{"templateId":"markdown","versions":[{"version":"20261201","label":"(Preview) 2026-12-01","link":"/products/3ds/20261201/web/device-data","default":false,"active":false,"folderId":"9e210f12"},{"version":"v1","label":"v1","link":"/products/3ds/v1/web/device-data","default":false,"active":false,"folderId":"9e210f12"},{"version":"v2","label":"v2","link":"/products/3ds/v2/web/device-data","default":false,"active":false,"folderId":"9e210f12"},{"version":"v3","label":"v3 (Latest)","link":"/products/3ds/web/device-data","default":true,"active":true,"folderId":"9e210f12"}],"sharedDataIds":{"sidebar":"sidebar-products/3ds/sidebars.yaml","current-catalog-info":"current-catalog-info-/products/3ds/openapi","oas-products/3ds/@v3/openapi.yaml":"oas-products/3ds/@v3/openapi.yaml"},"props":{"metadata":{"markdoc":{"tagList":["partial","admonition","tabs","tab","openapi-code-sample","json-schema","code-snippet","embeddable"]},"custom_product":"3DS","type":"markdown"},"seo":{"title":"Device Data (Web) | 3DS API","description":"Worldpay for Developers - docs, code examples, resources and tools. Everything you need to build your omnichannel payment solution.","siteUrl":"https://docs.worldpay.com/access","image":"/access/assets/worldpay-logo-light.21b7daf79984773a9fcd7d4fbcb07ae5289dfffd6023c4c3dca720c7058e53dc.33f780a6.svg","keywords":"documentation, api, openapi, sdks, developer, payments, json, payouts, 3ds","jsonLd":{"@context":"https://schema.org","@type":"Organization","url":"https://docs.worldpay.com/access","name":"Worldpay"},"meta":[{"name":"google-site-verification","content":"zjziIKaP3ImsqsfhYnEBnq1R85UabiSwl7HTXuwtZuo"},{"name":"doc_product","content":"Access"},{"name":"doc_category","content":"Documentation"}],"llmstxt":{"hide":false,"sections":[{"title":"Payments API","description":"Payment orchestration API combining fraud assessment, 3ds authentication, SCA exemptions, Worldpay Token creation and a card or wallet based payment.","includeFiles":["products/payments/@20240601/**/*"],"excludeFiles":[]},{"title":"Payment Queries API","description":"Querying your payments data, based on a variety of parameters.","includeFiles":["products/payment-queries/@v1/**/*"],"excludeFiles":[]},{"title":"Card BIN Data API","description":"Provides detailed information about a card.","includeFiles":["products/card-bin/@v1/**/*"],"excludeFiles":[]},{"title":"3DS Authentication API","description":"Request 3DS authentication to protect against fraud, be SCA compliant and to shift liability using this standalone API.","includeFiles":["products/3ds/@v3/**/*"],"excludeFiles":[]},{"title":"FraudSight API","description":"Request a risk assessment and receive a response with an outcome (e.g. lowRisk) using this standalone API.","includeFiles":["products/fraudsight/@v1/**/*"],"excludeFiles":[]},{"title":"Checkout SDK","description":"Integrate using our clientside SDKs for both web and native devices. Benefit from SAQ-A/PCI-SSF compliance.","includeFiles":["products/checkout/web/@v2/**/*","products/checkout/ios/@v4/**/*","products/checkout/android/@v4/**/*","products/checkout/react-native/@v3/**/*","products/checkout/flutter/@v1/**/*"],"excludeFiles":[]},{"title":"Tokens API","description":"Minimizes the exposure of sensitive card details and increases the security of your customer's card details.","includeFiles":["products/tokens/@v3/**/*"],"excludeFiles":[]},{"title":"Card Payments API","description":"Request a card payment using this standalone API, requires separate requests for 3DS, Fraud assessment etc.","includeFiles":["products/card-payments/@v7/**/*"],"excludeFiles":[]},{"title":"Card Verifications API","description":"Verify your customer's card to maximize your authentication rates.","includeFiles":["products/card-verifications/@v6/**/*"],"excludeFiles":[]},{"title":"Account Payouts API","description":"Send funds to your customer's bank accounts and search for payouts using parameters.","includeFiles":["products/account-payouts/@20250101/**/*"],"excludeFiles":[]},{"title":"APMs","description":"Pay using eWallets, bank transfers, direct debits, local card schemes, Postpay and eInvoice/ Buy Now Pay Later.","includeFiles":["products/apms/@20240701/**/*"],"excludeFiles":[]},{"title":"Balance API","description":"Request your account details for a single account or all accounts under an entity.","includeFiles":["products/balance/@20250101/**/*"],"excludeFiles":[]},{"title":"Card Payouts API","description":"Send funds to your customer's cards.","includeFiles":["products/card-payouts/@v4/**/*"],"excludeFiles":[]},{"title":"Events (Webhooks)","description":"Receive status updates from Access Worldpay by setting up a