Skip to main content

SCA Exemption Authorizations


This section shows you how to process an authorization with a strong customer authentication (SCA) exemption.

You can use SCA exemptions to streamline the payment process. SCA exemptions are part of the European second Payment Services Directive (PSD2) and allow certain types of low-risk transactions to bypass additional authentication steps while still remaining compliant with PSD2. You can choose which exemption can be applied to a transaction, but the card-issuing bank actually grants an SCA exemption during card authentication.

You can process an authorization with two types of SCA exemptions:

  • Exemption on Authorization: Send an authorization without payer authentication and request an SCA exemption on the authorization. If it is not approved, you might be required to request further authentication upon retry.
  • Exemption on Authentication: Request an SCA exemption during payer authentication and if successful, send an authorization including the SCA exemption details.

Depending on your processor, use one of these exemption fields:

  • Authentication Outage: Payer authentication is not available for this transaction due to a system outage.
  • B2B Corporate Card: Payment cards specifically for business-to-business transactions are exempt.
  • Delegated Authentication: Payer authentication was performed outside of the authorization workflow.
  • Follow-On Installment Payment: Installment payments of a fixed amount are exempt after the first transaction.
  • Follow-On Recurring Payment: Recurring payments of a fixed amount are exempt after the first transaction.
  • Low Risk: The average fraud levels associated with this transaction are considered low.
  • Low Value: The transaction value does not warrant SCA.
  • Merchant Initiated Transactions: As follow-on transactions, merchant-initiated transactions are exempt.
  • Stored Credential Transaction: Credentials are authenticated before storing, so stored credential transactions are exempt.
  • Trusted Merchant: Merchants registered as trusted beneficiaries.

Processor Support for SCA Exemptions

You can send an authorization without payer authentication and request an SCA exemption on the authorization. If it is not approved, you might be required to request further authentication upon retry. Use this table to determine which processors support SCA exemptions on authorization:

ProcessorAuthentication OutageFollow-On Recurring PaymentLow ValueTransaction Risk Analysis
AIBMSNoYesNoNo
Banque de France et Tresor PublicYesNoYesYes
BarclaysYesYesYesYes
BNP Paribas FranceYesNoYesYes
Credit Mutuel-CICYesNoYesYes
ElavonNoYesYesYes
HBoSYesYesYesYes
HSBCYesYesYesYes
Lloyds-OmniPayNoYesNoNo
LloydsTSB CardnetYesYesYesYes
OmniPay DirectYesYesYesYes
SIXNoYesYesYes
StreamlineYesYesYesYes
UATPNoNoNoNo

You can request an SCA exemption during payer authentication and if successful, send an authorization including the SCA exemption details. Use this table to determine which processors support SCA exemptions on authentication:

ProcessorB2B Corporate CardDelegated AuthenticationLow RiskLow ValueTrusted Merchant
AIBMSNoNoNoNoNo
Banque de France et Tresor PublicNoYesYesYesYes
BarclaysNoNoNoNoNo
BNP Paribas FranceNoYesYesYesYes
Credit Mutuel-CICNoYesYesYesYes
ElavonNoNoNoNoNo
HBoSNoNoNoNoNo
HSBCNoNoNoNoNo
Lloyds-OmniPayNoNoNoNoNo
LloydsTSB CardnetNoNoNoNoNo
OmniPay DirectYesYesYesYesYes
SIXNoNoNoNoNo
StreamlineNoNoNoNoNo
UATPNoNoNoNoNo

Processor Support for SCA Exemptions

You can send an authorization without payer authentication and request an SCA exemption on the authorization. If it is not approved, you might be required to request further authentication upon retry. Use this table to determine which processors support SCA exemptions on authorization:

ProcessorAuthentication OutageFollow-On Recurring PaymentLow ValueTransaction Risk Analysis
StreamlineYesYesYesYes

You can request an SCA exemption during payer authentication and if successful, send an authorization including the SCA exemption details. Use this table to determine which processors support SCA exemptions on authentication:

ProcessorB2B Corporate CardDelegated AuthenticationLow RiskLow ValueTrusted Merchant
StreamlineNoNoNoNoNo

Processor Support for SCA Exemptions

You can send an authorization without payer authentication and request an SCA exemption on the authorization. If it is not approved, you might be required to request further authentication upon retry. Use this table to determine which processors support SCA exemptions on authorization:

ProcessorAuthentication OutageFollow-On Recurring PaymentLow ValueTransaction Risk Analysis
BarclaysYesYesYesYes

You can request an SCA exemption during payer authentication and if successful, send an authorization including the SCA exemption details. Use this table to determine which processors support SCA exemptions on authentication:

ProcessorB2B Corporate CardDelegated AuthenticationLow RiskLow ValueTrusted Merchant
BarclaysNoNoNoNoNo

For information about exemption test cases, see the Payer Authentication Developer Guide.

Endpoints

POST /pts/v2/payments

POST /pts/v2/payments

POST /pts/v2/payments

Example

This example processes an authorization with an SCA exemption for a low-value transaction.

