{"templateId":"markdown","versions":[{"version":"20261201","label":"(Preview) 2026-12-01","link":"/products/3ds/20261201/android-ios/challenge-verification","default":false,"active":false,"folderId":"9e210f12"},{"version":"v1","label":"v1","link":"/products/3ds/v1/android-ios/challenge-verification","default":false,"active":false,"folderId":"9e210f12"},{"version":"v2","label":"v2","link":"/products/3ds/v2/android-ios/challenge-verification","default":false,"active":true,"folderId":"9e210f12"},{"version":"v3","label":"v3 (Latest)","link":"/products/3ds/android-ios/challenge-verification","default":true,"active":false,"folderId":"9e210f12"}],"sharedDataIds":{"sidebar":"sidebar-products/3ds/sidebars.yaml","current-catalog-info":"current-catalog-info-/products/3ds/openapi"},"props":{"metadata":{"markdoc":{"tagList":["admonition","partial","tabs","tab","code-snippet"]},"custom_product":"3DS","type":"markdown"},"seo":{"title":"Challenge Display and Verification","description":"Worldpay for Developers - docs, code examples, resources and tools. Everything you need to build your omnichannel payment solution.","siteUrl":"https://docs.worldpay.com/access","image":"/access/assets/worldpay-logo-light.21b7daf79984773a9fcd7d4fbcb07ae5289dfffd6023c4c3dca720c7058e53dc.33f780a6.svg","keywords":"documentation, api, openapi, sdks, developer, payments, json, payouts, 3ds","jsonLd":{"@context":"https://schema.org","@type":"Organization","url":"https://docs.worldpay.com/access","name":"Worldpay"},"meta":[{"name":"google-site-verification","content":"zjziIKaP3ImsqsfhYnEBnq1R85UabiSwl7HTXuwtZuo"},{"name":"doc_product","content":"Access"},{"name":"doc_category","content":"Documentation"}],"llmstxt":{"hide":false,"sections":[{"title":"Payments API","description":"Payment orchestration API combining fraud assessment, 3ds authentication, SCA exemptions, Worldpay Token creation and a card or wallet based payment.","includeFiles":["products/payments/@20240601/**/*"],"excludeFiles":[]},{"title":"Payment Queries API","description":"Querying your payments data, based on a variety of parameters.","includeFiles":["products/payment-queries/@v1/**/*"],"excludeFiles":[]},{"title":"Card BIN Data API","description":"Provides detailed information about a card.","includeFiles":["products/card-bin/@v1/**/*"],"excludeFiles":[]},{"title":"3DS Authentication API","description":"Request 3DS authentication to protect against fraud, be SCA compliant and to shift liability using this standalone API.","includeFiles":["products/3ds/@v3/**/*"],"excludeFiles":[]},{"title":"FraudSight API","description":"Request a risk assessment and receive a response with an outcome (e.g. lowRisk) using this standalone API.","includeFiles":["products/fraudsight/@v1/**/*"],"excludeFiles":[]},{"title":"Checkout SDK","description":"Integrate using our clientside SDKs for both web and native devices. Benefit from SAQ-A/PCI-SSF compliance.","includeFiles":["products/checkout/web/@v2/**/*","products/checkout/ios/@v4/**/*","products/checkout/android/@v4/**/*","products/checkout/react-native/@v3/**/*","products/checkout/flutter/@v1/**/*"],"excludeFiles":[]},{"title":"Tokens API","description":"Minimizes the exposure of sensitive card details and increases the security of your customer's card details.","includeFiles":["products/tokens/@v3/**/*"],"excludeFiles":[]},{"title":"Card Payments API","description":"Request a card payment using this standalone API, requires separate requests for 3DS, Fraud assessment etc.","includeFiles":["products/card-payments/@v7/**/*"],"excludeFiles":[]},{"title":"Card Verifications API","description":"Verify your customer's card to maximize your authentication rates.","includeFiles":["products/card-verifications/@v6/**/*"],"excludeFiles":[]},{"title":"Account Payouts API","description":"Send funds to your customer's bank accounts and search for payouts using parameters.","includeFiles":["products/account-payouts/@20250101/**/*"],"excludeFiles":[]},{"title":"APMs","description":"Pay using eWallets, bank transfers, direct debits, local card schemes, Postpay and eInvoice/ Buy Now Pay Later.","includeFiles":["products/apms/@20240701/**/*"],"excludeFiles":[]},{"title":"Balance API","description":"Request your account details for a single account or all accounts under an entity.","includeFiles":["products/balance/@20250101/**/*"],"excludeFiles":[]},{"title":"Card Payouts API","description":"Send funds to your customer's cards.","includeFiles":["products/card-payouts/@v4/**/*"],"excludeFiles":[]},{"title":"Events (Webhooks)","description":"Receive status updates from Access Worldpay by setting up a webhook.","includeFiles":["products/events/@v1/**/*"],"excludeFiles":[]},{"title":"FX API","description":"Manage Foreign Exchange (FX) on your payments.","includeFiles":["products/fx/@v1/**/*"],"excludeFiles":[]},{"title":"Hosted Payment Pages (HPP) API","description":"Our low-code option to take payments securely at the lowest PCI compliance level - SAQ A.","includeFiles":["products/hosted-payment-pages/@v1/**/*"],"excludeFiles":[]},{"title":"Money