webhook.","includeFiles":["products/events/@v1/**/*"],"excludeFiles":[]},{"title":"FX API","description":"Manage Foreign Exchange (FX) on your payments.","includeFiles":["products/fx/@v1/**/*"],"excludeFiles":[]},{"title":"Hosted Payment Pages (HPP) API","description":"Our low-code option to take payments securely at the lowest PCI compliance level - SAQ A.","includeFiles":["products/hosted-payment-pages/@v1/**/*"],"excludeFiles":[]},{"title":"Money Transfers API","description":"Money Transfer OCTs (Original Credit Transaction) allow funds to be pushed to an eligible card in 30 minutes or less.","includeFiles":["products/money-transfers/@v1/**/*"],"excludeFiles":[]},{"title":"Parties API","description":"Create parties, manage your payout instruments and beneficial owners and carry out identity verification checks.","includeFiles":["products/parties/@20250101/**/*"],"excludeFiles":[]},{"title":"SCA Exemptions API","description":"Maximize a frictionless checkout experience by using issuer data insights to apply exemptions.","includeFiles":["products/sca-exemptions/@v1/**/*"],"excludeFiles":[]},{"title":"Split Payments API","description":"Divide funds from a single payment amongst yourself and your parties/sellers.","includeFiles":["products/split-payments/@20250625/**/*"],"excludeFiles":[]},{"title":"Statements API","description":"Retrieve your account statement and see individual entries for all credits and debits.","includeFiles":["products/statements/@20250101/**/*"],"excludeFiles":[]},{"title":"Transfers API","description":"Transfer funds from source account to target account.","includeFiles":["products/transfers/@20250101/**/*"],"excludeFiles":[]},{"title":"Verified Tokens API","description":"Verified Tokens ensures that your customer's payment details are valid and CIT compliant when creating a token.","includeFiles":["products/verified-tokens/@v3/**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":["openapi"],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Last updated"]},": 09 June 2026 | ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/changelog/"},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Change log"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"device-data","__idx":0},"children":["Device Data"]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The card issuer uses Device Data Collection (DDC) to fingerprint the customer's device."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Along with the risk data in the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/web/authentication"},"children":["authentication"]}," request, it's used to decide if a ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/web/challenge-verification"},"children":["challenge"]}," is needed or if the authentication can be frictionless (no challenge displayed to your customer)."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Important"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Invoke this process immediately upon the customer providing their payment credentials. This ensures that DDC processes asynchronously behind the scenes as the customer completes the remaining checkout process. If a customer changes their card number after the DDC process is started or completed, re-execute the entire DDC process."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"device-data-initialization","__idx":1},"children":["Device data initialization"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["POST"]}," your device data initialization request to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["3ds:deviceDataInitialize"]}," action link."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This request creates a JSON Web Token (JWT) that is used as part of the DDC form. The DDC form also requires the first six digits of your customer's card number (BIN). The BIN can be returned if a token resource is provided, see ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["JWT + BIN (token)"]}," request."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For consistency of integration you can also provide the full card number ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["JWT + BIN (card)"]},"  or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["JWT + BIN (Network Token)"]},". It is truncated to become the BIN in the response."