SCA Exemption Authorizations
This section shows you how to process an authorization with a strong customer authentication (SCA) exemption.
You can use SCA exemptions to streamline the payment process. SCA exemptions are part of the European second Payment Services Directive (PSD2) and allow certain types of low-risk transactions to bypass additional authentication steps while still remaining compliant with PSD2. You can choose which exemption can be applied to a transaction, but the card-issuing bank actually grants an SCA exemption during card authentication.
You can process an authorization with two types of SCA exemptions:
- Exemption on Authorization: Send an authorization without payer authentication and request an SCA exemption on the authorization. If it is not approved, you might be required to request further authentication upon retry.
- Exemption on Authentication: Request an SCA exemption during payer authentication and if successful, send an authorization including the SCA exemption details.
Depending on your processor, use one of these exemption fields:
- Authentication Outage: Payer authentication is not available for this transaction due to a system outage.
- B2B Corporate Card: Payment cards specifically for business-to-business transactions are exempt.
- Delegated Authentication: Payer authentication was performed outside of the authorization workflow.
- Follow-On Installment Payment: Installment payments of a fixed amount are exempt after the first transaction.
- Follow-On Recurring Payment: Recurring payments of a fixed amount are exempt after the first transaction.
- Low Risk: The average fraud levels associated with this transaction are considered low.
- Low Value: The transaction value does not warrant SCA.
- Merchant Initiated Transactions: As follow-on transactions, merchant-initiated transactions are exempt.
- Stored Credential Transaction: Credentials are authenticated before storing, so stored credential transactions are exempt.
- Trusted Merchant: Merchants registered as trusted beneficiaries.
Processor Support for SCA Exemptions
You can send an authorization without payer authentication and request an SCA exemption on the authorization. If it is not approved, you might be required to request further authentication upon retry. Use this table to determine which processors support SCA exemptions on authorization:
| Processor | Authentication Outage | Follow-On Recurring Payment | Low Value | Transaction Risk Analysis |
|---|---|---|---|---|
| AIBMS | No | Yes | No | No |
| Banque de France et Tresor Public | Yes | No | Yes | Yes |
| Barclays | Yes | Yes | Yes | Yes |
| BNP Paribas France | Yes | No | Yes | Yes |
| Credit Mutuel-CIC | Yes | No | Yes | Yes |
| Elavon | No | Yes | Yes | Yes |
| HBoS | Yes | Yes | Yes | Yes |
| HSBC | Yes | Yes | Yes | Yes |
| Lloyds-OmniPay | No | Yes | No | No |
| LloydsTSB Cardnet | Yes | Yes | Yes | Yes |
| OmniPay Direct | Yes | Yes | Yes | Yes |
| SIX | No | Yes | Yes | Yes |
| Streamline | Yes | Yes | Yes | Yes |
| UATP | No | No | No | No |
You can request an SCA exemption during payer authentication and if successful, send an authorization including the SCA exemption details. Use this table to determine which processors support SCA exemptions on authentication:
| Processor | B2B Corporate Card | Delegated Authentication | Low Risk | Low Value | Trusted Merchant |
|---|---|---|---|---|---|
| AIBMS | No | No | No | No | No |
| Banque de France et Tresor Public | No | Yes | Yes | Yes | Yes |
| Barclays | No | No | No | No | No |
| BNP Paribas France | No | Yes | Yes | Yes | Yes |
| Credit Mutuel-CIC | No | Yes | Yes | Yes | Yes |
| Elavon | No | No | No | No | No |
| HBoS | No | No | No | No | No |
| HSBC | No | No | No | No | No |
| Lloyds-OmniPay | No | No | No | No | No |
| LloydsTSB Cardnet | No | No | No | No | No |
| OmniPay Direct | Yes | Yes | Yes | Yes | Yes |
| SIX | No | No | No | No | No |
| Streamline | No | No | No | No | No |
| UATP | No | No | No | No | No |
Processor Support for SCA Exemptions
You can send an authorization without payer authentication and request an SCA exemption on the authorization. If it is not approved, you might be required to request further authentication upon retry. Use this table to determine which processors support SCA exemptions on authorization:
