Visa Data Only (VDO) - Overviews

Visa Data Only (VDO)

Overview

The Visa Data Only (VDO) integration grants access to Visa's Digital Commerce Authentication Program (DCAP), allowing eligible merchants to qualify for an interchange discount of up to 5 basis points (0.05%) when rich transaction data is shared with the issuer through the 3DS protocol. Unlike standard 3DS authentication, the Data-Only flow does not produce a liability shift — liability is retained by the merchant — but a fully frictionless experience is delivered to the cardholder with no challenge step, while additional transaction data is relayed to the issuer with the intention of increasing authorization rates and reducing fraud declines.

VDO is intended for merchants who are not looking for the issuer to authenticate the transaction (for the purpose of fraud protection and liability shift), and who would benefit from potentially higher bank authorization rates and lower interchange fees (when the transaction is qualified for DCAP by Visa).

Eligible Transactions

DCAP applies to:

Integration Steps

  1. Confirm Prerequisites

    It must be verified that both Forter's and your PSP's integration requirements are met before development commences.

PSP Support for DCAP

It should be confirmed with your PSP that their authorization API supports the passing of CAVV and DSTID (Directory Server Transaction ID) specifically in the context of DCAP (not only for standard 3DS authentication). A specific indicator flag may be required by some PSPs in order for the interchange discount to be triggered.

It should also be verified with your PSP that DCAP is enabled at your specific MID. Even where PSP support exists, the interchange discount is only passed through when explicitly configured.

Acquirer and Merchant Data

It must be confirmed that all the details about the expected authorization process can be passed in the Order API:

Note: In some cases the gateway, acquirer, and processor services are provided by the same company.

BIN & Last 4

It must be verified that the card's BIN number and last four digits can be passed in Forter's Order API request. To cover both 6-digit and 8-digit BIN scenarios, 8 digits should be provided in the BIN field.

  1. Front-end Integration

    The instructions for front-end integration for Fraud Management should be followed, including the installation of Mobile SDKs on your mobile applications. The Device ID (fingerprint) collected here is a mandatory data element for DCAP eligibility.

  2. Send Order API Request

    As with the Checkout Integration for Fraud Management, the complete order details must be sent to Forter in the Order API in order for a real-time fraud decision to be returned, along with a payment optimization recommendation for the authorization call. The request must be sent before the payment gateway is called to authorize funds (pre-auth flow). The full request and response data can be found in our Order API reference documentation.

Mandatory Data for DCAP Eligibility

For a transaction to qualify for the DCAP interchange discount, the following data points must be included in the Order API request:

Field Notes
Cardholder Email Required by Visa for DCAP eligibility
Billing Address Required by Visa for DCAP eligibility
IP Address Required by Visa for DCAP eligibility
Device ID (Fingerprint) Collected via Forter's front-end SDK

The full request and response schema is available in the Order API v3 Reference.

  1. Handle Order API Response

    The response will include Forter's fraud decision, along with a recommendation regarding whether Visa Data Only or standard 3DS should be executed during the authorization call.
Outcome Call to Action Order Response Fields
Forter Approved
Transaction is approved by Forter, no Data Only or 3DS recommended
Standard Authorization "forterDecision": "APPROVE", "verificationMethod": {}
Forter Approved & Recommends Visa Data Only
Transaction is approved by Forter and Forter recommends that VDO be executed during the authorization call
Authorize with Data Only "forterDecision": "APPROVE", "recommendation": "VERIFICATION_REQUIRED_DATA_ONLY"
Forter Declined
Transaction is declined by Forter
Do not Authorize "forterDecision": "DECLINE", "verificationMethod": {}
Forter Did Not Review
Transaction was not reviewed for a fraud decision
Act according to policy prior to Forter integration "forterDecision": "NOT REVIEWED", "recommendation": "", "verificationMethod": {}
  1. Request authorization with Data Only

    When Visa Data Only is recommended by Forter, a request should be passed to the PSP for the Data Only flow to be executed during authorization. The integration with the PSP should be adjusted so that the Data Only request flag is included in the PSP Authorization request.

The following fields must be relayed by the PSP to Visa within the authorization payload:

Field Value Description
cavv Cryptogram CAVV identifying the transaction as Data Only
eci 07 (U.S.) Signals a data-only attempt; ECI 05/02 must not be used, as this would signal full authentication
dsTransId UUID Directory Server Transaction ID — links the 3DS data session to the financial authorization
threeDsVersion 2.1 or 2.2 The 3DS protocol version used

⚠️ The use of ECI 05 or ECI 02 would imply a full authentication, and the transaction would be disqualified from the DCAP discount.

  1. Verify Data Only recommendations with PSP

    It should be confirmed that authorization requests with Data Only recommendations are being correctly received by the PSP on live transactions, and that the DCAP interchange discount is being applied.

Visa Data Only Execution

The Visa Data Only Execution integration is an alternative flow in which the Visa Data Only request is executed by Forter on your behalf, and the resulting authentication values are returned for inclusion in your authorization request to your PSP. This is useful for merchants who do not have a 3DS provider in place or who wish to consolidate 3DS execution with Forter.

Forter's standard 3DS execution fee applies to Data-Only requests sent to Visa under DCAP. Both standard 3DS and 3DS Data Only are 3DS requests to the issuer and incur the same fee to Forter.

Additional Prerequisites for Execution

In addition to the prerequisites listed above, the following is required for the Execution flow:

Full PAN Full PAN

It must be verified that the full credit card number can be passed in the Order API. This information is required for Visa DCAP execution by Forter to be triggered.

If vaulted cards are in use and the full card number is not exposed on the checkout page, your Tokenization vendor should be consulted regarding the availability of a Detokenization Proxy service (aka Forward Proxy). This service enables a request to be made to a 3rd party (such as Forter Order API) with a Token included in the request. The request is then routed through the proxy, where the token is replaced with the corresponding card data.

Specifying the 3DS Execution Path Specifying the 3DS Execution Path

The Execute3DS field in the Order API request (payment.creditCard.threeDSecure.execute3DS) should be set to indicate whether the Data-Only path or standard 3DS should be followed for the transaction:

Execute3DS Value Behavior
FORCE_DATA_ONLY The VDO (Data-Only) flow is executed by Forter — no cardholder challenge, no liability shift
FORCE_3D Standard 3DS is executed by Forter — the cardholder may be challenged by the issuer, and liability is shifted on authentication and bank authorization

Supported in API version 2.18.

Handle Order API Response (Execution Flow) Handle Order API Response (Execution Flow)

DCAP eligibility is determined automatically by Forter during 3DS initialization, by checking whether the bank's ACS (Access Control Server — issuer side of 3DS) supports the Data-Only flow. When eligible, the VDO flow is executed by Forter, and the result values are returned in the Order API response.

Outcome Order Response Fields
Data Only executed successfully "verificationMethod": {"status": "DATA_ONLY"}, along with cavv, eci (07), dsTransId, and threeDsVersion fields populated
Bank ACS does not support Data Only "verificationMethod": {} (empty) — Data Only fields must not be passed to the PSP
Network error during execution "verificationMethod": {"status": "NETWORK_ERROR"} — Data Only fields must not be passed to the PSP