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"device-data-initialization-example-request","__idx":2},"children":["Device data initialization example request"]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"label":"Card (JWT + BIN)","disable":false},"children":[{"$$mdtype":"Tag","name":"OpenApiCodeSample","attributes":{"descriptionFile":"oas-products/3ds/@v3/openapi.yaml","operationId":"deviceDataInitialize","exampleKey":"card/front","parameters":{},"environments":{}},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Token (JWT + BIN)","disable":false},"children":[{"$$mdtype":"Tag","name":"OpenApiCodeSample","attributes":{"descriptionFile":"oas-products/3ds/@v3/openapi.yaml","operationId":"deviceDataInitialize","exampleKey":"card/tokenized","parameters":{},"environments":{}},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Network Token (JWT + BIN)","disable":false},"children":[{"$$mdtype":"Tag","name":"OpenApiCodeSample","attributes":{"descriptionFile":"oas-products/3ds/@v3/openapi.yaml","operationId":"deviceDataInitialize","exampleKey":"card/networkToken","parameters":{},"environments":{}},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Google Pay (JWT + BIN)","disable":false},"children":[{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Best practice"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://developers.google.com/pay/api/web/reference/request-objects#CardParameters"},"children":["Set ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["assuranceDetails"]}," to \"true\""]}," in your request when integrating with the Google Pay API, to avoid attempting authentication on an SCA compliant token. A response containing ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["\"cardHolderAuthenticated\": true"]}," indicates that authentication is not required and you can proceed directly to the authorization and reduce friction in your payment flow."]}]},{"$$mdtype":"Tag","name":"OpenApiCodeSample","attributes":{"descriptionFile":"oas-products/3ds/@v3/openapi.yaml","operationId":"deviceDataInitialize","exampleKey":"card/wallet+googlepay","parameters":{},"environments":{}},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"JWT only","disable":false},"children":[{"$$mdtype":"Tag","name":"OpenApiCodeSample","attributes":{"descriptionFile":"oas-products/3ds/@v3/openapi.yaml","operationId":"deviceDataInitialize","exampleKey":"No payment instrument provided (only jwt returned)","parameters":{},"environments":{}},"children":[]}]}]},{"$$mdtype":"Tag","name":"JsonSchema","attributes":{"schema":{"$ref":"../openapi.yaml#/components/schemas/3DS_deviceDataInitialize"},"options":{"schemaExpansionLevel":0,"hideSchemaTitles":true,"hidePropertiesPrefix":true},"schemaResolved":{"openapi":"3.1.0","components":{"schemas":{"__root":{"$ref":"#/components/schemas/3DS_deviceDataInitialize"},"transactionReference":{"maxLength":64,"minLength":1,"pattern":"^[-A-Za-z0-9_!@#$%()*=.:;?\\[\\]{}~`/+]*$","type":"string","description":"A unique reference for authentication. For example, e-commerce order code. Use the same transactionReference across all 3 potential request types (deviceDataInitialization, authentication, verification)."},"merchant":{"required":["entity"],"type":"object","description":"An object that contains information about the merchant and API level configuration.","properties":{"entity":{"maxLength":64,"minLength":1,"pattern":"^[A-Za-z0-9 ]*$","type":"string","description":"Used to route the request in Access Worldpay, created as part of on-boarding."}}},"cardHolderName":{"maxLength":255,"minLength":1,"type":"string","description":"The name on your customer's card. This is not a mandatory field, however we recommend that you supply this to improve authentication rates."},"billingAddress":{"required":["address1","city","postalCode","countryCode"],"type":"object","description":"An object containing the billing address information.","properties":{"city":{"maxLength":15,"minLength":1,"type":"string","description":"Billing address city"},"address1":{"maxLength":80,"minLength":1,"type":"string","description":"Billing address line 1"},"postalCode":{"maxLength":15,"minLength":1,"type":"string","description":"Billing address postal code, [See country codes with optional postalCode](/products/reference/supported-countries-currencies#postalcode-optional)"},"countryCode":{"maxLength":2,"minLength":2,"pattern":"^[A-Z]{2}$","type":"string","description":"Billing address country code"},"state":{"maxLength":30,"minLength":1,"type":"string","description":"Billing address state. Should only be provided following the `ISO-3611-2` two-character sub division (e.g.“CA” for California). We recommend you provide this for US and China addresses."},"address2":{"maxLength":80,"type":"string","description":"Billing address line 2"},"address3":{"maxLength":80,"type":"string","description":"Billing address line 3"}}},"card_front":{"required":["type","cardNumber","cardExpiryDate"],"type":"object","properties":{"type":{"type":"string","format":"card/front","description":"An identifier for the `paymentInstrument` being used."