| Processor | Authentication Outage | Follow-On Recurring Payment | Low Value | Transaction Risk Analysis |
|---|---|---|---|---|
| Streamline | Yes | Yes | Yes | Yes |
You can request an SCA exemption during payer authentication and if successful, send an authorization including the SCA exemption details. Use this table to determine which processors support SCA exemptions on authentication:
| Processor | B2B Corporate Card | Delegated Authentication | Low Risk | Low Value | Trusted Merchant |
|---|---|---|---|---|---|
| Streamline | No | No | No | No | No |
Processor Support for SCA Exemptions
You can send an authorization without payer authentication and request an SCA exemption on the authorization. If it is not approved, you might be required to request further authentication upon retry. Use this table to determine which processors support SCA exemptions on authorization:
| Processor | Authentication Outage | Follow-On Recurring Payment | Low Value | Transaction Risk Analysis |
|---|---|---|---|---|
| Barclays | Yes | Yes | Yes | Yes |
You can request an SCA exemption during payer authentication and if successful, send an authorization including the SCA exemption details. Use this table to determine which processors support SCA exemptions on authentication:
| Processor | B2B Corporate Card | Delegated Authentication | Low Risk | Low Value | Trusted Merchant |
|---|---|---|---|---|---|
| Barclays | No | No | No | No | No |
For information about exemption test cases, see the Payer Authentication Developer Guide.
Endpoints
POST /pts/v2/payments
POST /pts/v2/payments
POST /pts/v2/payments
Example
This example processes an authorization with an SCA exemption for a low-value transaction.
{ "consumerAuthenticationInformation": { "strongAuthentication": { "lowValueExemptionIndicator": "1" } }, "orderInformation": { "billTo": { "country": "US", "lastName": "Kim", "address1": "201 S. Division St.", "postalCode": "48104-2201", "locality": "Ann Arbor", "administrativeArea": "MI", "firstName": "Kyong-Jin", "email": "[email protected]" }, "amountDetails": { "totalAmount": "100.00", "currency": "eur" } }, "paymentInformation": { "card": { "expirationYear": "2031", "number": "CARD_NUMBER", "expirationMonth": "12" } }}{ "_links": { "authReversal": { "method": "POST", "href": "/pts/v2/payments/6709780221406171803955/reversals" }, "self": { "method": "GET", "href": "/pts/v2/payments/6709780221406171803955" }, "capture": { "method": "POST", "href": "/pts/v2/payments/6709780221406171803955/captures" } }, "clientReferenceInformation": { "code": "1670978022258" }, "id": "6709780221406171803955", "orderInformation": { "amountDetails": { "authorizedAmount": "100.00", "currency": "eur" } }, "paymentAccountInformation": { "card": { "type": "001" } }, "paymentInformation": { "tokenizedCard": { "type": "001" }, "card": { "type": "001" } }, "pointOfSaleInformation": { "terminalId": "123456" }, "processorInformation": { "approvalCode": "888888", "networkTransactionId": "123456789619999", "transactionId": "123456789619999", "responseCode": "100", "avs": { "code": "X", "codeRaw": "I1" } }, "reconciliationId": "62859554PBDEMI43", "status": "AUTHORIZED", "submitTimeUtc": "2022-12-14T00:33:42Z"}Required Fields
These fields are required when processing an authorization with an SCA exemption:
| Field | Description |
|---|---|
orderInformation.amountDetails.currency | — |
orderInformation.amountDetails.totalAmount | — |
orderInformation.billTo.address1 | — |
orderInformation.billTo.administrativeArea | — |
orderInformation.billTo.country | — |
orderInformation.billTo.email | — |
orderInformation.billTo.firstName | — |
orderInformation.billTo.lastName | — |
orderInformation.billTo.locality | — |
orderInformation.billTo.postalCode | — |
paymentInformation.card.expirationMonth | — |
paymentInformation.card.expirationYear | — |
paymentInformation.card.number | — |
paymentInformation.card.type | — |
SCA Exemptions Fields
Along with the standard authorization required fields, include one of these fields to request an SCA exemption:
| Field | Supported Processors | Exemption Type | Value |
|---|---|---|---|
consumerAuthenticationInformation.strongAuthentication.authenticationOutageExemptionIndicator | HBoS, HSBC | Authentication outage | 1 |
consumerAuthenticationInformation.strongAuthentication.secureCorporatePaymentIndicator | Credit Mutuel-CIC, OmniPay Direct | B2B corporate card transaction | 1 |
consumerAuthenticationInformation.strongAuthentication.delegatedAuthenticationExemptionIndicator | Credit Mutuel-CIC, OmniPay Direct | Delegated authentication | 1 |
processingInformation.commerceIndicator | Barclays, HBoS, HSBC, OmniPay Direct, SIX, Streamline | Follow-on recurring payment | recurring |
consumerAuthenticationInformation.strongAuthentication.riskAnalysisExemptionIndicator | Credit Mutuel-CIC, HBoS, HSBC, OmniPay Direct, SIX, Streamline | Low-risk transaction | 1 |
consumerAuthenticationInformation.strongAuthentication.lowValueExemptionIndicator | Credit Mutuel-CIC, HBoS, HSBC, OmniPay Direct, SIX, Streamline | Low-value transaction | 1 |
processingInformation.authorizationOptions.initiator.merchantInitiatedTransaction.reason | Barclays, HBoS, HSBC, OmniPay Direct, SIX, Streamline | Merchant initiated transaction | See the REST API Field Reference Guide for possible values. |
processingInformation.authorizationOptions.initiator.storedCredentialUsed | Barclays, HBoS, HSBC, OmniPay Direct, SIX, Streamline | Stored credential transaction | 1 |
consumerAuthenticationInformation.strongAuthentication. trustedMerchantExemptionIndicator | Credit Mutuel-CIC | Trusted merchant transaction | 1 |
Fields Specific to SCA Exemptions
Along with the standard authorization required fields, include one of these fields to request an SCA exemption:
| Field | Supported Processors | Exemption Type | Value |
|---|---|---|---|
processingInformation.commerceIndicator | Streamline | Follow-on recurring payment | recurring |
consumerAuthenticationInformation.strongAuthentication.riskAnalysisExemptionIndicator | Streamline | Low-risk transaction | 1 |
consumerAuthenticationInformation.strongAuthentication.lowValueExemptionIndicator | Streamline | Low-value transaction | 1 |
processingInformation.authorizationOptions.initiator.merchantInitiatedTransaction.reason | Streamline | Merchant initiated transaction | See the REST API Field Reference Guide for possible values. |
processingInformation.authorizationOptions.initiator.storedCredentialUsed | Streamline | Stored credential transaction | 1 |
Fields Specific to SCA Exemptions
Along with the standard authorization required fields, include one of these fields to request an SCA exemption:
| Field | Supported Processors | Exemption Type | Value |
|---|---|---|---|
processingInformation.commerceIndicator | Barclays | Follow-on recurring payment | recurring |
processingInformation.authorizationOptions.initiator.merchantInitiatedTransaction.reason | Barclays | Merchant initiated transaction | See the REST API Field Reference Guide for possible values. |
processingInformation.authorizationOptions.initiator.storedCredentialUsed | Barclays | Stored credential transaction | 1 |
Country-Specific Requirements
These fields are specific to certain countries and regions.
Argentina
| Field | Description |
|---|---|
merchantInformation.taxId | Required for Mastercard transactions. |
merchantInformation.transactionLocalDateTime | Required when the time zone is not included in your account. Otherwise, this field is optional. |
Brazil
| Field | Description |
|---|---|
paymentInformation.card.sourceAccountType | Required for combo card transactions. |
paymentInformation.card.sourceAccountTypeDetails | Required for combo card line-of-credit and prepaid-card transactions. |
Chile and Paraguay
| Field | Description |
|---|---|
merchantInformation.taxId | Required for Mastercard transactions. |
Latin America
| Field | Description |
|---|---|
orderInformation.billTo.buildingNumber | Required for Rede card customer validation. |
Saudi Arabia
| Field | Description |
|---|---|
processingInformation.authorizationOptions.transactionMode | — |
Taiwan
| Field | Description |
|---|---|
paymentInformation.card.hashedNumber | — |
Thanks for your feedback!
Last published: September 29, 2026