3D Secure: External Provider
Pass authentication values from a third-party 3D Secure vendor through to the gateway on your authorization call.
If you perform 3D Secure authentication through a third-party vendor before the transaction, you must pass the resulting authentication values to the gateway.
| Parameter | Description |
|---|---|
P3DS_CAVV Required |
Cardholder Authentication Verification Value. |
P3DS_ECI Required |
Electronic Commerce Indicator. |
P3DS_XID Required |
Transaction ID. |
P3DS_VERSION Required |
Reports on 3DS Version used to process Transaction (Required for Mastercard Identity Check transactions in Authorization on 3DS 2). |
P3DS_TRANSID Required |
Unique transaction identifier assigned by the Directory Server (DS) - (Required for Mastercard Identity Check transactions in Authorization IF P3DS_VERSION is 3DS 2). |
P3DS_SCREEN_HEIGHT Optional |
Total height of the cardholder's screen in pixels. |
P3DS_SCREEN_WIDTH Optional |
Total width of the cardholder's screen in pixels. |
P3DS_JAVA_ENABLED Optional |
A Boolean value (TRUE/FALSE) that represents the ability of the cardholder browser to execute Java. |
P3DS_JAVASCRIPT_ENABLED Optional |
A Boolean value (TRUE/FALSE) that represents the ability of the cardholder browser to execute JavaScript. |
P3DS_BROWSER_HEADER Optional |
The exact content of the HTTP accept headers sent from the cardholder's browser. Example: text/html,application/xhtml+xml,application/xml;q=0.9,*/*; q=0.8 |
P3DS_BROWSER_LANGUAGE Optional |
Value represents the browser language as defined in IETF BCP47. |
P3DS_BROWSER_COLOR_DEPTH Optional |
Value represents the bit depth of the color palette for displaying images, in bits per pixel. Possible Values: 1, 4, 8, 15, 16, 24, 32, 48. |
P3DS_BROWSER_TIME_ZONE Optional |
Time difference between UTC time and the cardholder browser local time, in minutes. Note: Regardless of direction value should be positive. |
P3DS_CHALLENGE_WINDOW Optional |
An override field that a merchant can pass in to set the challenge window size to display to the end cardholder. Possible values: 01 - 250x400, 02 - 390x400, 03 - 500x600, 04 - 600x400, 05 - Full page. |
USER_AGENT_XTL Optional |
Software agent responsible for retrieving and facilitating end-user interaction with Web content. |
XTL_IP Optional |
Cardholder's IP Address. |
These parameters are add-ons to a standard authorization call (for example CCAUTHCAP or CCAUTHORIZE), not a REQUEST_ACTION of their own. Attach them to the same request as your regular payment fields.
ThreeDSResult, the model for an externally-obtained 3DS authentication attached to a normal one-leg sale()/authorize(), exists only in the PHP SDK (Inovio\Gateway\Model\ThreeDSResult). Node, Python and Java carry BrowserData on the request and read the gateway's own challenge outcome from nextAction, but none of the three has an equivalent for attaching CAVV/ECI/XID values from a third-party 3DS provider. Use the cURL example directly in those languages, or see the SDKs.
curl -X POST "https://api.inoviopay.com/payment/pmt_service.cfm" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "request_action=CCAUTHCAP&req_username=api_user&req_password=P%40ssw0rd%21&site_id=12345&request_api_version=4.14&request_response_format=JSON&pmt_numb=4111111111111111&pmt_expiry=122026&pmt_key=123&request_currency=USD&li_value_1=49.99&xtl_order_id=INV-999&p3ds_cavv=[CAVV_FROM_YOUR_3DS_PROVIDER]&p3ds_eci=05&p3ds_xid=[XID_FROM_YOUR_3DS_PROVIDER]&p3ds_version=2.2.0&p3ds_transid=[DS_TRANSID_FROM_YOUR_3DS_PROVIDER]"
use Inovio\Gateway\{Credentials, InovioClient};
use Inovio\Gateway\Model\{LineItem, Money, PaymentMethods, ThreeDSResult};
use Inovio\Gateway\Request\TransactionRequest;
$client = new InovioClient(new Credentials('api_user', 'P@ssw0rd!', '12345'), 'SANDBOX');
$req = (new TransactionRequest(
PaymentMethods::card('4111111111111111', '122026', '123'),
[new LineItem('SKU-992', 1, Money::of('49.99', 'USD'))]
))->withIdempotency('INV-999');
// One leg, no redirect — the authentication already happened with your provider.
$req->threeDSResult = new ThreeDSResult(
cavv: '[CAVV_FROM_YOUR_3DS_PROVIDER]',
eci: '05',
transId: '[DS_TRANSID_FROM_YOUR_3DS_PROVIDER]',
version: '2.2.0',
xid: '[XID_FROM_YOUR_3DS_PROVIDER]'
);
$result = $client->sale($req);
match ($result->status) {
'APPROVED' => /* $result->threeDS->eci — 05/06 means full authentication (liability shift) */,
'DECLINED' => /* $result->outcome->service */,
default => /* PENDING | RUNNING | FAILED */,
};
{
"REQUEST_ACTION": "CCAUTHCAP",
"REQ_ID": "68192033",
"TRANS_STATUS_NAME": "APPROVED",
"TRANS_VALUE": 49.99,
"CURR_CODE_ALPHA": "USD",
"TRANS_VALUE_SETTLED": 49.99,
"CURR_CODE_ALPHA_SETTLED": "USD",
"TRANS_EXCH_RATE": "",
"TRANS_ID": 8839201112,
"CUST_ID": 9928102,
"XTL_CUST_ID": "cUsT992xP",
"PO_ID": 77281920,
"XTL_ORDER_ID": "INV-999",
"BATCH_ID": 882910,
"PROC_NAME": "Inovio Primary",
"MERCH_ACCT_ID": 110203,
"CARD_BRAND_NAME": "Mastercard",
"CARD_TYPE": "MASTERCARD BLACK CARD",
"CARD_CLASS": "Consumer Credit",
"CARD_PREPAID": 0,
"CARD_BANK": "CREDOMATIC INTERNATIONAL",
"CARD_COUNTRY": "CRI",
"CARD_DETAIL": "Credit",
"CARD_BALANCE": "",
"PMT_L4": "3535",
"PMT_ID": 8829102,
"PMT_ID_XTL": "",
"PMT_AAU_UPDATE_DT": "",
"PMT_AAU_UPDATE_DESC": "",
"PROC_UDF01": "",
"ANI_RESP_DECISION": "",
"PROC_UDF02": "",
"PROC_AUTH_RESPONSE": "AUTH99",
"PROC_RETRIEVAL_NUM": "1029384A-B8C7-D6E5-F4G3-H2I1J0K9L8M7",
"PROC_REFERENCE_NUM": "REF10293847",
"PROC_REDIRECT_URL": "",
"AVS_RESPONSE": "M",
"CVV_RESPONSE": "M",
"CARD_BRAND_TRANSID": "",
"REQUEST_API_VERSION": "4.14",
"P3DS_VENDOR": "[YOUR_3DS_PROVIDER]",
"P3DS_RESPONSE": "Y",
"PO_LI_ID_1": "8829103",
"PO_LI_COUNT_1": 1,
"PO_LI_AMOUNT_1": "49.99",
"PO_LI_PROD_ID_1": "SKU-992",
"MBSHP_ID_1": "88291",
"TRANS_NTOKEN_USED": 1
}