},"cardHolderName":{"$ref":"#/components/schemas/cardHolderName"},"cardExpiryDate":{"required":["month","year"],"type":"object","description":"Object containing card expiry information","properties":{"month":{"maximum":12,"minimum":1,"type":"integer","description":"Card expiry month"},"year":{"maximum":9999,"minimum":1,"type":"integer","description":"Card expiry year"}}},"cardNumber":{"maxLength":19,"minLength":10,"pattern":"^[0-9]*$","type":"string","description":"Clear card number (PAN)"},"billingAddress":{"$ref":"#/components/schemas/billingAddress"}}},"card_tokenized":{"required":["type","href"],"type":"object","properties":{"type":{"type":"string","format":"card/tokenized","description":"An identifier for the `paymentInstrument` being used."},"href":{"minLength":1,"type":"string","description":"An `http` address that contains your link to an Access Token"}}},"card_networktoken":{"required":["type","tokenNumber","cardExpiryDate"],"type":"object","properties":{"type":{"type":"string","format":"card/networkToken","description":"An identifier for the `paymentInstrument` being used."},"cardExpiryDate":{"required":["month","year"],"type":"object","description":"Object containing card expiry information","properties":{"month":{"maximum":12,"minimum":1,"type":"integer","description":"Card expiry month"},"year":{"maximum":9999,"minimum":1,"type":"integer","description":"Card expiry year"}}},"tokenNumber":{"maxLength":19,"minLength":10,"pattern":"^[0-9]*$","type":"string","description":"The network token number"},"cardHolderName":{"$ref":"#/components/schemas/cardHolderName"},"billingAddress":{"$ref":"#/components/schemas/billingAddress"}}},"card_wallet_googlepay":{"required":["type","walletToken"],"type":"object","properties":{"type":{"enum":["card/wallet+googlepay"],"type":"string"},"walletToken":{"type":"string","description":"The encrypted wallet token returned by Google","example":"{\"protocolVersion\":\"ECv1\",\"signature\":\"MEQCIH6Q4OwQ0jAceFEkGF0JID6sJNXxOEi4r+mA7biRxqBQAiAondqoUpU/bdsrAOpZIsrHQS9nwiiNwOrr24RyPeHA0Q\\u003d\\u003d\",\"signedMessage\":\"{\\\"tag\\\":\\\"jpGz1F1Bcoi/fCNxI9n7Qrsw7i7KHrGtTf3NrRclt+U\\\\u003d\\\",\\\"ephemeralPublicKey\\\":\\\"BJatyFvFPPD21l8/uLP46Ta1hsKHndf8Z+tAgk+DEPQgYTkhHy19cF3h/bXs0tWTmZtnNm+vlVrKbRU9K8+7cZs\\\\u003d\\\",\\\"encryptedMessage\\\":\\\"mKOoXwi8OavZ\\\"}\"}"},"billingAddress":{"required":["postalCode","countryCode"],"type":"object","description":"Contains the billing address information.","properties":{"address1":{"type":"string","description":"First line of the address. Required if `city` is provided."},"address2":{"type":"string","description":"Second line of the address."},"address3":{"type":"string","description":"Third line of the address."},"city":{"type":"string","description":"City. Required if `address1` is provided."},"postalCode":{"type":"string","description":"Post code. Required, but an empty value can be provided for specific countries (e.g., `IE`)."},"state":{"type":"string","description":"State/province in max 3 characters."},"countryCode":{"type":"string","description":"Must be provided in [ISO 3166-1 Alpha-2 format](/products/reference/supported-countries-currencies#iso-country-codes)."}}}}},"3DS_deviceDataInitialize":{"required":["transactionReference","merchant"],"type":"object","properties":{"transactionReference":{"$ref":"#/components/schemas/transactionReference"},"merchant":{"$ref":"#/components/schemas/merchant"},"paymentInstrument":{"oneOf":[{"$ref":"#/components/schemas/card_front"},{"$ref":"#/components/schemas/card_tokenized"},{"$ref":"#/components/schemas/card_networktoken"},{"$ref":"#/components/schemas/card_wallet_googlepay"}],"discriminator":{"mapping":{"card/front":"#/components/schemas/card_front","card/tokenized":"#/components/schemas/card_tokenized","card/networkToken":"#/components/schemas/card_networktoken","card/wallet+googlepay":"#/components/schemas/card_wallet_googlepay"},"propertyName":"type"}}}}}}},"schemaResolvedErrors":[]},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"device-data-initialization-response","__idx":3},"children":["Device data initialization response"]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Best practice"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Access Worldpay returns a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["WP-CorrelationId"]}," in the headers of service responses. We ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["highly recommend"]}," you log this. The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["WP-CorrelationId"]}," is used by us to examine individual service requests."