Transfers API","description":"Money Transfer OCTs (Original Credit Transaction) allow funds to be pushed to an eligible card in 30 minutes or less.","includeFiles":["products/money-transfers/@v1/**/*"],"excludeFiles":[]},{"title":"Parties API","description":"Create parties, manage your payout instruments and beneficial owners and carry out identity verification checks.","includeFiles":["products/parties/@20250101/**/*"],"excludeFiles":[]},{"title":"SCA Exemptions API","description":"Maximize a frictionless checkout experience by using issuer data insights to apply exemptions.","includeFiles":["products/sca-exemptions/@v1/**/*"],"excludeFiles":[]},{"title":"Split Payments API","description":"Divide funds from a single payment amongst yourself and your parties/sellers.","includeFiles":["products/split-payments/@20250625/**/*"],"excludeFiles":[]},{"title":"Statements API","description":"Retrieve your account statement and see individual entries for all credits and debits.","includeFiles":["products/statements/@20250101/**/*"],"excludeFiles":[]},{"title":"Transfers API","description":"Transfer funds from source account to target account.","includeFiles":["products/transfers/@20250101/**/*"],"excludeFiles":[]},{"title":"Verified Tokens API","description":"Verified Tokens ensures that your customer's payment details are valid and CIT compliant when creating a token.","includeFiles":["products/verified-tokens/@v3/**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We have released a new version. Documentation for our latest version can be found ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/"},"children":["here"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Last updated"]},": 09 June 2026 | ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/changelog/"},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Change log"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"challenge-display-and-verification","__idx":0},"children":["Challenge Display and Verification"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If the authentication response ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["outcome"]}," is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["challenged"]}," and the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authentication.version"]}," is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.x.x"]}," (3DS2) you can use the SDK to provide the improved ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#3ds2-challenge-display"},"children":["3DS2 Challenge display"]}," for mobile devices."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authentication.version"]}," is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["1.x.x"]}," (3DS1) you must follow the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"#3ds1-challenge-display"},"children":["3DS1 Challenge display"]},". The integration more closely follows the steps for web."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"3ds2-challenge-display","__idx":1},"children":["3DS2 Challenge display"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authentication.version"]}," is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2.x.x"]}," you will need the following values from the authentication response to use in the SDK."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Access Name"},"children":["Access Name"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value from"},"children":["Value from"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Cardinal SDK Name"},"children":["Cardinal SDK Name"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["challenge.reference"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["authentication response"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["transactionId"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["challenge.payload"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["authentication response"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["payload"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The Access 3DS API will be periodically tested against the latest version of the Cardinal SDK. Current tested Cardinal SDK version: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v2.2.5"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"sdk-challenge-display","__idx":2},"children":["SDK challenge display:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://cardinaldocs.atlassian.net/wiki/spaces/CMSDK/pages/1998914544/Handle+the+Centinel+Lookup+Response+and+SDK+Handle+the+Challenge+UI+-+Android+-+V+2.2.5"},"children":["Android"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://cardinaldocs.atlassian.net/wiki/spaces/CMSDK/pages/2005696790/Handle+the+Centinel+Lookup+Response+and+SDK+handle+the+Challenge+UI+-+iOS+-+V+2.2.5"},"children":["iOS"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"customize-challenge-interface","__idx":3},"children":["Customize Challenge Interface"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["As part of SDK setup you can customize the challenge user interface"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://cardinaldocs.atlassian.net/wiki/spaces/CMSDK/pages/1998914483/Challenge+User+InterfaceCustomization+Android-+V+2.2.5"},"children":["Android"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://cardinaldocs.atlassian.net/wiki/spaces/CMSDK/pages/2005696657/Challenge+User+Interface+Customization+iOS+V+2.2.5"},"children":["iOS"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"3ds1-challenge-display","__idx":4},"children":["3DS1 Challenge display"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authentication.version"]}," is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["1.x.x"]}," use the following steps to display the challenge screen."