Phone Order Enrichment - Overviews
Phone Order Enrichment
Forter can help you combat fraudulent omnichannel orders, including orders placed over the phone. By providing the customer's internet connection information, Forter will be able to use the same advanced behavioral analytics to identify fraud over the phone as we do for online purchases. You can do this either by sending the customer an authentication link or by generating a unique ID on your website that the customer will share with your call center representative.
Authenticate via link Authenticate via link
This solution will trigger an SMS or an email to your customer that directs them to a landing page to complete the transaction. By placing Forter's JavaScript snippet on the designated landing page, Forter will be able to collect important information about the customer during this last step before making a decision.
Integration Steps Integration Steps
1
Send Order API request Send Order API request
When your customer places an order over the phone and your customer service team enters it into the system, send a request to the Order API with all of the checkout details and with "orderType": "PHONE"
{
"orderId":"123456",
"timeSentToForter":1568309531121,
"checkoutTime":1568309523223,
"connectionInformation":{
"customerIP":"172.18.13.3",
"userAgent":"",
"forterTokenCookie":""
},
"orderType":"PHONE"
}
2
Handle response with recommendation Handle response with recommendation
Based on your configuration to use this solution for phone orders, the Order API will return a response with a recommendation to follow up with verification. Note that the decision in this response will always be decline, but you should follow the recommendation. Hold the order; do not void it.
v2 Response format
{
"action":"decline",
"recommendations":["VERIFICATION_REQUIRED_SEND_LINK"]
}
v3 Response format
{
"forterDecision":"DECLINE",
"recommendation":"VERIFICATION_REQUIRED_SEND_LINK"
}
3
Create landing page with Confirm button Create landing page with Confirm button
Create a designated landing page for the customer to confirm their phone order. We recommend hashing the URL to prevent abuse.
Add a Confirm button to the page with the following JavaScript.
let timeout;
function enableConfirmationButton() {
if(timeout) {
clearTimeout(timeout);
}
// Logic for enabling the confirmation button, for example:
$("#confirm-btn").prop('disabled', false);
}
timeout = setTimeout(enableConfirmationButton, 10000);
document.addEventListener('ftr:loaded', enableConfirmationButton);
Ensure that Forter's JavaScript snippet is also placed on this page, as described in Front-end integration. This must be placed after the button script. The timeout extends the load time so that the asynchronous JavaScript for user behavior can load fully and capture the relevant data from the customer's device. On mobile, the button should be disabled by default for this reason.
<!doctype html>
<html>
<head>
<!-- stylesheet -->
<link href="/static/css/main.d2705104.chunk.css" rel="stylesheet">
<title>Confirmation Page</title>
</head>
<body>
<div>Confirmation Page</div>
<form action="/action_page.php" method="get">
<div>
<button class="confirm-btn" type="submit" value="confirm">Confirm Purchase</button>
</div>
</form>
<!-- script for timing enablement of confirmation button -->
<script type="text/javascript">
let timeout;
function enableConfirmationButton() {
timeout && clearTimeout(timeout);
$("#confirm-btn").prop("disabled", false);
}
timeout = setTimeout(enableConfirmationButton, 10000);
document.addEventListener("ftr:loaded", enableConfirmationButton);
</script>
<!-- forter JS snippet -->
<script type="text/javascript" id="927ffde14145">
(function() {
var siteId = "927ffde14145";
function t(t,e) {
for(var n=t.split(""), r=0;r<n.length;++r)n[r]=String.fromCharCode(n[r].charCodeAt(0)+e);
return n.join("")
}
function e(e) { return ... }
})();
</script>
</body>
</html>
Provide your Forter Implementation Engineer with the URL for this page to include in your site configuration.
4
Send SMS or email to customer Send SMS or email to customer
Create a service that sends an SMS or email to the customer who placed the order with a link to the landing page created in the previous step. The customer must click this link and the Confirm button to complete the order.
You should invalidate the link after the Confirm button is clicked, so that the customer cannot reopen the page on another device for additional attempts.
5
Request decision from Order Update API Request decision from Order Update API
When the customer clicks Confirm, send a request to the Order update API that includes the same orderId as the first call, along with an updated "orderType": "PHONE_LINK". Include full headers collected from the confirmation page as well as the connectionInformation, including forterTokenCookie.
{
"orderId":"123456",
"orderType":"PHONE_LINK",
"connectionInformation":{
"customerIP":"10.0.0.127",
"userAgent":"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36",
"forterTokenCookie":"2315688945984",
"merchantDeviceIdentifier":"HGJ7512345H3",
"fullHeaders":"{\\\"method\\\":\\\"GET \\/ HTTP\\/1.1\\\", \\\"Host\\\": \\\"forter.com\\\", \\\"Connection\\\": \\\"keep-alive\\\", \\\"Accept\\\": ...}"
}
}
6
Handle decision from response Handle decision from response
This second API response will contain Forter's decision on the order. Determine next steps as described in Checkout integration.
We recommend setting an expiration timeframe if you do not receive the second response from Forter because the customer did not click Confirm. Inform your Forter Implementation Engineer of the expiration timeframe so we can configure decisions to match.