challengeNotificationUrl",
   "method_url_completion": "YES",
   "browser_data": {
      "accept_header": "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8",
      "color_depth": "TWENTY_FOUR_BITS",
      "ip": "123.123.123.123",
      "java_enabled": "true",
      "javascript_enabled": "true",
      "language": "en-US",
      "screen_height": "1080",
      "screen_width": "1920",
      "challenge_window_size": "FULL_SCREEN",
      "timezone": "0",
      "user_agent": "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36"
   },
   "merchant_contact_url": "https://www.example.com/about"
}'

Interpret the Issuer’s response

For an exemption sought through the 3D Secure 2 authentication request, the response indicates whether the Issuer granted the exemption.

{
    "server_trans_id": "ad0fffeb-bfff-44d0-881f-b857fe77c5a2",
    "acs_trans_id": "13c701a3-5a88-4c45-89e9-ef65e50a8bf9",
    "ds_trans_id": "c272b04f-6e7b-43a2-bb78-90f4fb94aa25",
    "authentication_value": "ODQzNjgwNjU0ZjM3N2JmYTg0NTM=",
    "eci": "07",
    "acs_rendering_type": {},
    "status": "AUTHENTICATION_SUCCESSFUL",
    "status_reason": "LOW_CONFIDENCE",
    "authentication_source": "BROWSER",
    "message_category": "PAYMENT_AUTHENTICATION",
    "message_version": "2.2.0",
    "message_extension": [
        {
            "name": "Sample Extension",
            "id": "B000000009-sampleExtension",
            "criticality_indicator": "false",
            "data": {
                "B000000009-sampleExtension": {
                    "sampleData": "sampleValue"
                }
            }
        }
    ],
    "acs_reference_number": "3DS_LOA_ACS_201_13579",
    "eos_reason": "APPLY_EXEMPTION"
}

Depending on the card type, one of the following response values would indicate that the Issuer has accepted the exemption request and approved the exemption.

Accepted response: Visa

 

Accepted response: Mastercard

Only Issuers supporting 3DS 2.2 (for Visa and Mastercard) and 3DS 2.1 + Message Extensions (for Mastercard) will be able to support merchant exemption requests.

info

Flag exemption in an authorization

After your TRA request receives an APPLY_EXEMPTION outcome response, you can then add the appropriate value to the Exempt Status Value field and proceed with authorization.

For all other 3D Secure 2 response outcomes, you should proceed with authentication as normal. For more information, see the API Reference for 3D Secure 2 Authentication Flows.

<?xml version="1.0" encoding="UTF-8"?>
<request type="auth" timestamp="20180613104233">
  <merchantid>MerchantId</merchantid>
  <account>internet</account>
  <orderid>AWfoT2k9TzuA0wn8Ze_IIQ</orderid>
  <amount currency="EUR">1000</amount>
  <card>
    <number>4263970000005262</number>
    <expdate>0525</expdate>
    <chname>Philip Marlowe</chname>
    <type>VISA</type>
    <cvn>
      <number>123</number>
      <presind>1</presind>
    </cvn>
  </card>
  <autosettle flag="1"/>
  <mpi>
    <eci>7</eci>
    <ds_trans_id>c272b04f-6e7b-43a2-bb78-90f4fb94aa25</ds_trans_id>
    <authentication_value>ODQzNjgwNjU0ZjM3N2JmYTg0NTM=</authentication_value>
    <message_version>2.2.0</message_version>
    <exempt_status>TRANSACTION_RISK_ANALYSIS</exempt_status> 
</mpi>
  <sha1hash>c87e5fa0858671510a02477d146ef744233e4ba8</sha1hash>
</request>

Test in Sandbox

In the production environment, the TRA outcome is determined by the overall analysis of the provided transaction data. However, for Sandbox testing, you need to trigger an outcome by setting the transaction amount value within a specific range, as indicated below.

In Sandbox, the Access Control Server simulator will not accept the exemption request and will process the authentication as standard. The Electronic Commerce Indicator and Transaction Status values will remain as described in the Test Cards section of the documentation.

info
Unavailable
Off
Internal Title
XML (Ecommerce Only)
Show Content Nav
On
Tags
Subtitle
Receive real-time exemption eligibility for transactions.