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["3DS version 1 was implemented by issuers long before smartphones existed so offers a degraded experience compared to version 2. We expect version 1 traffic from issuers to drop during 2021."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"challenge-form-webview","__idx":5},"children":["Challenge form (webView)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["POST the request to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["challenge.url"]}," with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["challenge.jwt"]}," and optional ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["MD"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["MD"]}," field allows you to pass url parameters (max 1024 characters) in the challenge form that is included/echoed in the response url (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["challenge.returnUrl"]},")."]},{"$$mdtype":"Tag","name":"details","attributes":{},"children":[{"$$mdtype":"Tag","name":"summary","attributes":{},"children":["iOS"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Add a WKWebView to your Storyboard and UIViewController and enable JavaScript"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"@IBOutlet var webView: WKWebView!\noverride func viewDidLoad() {\n    super.viewDidLoad()\n    webView.configuration.preferences.javaScriptEnabled = true\n}\n"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Implement a method similar to the code snippet below in your UIViewController"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"let iframeSrcDoc = \"\"\"\n<html>\n  <body onload='document.frmLaunch.submit();'>\n    <form name='frmLaunch' method='POST' action='\\(challengeUrl)'>\n      <input type='hidden' name='JWT' value='\\(jwt)'>\n      <input type='hidden' name='MD' value='\\(md)'>\n    </form>\n  </body>\n</html>\n\"\"\"\n// A viewport meta tag is used to scale the content nicely to the device's screen size\nlet html = \"\"\"\n<html>\n  <head>\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\">\n  </head>\n  <body>\n    <iframe srcdoc=\"\\(iframeSrcDoc)\" width=\"100%\" height=\"400\" frameborder=\"0\">\n    </iframe>\n  </body>\n</html>\n\"\"\"\nwebView.loadHTMLString(html, baseURL: URL(string: \"about:srcdoc\")!)\n"},"children":[]}]},{"$$mdtype":"Tag","name":"details","attributes":{},"children":[{"$$mdtype":"Tag","name":"summary","attributes":{},"children":["Android"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Add a WebView to your fragment and enable JavaScript"]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"label":"Kotlin","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"override fun onViewCreated(view: View, savedInstanceState: Bundle?) {\n    super.onViewCreated(view, savedInstanceState)\n    val webView = view.findViewById<WebView>(...)\n    webView.settings.javaScriptEnabled = true\n}\n"},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Java","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"@Override\npublic void onViewCreated(View view, Bundle savedInstanceState) {\n    super.onViewCreated(view, savedInstanceState);\n    WebView webView = view.findViewById(...);\n    webView.getSettings().setJavaScriptEnabled(true);\n}\n"},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Implement a method similar to the code snippet below in your Fragment"]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"label":"Kotlin","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"val iframeSrcDoc = \"\"\"\n<html>\n  <body onload='document.frmLaunch.submit();'>\n    <form name='frmLaunch' method='POST' action='$challengeUrl'>\n      <input type='hidden' name='JWT' value='$jwt'>\n      <input type='hidden' name='MD' value='$md'>\n    </form>\n  </body>\n</html>\n\"\"\"\n// A viewport meta tag is used to scale the content nicely to the device's screen size\nval html = \"\"\"\n<html>\n  <head>\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\">\n  </head>\n  <body>\n    <iframe srcdoc=\"$iframeSrcDoc\" width=\"100%\" height=\"400\" frameborder=\"0\">\n    </iframe>\n  </body>\n</html>\n\"\"\"\nwebView.loadData(html, \"text/html; charset=utf-8\", \"UTF-8\")\n"},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Java","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"String challengeUrl = \"add challengeUrl here\";\nString iframeSrcDoc = \"<html>\" +\n        \"<body onload='document.frmLaunch.submit();'>\" +\n        \"<form name='frmLaunch' method='POST' action='\" + challengeUrl + \"'>\" +\n        \"<input type='hidden' name='JWT' value='\" + jwt + \"'>\" +\n        \"<input type='hidden' name='MD' value='\" + md + \"'>\" +\n        \"</form>\" +\n        \"</body>\" +\n        \"</html>\";\n// A viewport meta tag is used to scale the content nicely to the device's screen size\nString html = \"<html>\" +\n        \"<head>\" +\n        \"<meta name=\\\"viewport\\\" content=\\\"width=device-width, initial-scale=1\\\">\" +\n        \"</head>\" +\n        \"<iframe srcdoc=\\\"\" + iframeSrcDoc + \"\\\" width=\\\"100%\\\" height=\\\"400\\\" frameborder=\\\"0\\\">\" +\n        \"</iframe>\" +\n        \"</body>\" +\n        \"</html>\";\nwebView.loadData(html, \"text/html; charset=utf-8\", \"UTF-8\");\n"},"children":[]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"intercept-challenge-return","__idx":6},"children":["Intercept challenge return"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Intercept the POST request to your ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["challenge.returnUrl"]}]},{"$$mdtype":"Tag","name":"details","attributes":{},"children":[{"$$mdtype":"Tag","name":"summary","attributes":{},"children":["iOS"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Have your UIViewController adopt the WKNavigationDelegate protocol"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Point the navigationDelegate property of your WKWebView to your UIViewController, just before the call to webView.loadHTMLString"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"webView.navigationDelegate = self\n"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Implement the following method in your UIViewController to be notified when the challenge has been completed"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"func webView(_ webView: WKWebView, decidePolicyFor navigationAction: WKNavigationAction, decisionHandler: @escaping (WKNavigationResponsePolicy) -> Void) {\n     if navigationAction.request.url!.absoluteString == \"<value of your challenge return url>\" {\n        // TODO: add your logic\n     }\n     decisionHandler(.allow)\n}\n"},"children":[]}]},{"$$mdtype":"Tag","name":"details","attributes":{},"children":[{"$$mdtype":"Tag","name":"summary","attributes":{},"children":["Android"]},"\nIntercept the POST request to your challenge return url\n",{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create a class that extends WebViewClient and override the onLoadResource method to be notified when the challenge has been completed"]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"label":"Kotlin","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"private class CustomWebViewClient: WebViewClient() {\n    override fun onLoadResource(view: WebView?, url: String?) {\n        if (url.toString() == \"<value of your challenge return url>\") {\n            // TODO: add your logic\n        }\n        super.onLoadResource(view, url)\n    }\n}\n"},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Java","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"private static class CustomWebViewClient extends WebViewClient {\n    @Override\n    public void onLoadResource(WebView view, String url) {\n        if (url.equals(\"<value of your challenge return url>\")) {\n            // TODO: add your logic\n        }\n        super.onLoadResource(view, url);\n    }\n}\n"},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Set the webViewClient property of your WebView to an instance of this class, just before the call to webView.loadData()"]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"label":"Kotlin","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"webView.webViewClient = CustomWebViewClient()\n"},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Java","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"webView.setWebViewClient(new CustomWebViewClient());\n"},"children":[]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"verification","__idx":7},"children":["Verification"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once the challenge has been completed, a verification request needs to be made to verify the result of the challenge."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You should only request the verification from your backend system, not call it directly from the mobile application using the Access credentials."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["POST your verification request to our ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["3ds:verify"]}," action link received in your authentication response."