{  "consumerAuthenticationInformation": {    "strongAuthentication": {      "lowValueExemptionIndicator": "1"    }  },  "orderInformation": {    "billTo": {      "country": "US",      "lastName": "Kim",      "address1": "201 S. Division St.",      "postalCode": "48104-2201",      "locality": "Ann Arbor",      "administrativeArea": "MI",      "firstName": "Kyong-Jin",      "email": "[email protected]"    },    "amountDetails": {      "totalAmount": "100.00",      "currency": "eur"    }  },  "paymentInformation": {    "card": {      "expirationYear": "2031",      "number": "CARD_NUMBER",      "expirationMonth": "12"    }  }}
{    "_links": {        "authReversal": {            "method": "POST",            "href": "/pts/v2/payments/6709780221406171803955/reversals"        },        "self": {            "method": "GET",            "href": "/pts/v2/payments/6709780221406171803955"        },        "capture": {            "method": "POST",            "href": "/pts/v2/payments/6709780221406171803955/captures"        }    },    "clientReferenceInformation": {        "code": "1670978022258"    },    "id": "6709780221406171803955",    "orderInformation": {        "amountDetails": {            "authorizedAmount": "100.00",            "currency": "eur"        }    },    "paymentAccountInformation": {        "card": {            "type": "001"        }    },    "paymentInformation": {        "tokenizedCard": {            "type": "001"        },        "card": {            "type": "001"        }    },    "pointOfSaleInformation": {        "terminalId": "123456"    },    "processorInformation": {        "approvalCode": "888888",        "networkTransactionId": "123456789619999",        "transactionId": "123456789619999",        "responseCode": "100",        "avs": {            "code": "X",            "codeRaw": "I1"        }    },    "reconciliationId": "62859554PBDEMI43",    "status": "AUTHORIZED",    "submitTimeUtc": "2022-12-14T00:33:42Z"}

Required Fields

These fields are required when processing an authorization with an SCA exemption:

FieldDescription
orderInformation.amountDetails.currency—
orderInformation.amountDetails.totalAmount—
orderInformation.billTo.address1—
orderInformation.billTo.administrativeArea—
orderInformation.billTo.country—
orderInformation.billTo.email—
orderInformation.billTo.firstName—
orderInformation.billTo.lastName—
orderInformation.billTo.locality—
orderInformation.billTo.postalCode—
paymentInformation.card.expirationMonth—
paymentInformation.card.expirationYear—
paymentInformation.card.number—
paymentInformation.card.type—

SCA Exemptions Fields

Along with the standard authorization required fields, include one of these fields to request an SCA exemption:

FieldSupported ProcessorsExemption TypeValue
consumerAuthenticationInformation.strongAuthentication.authenticationOutageExemptionIndicatorHBoS, HSBCAuthentication outage1
consumerAuthenticationInformation.strongAuthentication.secureCorporatePaymentIndicatorCredit Mutuel-CIC, OmniPay DirectB2B corporate card transaction1
consumerAuthenticationInformation.strongAuthentication.delegatedAuthenticationExemptionIndicatorCredit Mutuel-CIC, OmniPay DirectDelegated authentication1
processingInformation.commerceIndicatorBarclays, HBoS, HSBC, OmniPay Direct, SIX, StreamlineFollow-on recurring paymentrecurring
consumerAuthenticationInformation.strongAuthentication.riskAnalysisExemptionIndicatorCredit Mutuel-CIC, HBoS, HSBC, OmniPay Direct, SIX, StreamlineLow-risk transaction1
consumerAuthenticationInformation.strongAuthentication.lowValueExemptionIndicatorCredit Mutuel-CIC, HBoS, HSBC, OmniPay Direct, SIX, StreamlineLow-value transaction1
processingInformation.authorizationOptions.initiator.merchantInitiatedTransaction.reasonBarclays, HBoS, HSBC, OmniPay Direct, SIX, StreamlineMerchant initiated transactionSee the REST API Field Reference Guide for possible values.
processingInformation.authorizationOptions.initiator.storedCredentialUsedBarclays, HBoS, HSBC, OmniPay Direct, SIX, StreamlineStored credential transaction1
consumerAuthenticationInformation.strongAuthentication. trustedMerchantExemptionIndicatorCredit Mutuel-CICTrusted merchant transaction1

Fields Specific to SCA Exemptions

Along with the standard authorization required fields, include one of these fields to request an SCA exemption:

FieldSupported ProcessorsExemption TypeValue
processingInformation.commerceIndicatorStreamlineFollow-on recurring paymentrecurring
consumerAuthenticationInformation.strongAuthentication.riskAnalysisExemptionIndicatorStreamlineLow-risk transaction1
consumerAuthenticationInformation.strongAuthentication.lowValueExemptionIndicatorStreamlineLow-value transaction1
processingInformation.authorizationOptions.initiator.merchantInitiatedTransaction.reasonStreamlineMerchant initiated transactionSee the REST API Field Reference Guide for possible values.
processingInformation.authorizationOptions.initiator.storedCredentialUsedStreamlineStored credential transaction1

Fields Specific to SCA Exemptions

Along with the standard authorization required fields, include one of these fields to request an SCA exemption:

FieldSupported ProcessorsExemption TypeValue
processingInformation.commerceIndicatorBarclaysFollow-on recurring paymentrecurring
processingInformation.authorizationOptions.initiator.merchantInitiatedTransaction.reasonBarclaysMerchant initiated transactionSee the REST API Field Reference Guide for possible values.
processingInformation.authorizationOptions.initiator.storedCredentialUsedBarclaysStored credential transaction1

Country-Specific Requirements

These fields are specific to certain countries and regions.

Argentina

FieldDescription
merchantInformation.taxIdRequired for Mastercard transactions.
merchantInformation.transactionLocalDateTimeRequired when the time zone is not included in your account. Otherwise, this field is optional.

Brazil

FieldDescription
paymentInformation.card.sourceAccountTypeRequired for combo card transactions.
paymentInformation.card.sourceAccountTypeDetailsRequired for combo card line-of-credit and prepaid-card transactions.

Chile and Paraguay

FieldDescription
merchantInformation.taxIdRequired for Mastercard transactions.

Latin America

FieldDescription
orderInformation.billTo.buildingNumberRequired for Rede card customer validation.

Saudi Arabia

FieldDescription
processingInformation.authorizationOptions.transactionMode—

Taiwan

FieldDescription
paymentInformation.card.hashedNumber—

Last published: September 29, 2026