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To understand what these outcomes mean and how to reproduce them for testing purposes see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/testing"},"children":["3DS testing"]}]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"size":"medium"},"children":[{"$$mdtype":"Tag","name":"div","attributes":{"label":"JWT + BIN returned","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../examples/responses/ddc-jwt-bin.yaml","language":"json","title":"JWT & BIN returned","header":{"title":"JWT & BIN returned","controls":{"copy":{}}},"lang":"json","source":"  {\n      \"outcome\": \"initialized\",\n      \"transactionReference\": \"Memory265-13/08/1876\",\n      \"deviceDataCollection\": {\n          \"jwt\": \"eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJPcmdVbml0SWQiOiJPcmdVbml0IiwiaXNzIjoiYXBpSWQiLCJleHAiOjE1NjI5MjMzNDYsImlhdCI6MTU2MjkyMzQwNiwianRpIjoiYTAzMWVhOGEtN2E0Zi00YTQwLWI1NjMtOTUzMzYzMzVhZGNmIn0.0IK74OIXBxFsxqeOURJz1TFnz14ZTbFJTdTWo9cHUJQ\",\n          \"url\": \"https://ddcUrl.example.com\",\n          \"bin\": \"555555\"\n      },\n      \"_links\": {\n          \"3ds:authenticate\": {\n              \"href\": \"https://try.access.worldpay.com/verifications/customers/3ds/authentication\"\n          },\n          \"curies\": [\n              {\n                  \"href\": \"https://try.access.worldpay.com/rels/verifications/customers/3ds/{rel}\",\n                  \"templated\": true,\n                  \"name\": \"3ds\"\n              }\n          ]\n      }\n  }"},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"JWT only","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../examples/responses/ddc-jwt-only.yaml","language":"json","title":"Only JWT returned","header":{"title":"Only JWT returned","controls":{"copy":{}}},"lang":"json","source":"  {\n      \"outcome\": \"initialized\",\n      \"transactionReference\": \"Memory265-13/08/1876\",\n      \"deviceDataCollection\": {\n          \"jwt\": \"eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJPcmdVbml0SWQiOiJPcmdVbml0IiwiaXNzIjoiYXBpSWQiLCJleHAiOjE1NjI5MjMzNDYsImlhdCI6MTU2MjkyMzQwNiwianRpIjoiYTAzMWVhOGEtN2E0Zi00YTQwLWI1NjMtOTUzMzYzMzVhZGNmIn0.0IK74OIXBxFsxqeOURJz1TFnz14ZTbFJTdTWo9cHUJQ\",\n          \"url\": \"https://ddcUrl.example.com\"\n      },\n      \"_links\": {\n          \"3ds:authenticate\": {\n              \"href\": \"https://try.access.worldpay.com/verifications/customers/3ds/authentication\"\n          },\n          \"curies\": [\n              {\n                  \"href\": \"https://try.access.worldpay.com/rels/verifications/customers/3ds/{rel}\",\n                  \"templated\": true,\n                  \"name\": \"3ds\"\n              }\n          ]\n      }\n  }"},"children":[]}]},{"$$mdtype":"Tag","name":"div","attributes":{"label":"Token already authenticated","disable":false},"children":[{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../examples/responses/already-authenticated.yaml","language":"json","title":"Wallet token already authenticated","header":{"title":"Wallet token already authenticated","controls":{"copy":{}}},"lang":"json","source":"  {\n      \"outcome\": \"alreadyAuthenticated\",\n      \"transactionReference\": \"Memory265-13/08/1876\"\n  }"},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["DeviceDataCollection"]}," object will be used for the next step."]},{"$$mdtype":"Tag","name":"JsonSchema","attributes":{"schema":{"$ref":"../openapi.yaml#/components/schemas/deviceDataCollection"},"options":{"schemasExpansionLevel":2,"hideSchemaTitles":true,"hidePropertiesPrefix":true},"schemaResolved":{"openapi":"3.1.0","components":{"schemas":{"__root":{"$ref":"#/components/schemas/deviceDataCollection"},"deviceDataCollection":{"required":["jwt","url"],"type":"object","description":"Object containing device data collection related information","properties":{"jwt":{"maxLength":2048,"minLength":1,"type":"string","description":"A digitally signed token that contains additional details required for DDC."},"url":{"maxLength":2048,"minLength":1,"type":"string","description":"A `POST` action on the DDC form. Used to redirect to the issuers DDC page."},"bin":{"maxLength":6,"minLength":6,"type":"string","description":"First six digits of the card number (Bank Identification Number), used as part of DDC. Returned if a token resource, network payment token or card number is included in the request."