3DS Execution - Overviews
3DS Execution
The 3DS Execution integration grants full access to Forter's [Fraud Management](/content/platform/fraud-management/ "Fraud Management"/index.html) and [Payment Optimization](/content/platform/payment-optimization/ "Payment Optimization"/index.html) in a streamlined approach that reduces your development effort. It transparently manages the entire 3DS challenge flow, minimizing the communication needed between frontend and backend for a more efficient integration process.
Integration Flow
Yes
No
Standard Authorization
PSD2 exemption over Authorization
PSD2 exemption over 3DS
3DS Recommended
Send order data to Forter via Order API
Fraudulent transaction?
Forter declines
Send decline message to buyer
Authorization path
Forter approves
Request authorization from PSP
Share order and authorization status with Forter
Forter approves + recommends exemption
Request authorization with exemption from PSP
Fetch 3DS exemption results from Order API response
Request authorization with 3DS results (ECI, CAVV) from PSP
Forter returns managedOrderToken
Call Forter JS with managedOrderToken
Forter JS executes 3DS flow and triggers your JS on completion
Trigger your backend to fetch results from Forter
Fetch results via Results API
Request authorization with 3DS results (ECI, CAVV) from PSP
flowchart TD
B["Send order data to Forter via Order API"] --> C{"Fraudulent transaction?"}
C -- Yes --> D["Forter declines"]
D --> E["Send decline message to buyer"]
C -- No --> F{"Authorization path"}
F -- Standard Authorization --> G["Forter approves"]
G --> H["Request authorization from PSP"]
H --> Z["Share order and authorization status with Forter"]
F -- PSD2 exemption over Authorization --> I["Forter approves + recommends exemption"]
I --> J["Request authorization with exemption from PSP"]
J --> Z
F -- PSD2 exemption over 3DS --> Q["Fetch 3DS exemption results from Order API response"]
Q --> R["Request authorization with 3DS results (ECI, CAVV) from PSP"]
R --> Z
F -- 3DS Recommended --> K["Forter returns managedOrderToken"]
K --> L["Call Forter JS with managedOrderToken"]
L --> M["Forter JS executes 3DS flow and triggers your JS on completion"]
M --> N["Trigger your backend to fetch results from Forter"]
N --> O["Fetch results via Results API"]
O --> P["Request authorization with 3DS results (ECI, CAVV) from PSP"]
P --> Z
Integration Steps
Confirm 3DS Prerequisites Confirm 3DS Prerequisites
Verify that both Forter's and your PSP's integration requirements are met. PSD2 Regulation Solution
Exemption support in the authorization request Confirm that your PSP can accept and act on an exemption flag in the authorization call. This is not always enabled by default — contact your PSP to activate it and obtain the relevant API reference. Forter will return the exemption recommendation in the order response (REQUEST_SCA_EXEMPTION_LOW_VALUE, REQUEST_SCA_EXEMPTION_TRA, or REQUEST_SCA_EXEMPTION_CORP). Pass the exemption flag to your PSP in the authorization request as described above.
Exemptions over the 3DS rails: Certain markets, such as France, require that SCA-exempt transactions be routed over the 3DS rails (i.e., the exemption is embedded within the 3DS message) rather than sent directly in the authorization request (DTA path). Forter manages this flow end-to-end internally. No additional action is required on your side. This is a regulatory routing requirement only — no real 3DS authentication takes place and no challenge will be presented to the cardholder unless the exemption is declined by the bank (soft decline), which will trigger a 3DS authentication flow.
ECI value in the authorization response Confirm that your PSP returns the ECI (Electronic Commerce Indicator) value as part of the authorization or authentication response, and that your system captures and forwards it to Forter via the post-authorization / status call update. The ECI value allows Forter to accurately assess liability shift, inform future decisioning, and determine whether the exemption was processed over the 3DS rails or via the standard DTA path.
Japan Regulation Solution Notify Forter which scenarios you are subject to under Japan's 3DS regulation:
- 3DS upon the merchant judgment, for high risk transactions and when preferred by issuers.