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"verification-example-request","__idx":8},"children":["Verification example request"]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You must use ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["v2"]}," and later of the API for the Android/iOS SDK"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["POST ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://try.access.worldpay.com/verifications/customers/3ds/verification"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Verification request body:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../code/verification-request.json","language":"json","header":{"controls":{"copy":{}}},"lang":"json","source":"{\n    \"transactionReference\": \"unique-transactionReference\",\n    \"merchant\": {\n        \"entity\": \"default\"\n    },\n    \"challenge\": {\n        \"reference\": \"123456789\"\n    }\n}"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"verification-responses","__idx":9},"children":["Verification responses"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Here are examples of the verification responses you would receive."]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"label":"Authenticated","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../code/verification-response-authenticated.json","language":"json","header":{"controls":{"copy":{}}},"lang":"json","source":"{\n    \"outcome\": \"authenticated\",\n    \"transactionReference\": \"unique-transactionReference\",\n    \"authentication\": {\n        \"version\": \"2.1.0\",\n        \"authenticationValue\": \"MAAAAAAAAAAAAAAAAAAAAAAAAAA=\",\n        \"eci\": \"05\",\n        \"transactionId\": \"c5b808e7-1de1-4069\"\n    }\n}\n"},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Authentication Failed","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../code/verification-response-authentication-failed.json","language":"json","header":{"controls":{"copy":{}}},"lang":"json","source":"{\n    \"outcome\": \"authenticationFailed\",\n    \"transactionReference\": \"unique-transactionReference\",\n    \"authentication\": {\n      \"version\": \"1.0.2\",\n      \"eci\": \"00\",\n      \"transactionId\": \"N+en2I5+ZK/kQqk69wXdI8XIPg8=\"\n    },\n    \"_links\": {\n        \"3ds:authenticate\": {\n            \"href\": \"https://try.access.worldpay.com/verifications/customers/3ds/authentication\"\n        },\n        \"curies\": [{\n            \"href\": \"https://try.access.worldpay.com/rels/verifications/customers/3ds/{rel}\",\n            \"templated\": true,\n            \"name\": \"3ds\"\n        }]\n    }\n}\n"},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Signature Failed","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../code/verification-response-signature-failed.json","language":"json","header":{"controls":{"copy":{}}},"lang":"json","source":"{\n    \"outcome\": \"signatureFailed\",\n    \"transactionReference\": \"unique-transactionReference\",\n    \"authentication\": {\n      \"version\": \"1.0.2\",\n      \"eci\": \"02\"\n    },\n    \"_links\": {\n        \"3ds:authenticate\": {\n            \"href\": \"https://try.access.worldpay.com/verifications/customers/3ds/authentication\"\n        },\n        \"curies\": [{\n            \"href\": \"https://try.access.worldpay.com/rels/verifications/customers/3ds/{rel}\",\n            \"templated\": true,\n            \"name\": \"3ds\"\n        }]\n    }\n}\n"},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Unavailable","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../code/verification-response-unavailable.json","language":"json","header":{"controls":{"copy":{}}},"lang":"json","source":"{\n    \"outcome\": \"unavailable\",\n    \"transactionReference\": \"unique-transactionReference\",\n    \"_links\": {\n        \"3ds:authenticate\": {\n            \"href\": \"https://try.access.worldpay.com/verifications/customers/3ds/authentication\"\n        },\n        \"3ds:verify\": {\n            \"href\": \"https://try.access.worldpay.com/verifications/customers/3ds/verification\"\n        },\n        \"curies\": [{\n            \"href\": \"https://try.access.worldpay.com/rels/verifications/customers/3ds/{rel}\",\n            \"templated\": true,\n            \"name\": \"3ds\"\n        }]\n    }\n}"},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Bypassed","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../code/verification-response-bypassed.json","language":"json","header":{"controls":{"copy":{}}},"lang":"json","source":"{\n  \"outcome\": \"bypassed\",\n  \"transactionReference\": \"6032c024-8d33-4e89-98e9-a944f66c3906\",\n  \"authentication\": {\n    \"version\": \"2.1.0\",\n    \"eci\": \"00\",\n    \"transactionId\": \"c5b808e7-1de1-4069-a17b-f70d3b3b1645\"\n  }\n}\n"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Warning"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You cannot re-use the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authenticationValue"]}," in multiple authorization requests. Re-using the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authenticationValue"]}," in this way will result in issuer declines and may incur fees."