PSP Authorization - Overviews

PSP Authorization

Authorization with 3DS Results

To provide the bank with the 3DS results, it is necessary to modify your integration with the Payment Service Provider (PSP).
This adjustment usually involves enriching the PSP payment request with the following values from the Forter 3DS result response's verificationMethod.verificationSpecificData.ThreeDS object:

Forter'sThreeDSfield Common Names
authenticationValue Authentication Value / CAVV / AAV / Cryptogram
ECIValue ECI / ECIFlag / ECIValue / Electronic Commerce Indicator
version 3DS Version
dsTransID dsTransID / Directory Server Transaction ID / Transaction ID (formerly xid)

Examples for common PSPs

Adyen

Map the previously mentioned Forter fields to the corresponding fields within the Adyen authorize request:

Adyen's mpiData. Forter's verificationMethod.verificationSpecificData.ThreeDS.
cavv authenticationValue
eci ECIValue
threeDSVersion version
dsTransID dsTransID

Braintree

Map the previously mentioned Forter fields to the corresponding fields within the Braintree Transaction: Sale request:

Braintree's three_d_secure_pass_thru. Forter's verificationMethod.verificationSpecificData.ThreeDS.
cavv authenticationValue
eciFlag ECIValue
threeDSecureVersion version
dsTransactionId dsTransID

Stripe

  1. Contact your Account Manager at Stripe and ask to enable “3DS Import”.
  2. In the paymentintent object, please include the following child attributes inside the payment_method_options.card attribute and map them to the corresponding Forter fields as indicated below:
Stripe's payment_method_options.card.three_d_secure. Forter's verificationMethod.verificationSpecificData.ThreeDS.
cryptogram authenticationValue
transaction_id dsTransID
version version
electronic_commerce_indicator ECIValue

See also Stripe's 3DSecure import guide

Worldpay AWP GW

  1. Review Worldpay AWP for full details
  2. Add the customer object to the request with Forter's 3DS results
Worldpay's customer.authentication. Forter's verificationMethod.verificationSpecificData.ThreeDS
version version
type "3DS"
eci ECIValue
authenticationValue authenticationValue
transactionId dsTransID

Checkout.com

Map the previously mentioned Forter fields to the corresponding fields within Checkout's Authorization Request

Checkout.com's 3ds. Forter's verificationMethod.verificationSpecificData.ThreeDS.
enabled true
cryptogram authenticationValue
eci ECIValue
version version
xid dsTransID

Authorization with PSD2 Exemption

The following part is relevant only for PSD2 solution
In order to pass the bank a request for exemption from 3DS following Forter's recommendation in the Order Response, you should adjust your integration with the PSP and include in the PSP Authorization request a flag for TRA Exemption or Low Value or Secure Corp Exemption.

Contact your PSP to enable such a call (it is not always activated by default), and get their relevant Authorization API reference which explains how to pass a request for TRA Exemption and Low Value Exemption.

Examples for common PSPs

Adyen

  1. Review Adyen documentation for passing exemption

  2. Change the default setting in the Customer Area in your Adyen Dashboard. Doing this will override Adyen's choice to apply TRA for a transaction or not. Navigate to Risk > Risk Settings > General > Perform TRA. Choose Enable 3rd party/proprietary risk solution TRA to apply the TRA exemption yourself per transaction.

  3. Pass the relevant exemption type (transactionRiskAnalysis\ lowValue\ secureCorporate) in the scaExemption object, following Forter's recommendation (REQUEST_SCA_EXEMPTION_TRA \ REQUEST_SCA_EXEMPTION_LOW_VALUE \ REQUEST_SCA_EXEMPTION_CORP) . Example:

{"additionalData":{"scaExemption":"lowValue"}}

Checkout.com

  1. Review Checkout SCA documentation for passing exemption
  2. Pass the relevant exemption type via the 3ds.enabled and 3ds.exemption fields within the 3ds object
{"source":{"type":"token","token":"tok\_f6z4mnoububudpqnvhwa5ff27u"},"amount":2000,"currency":"USD","3ds":{"enabled":false,"exemption":"low\_value"},"success\_url":"https://example.com/payments/success","failure\_url":"https://example.com/payments/failure"}
{"source":{"type":"token","token":"tok\_f6z4mnoububudpqnvhwa5ff27u"},"amount":2000,"currency":"USD","3ds":{"enabled":true,"exemption":"low\_value"},"success\_url":"https://example.com/payments/success","failure\_url":"https://example.com/payments/failure"}

Authorization with IDCI results

To provide the bank with the IDCI results, it is necessary to modify your integration with the Payment Service Provider (PSP). This adjustment involves including the verificationMethod.verificationSpecificData.ThreeDS.dsTransID , verificationMethod.verificationSpecificData.ThreeDS.authenticationValue and verificationMethod.verificationSpecificData.ThreeDS.ECIValue values from Forter Order Response in the PSP Authorization request.