- 3DS when registering a card number to an account (either at checkout or via the account page) AND for high risk transactions. 3DS on transactions with a saved card is not required as long as fraud check at checkout is in place.
- 3DS on every transaction
BIN & Last 4 Verify that you can pass the card's BIN number & last four digits in Forter's Order API request. To cover both 6-digit and 8-digit BIN scenarios, we ask you to provide 8 digits in the BIN field.
Front-end Integration for 3DS In addition to the Forter's Javascript snippet and Mobile SDKs that share user behavior information, you'll need to incorporate Forter's 3DS client components into the front-end of your website and mobile applications. These are used in the 3DS Initialization and 3DS Challenge phases for easier integration
Checkout with 3DS Send Forter the complete order details in the Order API to get real time fraud decision, or alternatively an indication to process the response in your checkout page using Forter JS SDK in order to execute 3DS for the transaction. For the Forter PSD2 solution, a recommendation to request an exemption may be provided in addition to the fraud decision.
Request 3DS Results Request 3DS Results After processing the Order response in your checkout page using Forter JS SDK, call Forter to get the fraud decision and 3DS results. Note this phase is required only in case 3DS is executed for the transaction.
PSP Authorization In cases where Forter approved the transaction, call your PSP Authorization API with the 3DS results (or PSD2 exemption request) provided by Forter.
If Forter is acting as your 3DS executor and the issuer returns a soft decline after an exemption attempt, Forter can continue the flow by initiating 3DS authentication. In this case, the transaction is not treated as a final failure yet. Instead, the soft decline is the issuer’s signal that authentication is required before authorization can proceed. To support this flow, your integration should send Forter a post-authorization update with the authorization result and the relevant 3DS input, in the same general way Forter receives data in the pre-authorization stage. After receiving the soft-decline result, Forter evaluates whether 3DS should be executed and returns the next step in the authentication flow, including a challenge when applicable. If a challenge is required, the customer should remain on the payment page so the authentication can be completed in-session. Once authentication succeeds, pass the 3DS result to your payment service provider on the same transaction, and then send Forter the final post-authorization update.
Post-purchase Updates As you receive payment authentication updates and the order fulfillment status changes, it's important to keep Forter notified, so that this information can be used in future decisions. We strongly recommend using a webhook to send notifications about payment authorization and disputes if your PSP is supported.
Dispute Notifications Notifying Forter of disputes (also called claims, chargebacks, or fraud alerts) is extremely important because it enables Forter's system to learn and continually improve future decisions, tailoring our system to your company's needs. You can send these updates to Forter via a webhook from your PSP or via Forter's Dispute API endpoint.
Complete Integration Tests Complete Integration Tests The purpose of Forter's integration tests is to make sure that your integration covers all relevant use cases, while still in the sandbox or test environment. Each use case may need a different combination of attributes and values. To make sure you have covered each of the use cases we expect in your integration, please go through the test scenario list in the Integration Tests section of Portal. For each, you'll need to create the scenario in your sandbox site that will generate a call to Forter's API. Then, select the corresponding API request that Forter received and click Run to verify that the sample request meets the criteria.
Deploy to Production Once the Integration tests have passed, and you've reviewed any gaps with a Forter Implementation Engineer please, deploy your code to your production environment, with two critical adjustments:
- Replace your Site ID and secret key with your production credentials.
- Update both Javascript snippets and both Mobile SDKs to use your production Site ID and the production hash keys, if relevant.
Please note that this does not yet complete your integration. Until Forter has switched your site to Live (after Data Validation), all Forter decisions will return "Not Reviewed".
Data Validation Once in production, Forter uses a Data Validation tool to execute a set of automated tests across your live data in aggregation. The test outputs are daily reports that validate the accuracy and completeness of the production data we receive from you. You can monitor this output in Forter Portal under Integration Center Tools. We recommend checking the report daily to identify any failed tests.
Go Live As Forter begins to send decisions and executing 3DS on live transactions, confirm that your production site is handling responses as expected.
If you are rolling out gradually, work with your Implementation Engineer to coordinate ramp-up.
Verify 3DS results received by PSP Confirm that your PSP is correctly receiving authorization requests with 3DS results on live transactions.