}}}}}},"schemaResolvedErrors":[]},"children":[]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In case of an error, you can get further information in our ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/reference/worldpay-error-responses"},"children":["error reference"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"device-data-collection-ddc","__idx":4},"children":["Device Data Collection (DDC)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once you have the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["JWT"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["URL"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["BIN"]}," you can create and submit the DDC form."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The issuer uses a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SessionId"]}," representing this collection as part of the risk analysis in the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/web/authentication"},"children":["authentication request"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"test-data-collection-form","__idx":5},"children":["Test data collection form"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Here's an example of how you would set-up the DDC form in an iframe."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Create a hidden iframe and set the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["src"]}," attribute with the URL of the page that POSTs the DDC form."," ","This URL should contain in query string parameters the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["deviceDataCollection.jwt"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["deviceDataCollection.bin"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["deviceDataCollection.url"]}," as those are used in the DDC form."]}]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../examples/forms/ddc-iframe.html","language":"html","title":"iframe for DDC form","header":{"title":"iframe for DDC form","controls":{"copy":{}}},"lang":"html","source":"<iframe height=\"1\" width=\"1\" style=\"display: none;\" src=\"replace-this-with-the-url-of-your-page-that-posts-the-ddc-form\"></iframe>"},"children":[]},{"$$mdtype":"Tag","name":"ol","attributes":{"start":2},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Create and host the page that POSTs the DDC form."]}]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../examples/forms/ddc-form.html","language":"html","title":"DDC form","header":{"title":"DDC form","controls":{"copy":{}}},"lang":"html","source":"<html>\n<head>\n</head>\n<body>\n<!-- Using your preferred programming language, set the 'action' attribute with the value of the query string parameter containing the 'deviceDataCollection.url' from the device data initialization response -->\n<form id=\"collectionForm\" name=\"devicedata\" method=\"POST\" action=\"https://ddcUrl.example.com\">\n\n<!-- Using your preferred programming language, set the 'value' attribute with the value of the query string parameter containing the 'deviceDataCollection.bin' from the device data initialization response -->\n<input type=\"hidden\" name=\"Bin\" value=\"555555\" />\n\n\n<!-- Using your preferred programming language, set the 'value' attribute with the value of the query string parameter containing the 'deviceDataCollection.jwt' from the device data initialization response -->\n\n <input type=\"hidden\" name=\"JWT\" value=\"eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJPcmdVbml0SWQiOiJPcmdVbml0IiwiaXNzIjoiYXBpSWQiLCJleHAiOjE1NjI5MjMzNDYsImlhdCI6MTU2MjkyMzQwNiwianRpIjoiYTAzMWVhOGEtN2E0Zi00YTQwLWI1NjMtOTUzMzYzMzVhZGNmIn0.0IK74OIXBxFsxqeOURJz1TFnz14ZTbFJTdTWo9cHUJQ\" />\n\n</form>\n\n<script>\nwindow.onload = function() {\n  document.getElementById('collectionForm').submit();\n }\n</script>\n</body>\n</html>\n"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"example-device-data-form","__idx":6},"children":["Example device data form"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The form below allows you to submit the 3DS device data details provided in the API response. You then receive the sessionId/collectionReference, back in the postMessage, for use in the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/web/authentication"},"children":["authentication"]}," request. This is useful if using tools such as postman/insomnia to test your integration."]},{"$$mdtype":"Tag","name":"Embeddable","attributes":{"url":"/embeddable/3ds/ddc.html","title":"Access 3ds - Device Data Collection form","height":"518"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"device-data-collection-postmessage","__idx":7},"children":["Device Data Collection postMessage"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once the DDC form is submitted and is successfully sent to the card issuer, you are notified via a ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage"},"children":["postMessage"]}," event."