Forter's Orchestration service provides one unified integration that unlocks multiple services - Fraud Prevention, Predictive Payment Routing (PPR), and Payment Orchestration. Each service can be enabled independently or combined, with no additional engineering work, allowing merchants to start with any capability and expand seamlessly over time.
flowchart TD
A["Customer enters card details"] --> B["Hosted Fields tokenizes card"]
B --> C["Create Payment via API"]
C --> D{"Fraud Check"}
D -- Decline --> E["Transaction Rejected"]
D -- Approve --> F{"3DS Required?"}
F -- Yes --> G["Execute 3DS Challenge"]
G --> H{"Challenge Success?"}
H -- No --> E
H -- Yes --> I["Route to Optimal PSP"]
F -- No --> I
I --> J{"Authorization Success?"}
J -- No --> K["PPR Retry with Next PSP"]
K --> J
J -- Yes --> L["Payment Captured"]
L --> M["Webhook Notification"]
Add Forter's checkoutTools library to your checkout page, wherever the card entry iframe is located. The script should be pasted directly before the closing HTML
Include a unique idempotency-key header (e.g. a UUID) on each request. Reusing the same key for a retry ensures we return the original result instead of executing the operation again.
orderId is a required field — pass the merchant order ID to link the payment to fraud assessment
forterTokenString is the token generated in the previous section
If Forter determines that 3DS is recommended or required, the payment create response will include a 3DS SDK token. You'll need to pass this token to the frontend so it can run the 3DS flow.
POST /api/payments/:id/capture
Used only if captureMethod was set to manual in /api/payments. The amountToCapture is optional and should be provided only for partial captures.
Example Request
Full Refund
Issue a reversal for a captured payment. Omit amount for a full refund.
Partial Refund
To issue a partial refund, include the amount field in your request. Forter will apply the same settlement-status check — if the transaction has settled, the partial refund is processed normally. If the transaction has not yet settled, partial refunds are not possible and Forter will return an error.
Forter's Hosted Fields must be used for PCI compliance - merchants are never exposed to raw PCI data
Single-use Forter Token expires within a maximum of 24 hours. In case the customer chooses to store the payment method, you can upgrade to a long-lived token using the Forter Tokenization API
Each transaction is idempotent by idempotency key to prevent double charges.