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the values: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["version"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authenticationValue"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["eci"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["transactionId"]}," from the request when ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/card-payments/v6/authorize-a-payment#authorize-a-payment"},"children":["authorizing a payment"]},". The values prove that the verification was successful, and that the fraud liability has shifted to the issuer."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Parameter"},"children":["Parameter"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authentication.version"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The version of 3DS used to process the transaction.",{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[" Required for Mastercard's Identity Check transactions in Authorization."]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authentication.authenticationValue"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A cryptographic value that provides evidence of the outcome of a 3DS verification.",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Visa - Cardholder Authentication Verification Value (CAVV)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Mastercard - Universal Cardholder Authentication Field (UCAF)"]}]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"Used when ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/card-payments/v6/authorize-a-payment"},"children":["authorizing a payment"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authentication.eci"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Electronic Commerce Indicator (ECI).",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"Indicates the outcome of the 3DS authentication.",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["02 or 05 - Fully Authenticated Transaction"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["01 or 06 - Attempted Authentication Transaction"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["00 or 07 - Non 3-D Secure Transaction"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"b","attributes":{},"children":["Mastercard"]}," - 02, 01, 00"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"b","attributes":{},"children":["Visa"]}," - 05, 06, 07"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"b","attributes":{},"children":["Amex"]}," - 05, 06, 07"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"b","attributes":{},"children":["JCB"]}," - 05, 06, 07"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"b","attributes":{},"children":["Diners"]}," - 05, 06, 07"]}]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}," You will need to use this when you are ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/card-payments/v6/authorize-a-payment"},"children":["authorizing a payment"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authentication.transactionId"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A transaction identifier.",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"If provided, you should use it as part of your ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/card-payments/v6/authorize-a-payment"},"children":["payment authorization"]},".",{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]},"If the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authentication.version"]}," has a major version of:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["1"]}," - value returned known as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["xid"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["2"]}," - value returned known as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["dsTransactionId"]}]}]}]}]}]}]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next steps"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/card-payments/v6/authorize-a-payment#3ds"},"children":["Take a payment"]},{"$$mdtype":"Tag","name":"br","attributes":{},"children":[]}]}]},"headings":[{"value":"Challenge Display and Verification","id":"challenge-display-and-verification","depth":1},{"value":"3DS2 Challenge display","id":"3ds2-challenge-display","depth":2},{"value":"SDK challenge display:","id":"sdk-challenge-display","depth":3},{"value":"Customize Challenge Interface","id":"customize-challenge-interface","depth":3},{"value":"3DS1 Challenge display","id":"3ds1-challenge-display","depth":2},{"value":"Challenge form (webView)","id":"challenge-form-webview","depth":4},{"value":"Intercept challenge return","id":"intercept-challenge-return","depth":4},{"value":"Verification","id":"verification","depth":1},{"value":"Verification example request","id":"verification-example-request","depth":2},{"value":"Verification responses","id":"verification-responses","depth":2}],"frontmatter":{"seo":{"title":"Challenge Display and Verification"}},"lastModified":"2026-03-11T10:08:16.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/3ds/v2/android-ios/challenge-verification","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}