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For security, verify the sender's identity using the postMessage ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["origin"]}," property as detailed ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://developer.mozilla.org/en-US/docs/Web/API/Window/postMessage"},"children":["here"]},"."]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Environment"},"children":["Environment"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Origin"},"children":["Origin"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Try"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["https://centinelapistag.cardinalcommerce.com"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Production"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["https://centinelapi.cardinalcommerce.com"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["An example postMessage response:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"file":"../examples/forms/ddc-postmessage.json","language":"json","title":"postmessage","header":{"title":"postmessage","controls":{"copy":{}}},"lang":"json","source":"{\n    \"MessageType\": \"profile.completed\",\n    \"SessionId\": \"0_3XXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXX6b5\",\n    \"Status\": true\n}"},"children":[]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Key"},"children":["Key"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["messageType"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["profile.completed"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SessionId"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["UUID, not present or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["undefined"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Status"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["true"]}," - Use the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SessionId"]}," value in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["deviceData.collectionReference"]}," as part of the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/web/authentication"},"children":["Authentication request"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["false"]}," -  SessionId is empty. Either retry DDC or send the authentication request without the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["deviceData.collectionReference"]},"."]}]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The DDC call typically takes 1-2 seconds, depending on the latency between the customer's device, the Cardinal servers and, in part, the type of device data collection performed by the different issuers. The 3DS specification has the maximum response time at 10 seconds."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Note"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If no postMessage is provided either retry DDC or send the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/web/authentication"},"children":["Authentication request"]}," without the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["deviceData.collectionReference"]},". We ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["highly recommend"]}," ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/web/authentication#how-much-data-to-provide"},"children":["providing device data"]}," (e.g. browserScreenHeight) in the authentication request as well. This maximizes authentication rates in the case of DDC failure."]}]},{"$$mdtype":"Tag","name":"hr","attributes":{},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Next steps"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/3ds/web/authentication"},"children":["Authentication"]}]}]},"headings":[{"value":"Device Data","id":"device-data","depth":1},{"value":"Device data initialization","id":"device-data-initialization","depth":2},{"value":"Device data initialization example request","id":"device-data-initialization-example-request","depth":3},{"value":"Device data initialization response","id":"device-data-initialization-response","depth":3},{"value":"Device Data Collection (DDC)","id":"device-data-collection-ddc","depth":2},{"value":"Test data collection form","id":"test-data-collection-form","depth":3},{"value":"Example device data form","id":"example-device-data-form","depth":3},{"value":"Device Data Collection postMessage","id":"device-data-collection-postmessage","depth":3}],"frontmatter":{"seo":{"title":"Device Data (Web) | 3DS API"}},"lastModified":"2026-06-09T12:05:35.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/3ds/web/device-data","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}