Skip to main content

Mastercard Identity Check


Mastercard Identity Check is the authentication service in the Mastercard card network that uses the 3-D Secure protocol in online transactions to authenticate customers at checkout.

Mastercard Identity Check generates a unique, 32-character transaction token, called the account authentication value (AAV) each time a Mastercard Identity Check-enabled account holder makes an online purchase. The AAV binds the account holder to a specific transaction. Mastercard Identity Check transactions use the universal cardholder authentication field (UCAF) as a standard to collect and pass AAV data.

Before implementing payer authentication for Mastercard Identity Check, contact customer support to have your account configured for this feature.

Supported Processors

  • AIBMS
  • Banque de France et Tresor Public
  • Barclays
  • BNP Paribas France
  • Chase Paymentech Solutions
  • Chase Tandem
  • Cielo
  • Comercio Latino
  • Credit Mutuel-CIC
  • Elavon
  • Elavon Americas
  • FDC Compass
  • FDC Nashville Global
  • FDI Australia
  • FDMS Nashville
  • Getnet
  • GPN
  • HBoS
  • HSBC
  • JCN Gateway
  • Lloyds-OmniPay
  • LloydsTSB Cardnet
  • Moneris
  • OmniPay Direct
  • Prosa
  • Rede
  • SIX
  • Streamline
  • TSYS Acquiring Solutions
  • Vero
  • Worldpay VAP
  • Barclays
  • TSYS Acquiring Solutions
  • Chase Paymentech Solutions
  • Elavon Americas
  • FDC Nashville Global
  • Streamline
  • Worldpay VAP

Processor-Specific Information

Processor-Specific Information

Fields Specific to the Mastercard Identity Check Use Case

These API fields are required specifically for this use case.

  • consumerAuthenticationInformation.directory ServerTransactionId: set this field to the transaction ID returned by Mastercard Identity Check during the authentication process.
  • consumerAuthenticationInformation.paSpecificationVersion: set this field to the Mastercard Identity Check version returned by Mastercard Identity Check during the authentication process.
  • consumerAuthenticationInformation.ucafCollectionIndicator: set to the last digit of the raw ECI value returned from authentication. For example, if ECI=02, this value should be 2.
  • processingInformation.commerceIndicator: set this field to one of these values:
    • spa: Successful authentication (3-D Secure value of 02).
    • spa: Authentication was attempted (3-D Secure value of 01).
    • spa or internet: Authentication failed or was not attempted (3-D Secure value of 00)

Endpoints

POST /pts/v2/payments

POST /pts/v2/payments

POST /pts/v2/payments

Example

{  "clientReferenceInformation": {    "code": "TC50171_6"  },  "consumerAuthenticationInformation": {    "ucafCollectionIndicator": "2",    "ucafAuthenticationData": "EHuWW9PiBkWvqE5juRwDzAUFBAk",    "directoryServerTransactionId": "f38e6948-5388-41a6-bca4-b49723c19437",    "paSpecificationVersion": "2.2.0"  },  "processingInformation": {    "commerceIndicator": "spa"  },  "orderInformation": {    "billTo": {      "country": "US",      "lastName": "Deo",      "address1": "201 S. Division St.",      "postalCode": "48104-2201",      "locality": "Ann Arbor",      "administrativeArea": "MI",      "firstName": "John",      "email": "[email protected]"    },    "amountDetails": {      "totalAmount": "105.00",      "currency": "USD"    }  },  "paymentInformation": {    "card": {      "expirationYear": "2031",      "number": "555555555555XXXX",      "securityCode": "123",      "expirationMonth": "12",      "type": "002"    }  }}
{  "_links": {    "authReversal": {      "method": "POST",      "href": "/pts/v2/payments/6758990751436655004951/reversals"    },    "self": {      "method": "GET",      "href": "/pts/v2/payments/6758990751436655004951"    },    "capture": {      "method": "POST",      "href": "/pts/v2/payments/6758990751436655004951/captures"    }  },  "clientReferenceInformation": {    "code": "TC50171_3"  },  "id": "6758990751436655004951",  "orderInformation": {    "amountDetails": {      "authorizedAmount": "100.00",      "currency": "USD"    }  },  "paymentAccountInformation": {    "card": {      "type": "002"    }  },  "paymentInformation": {    "tokenizedCard": {      "type": "002"    },    "card": {      "type": "002"    }  },  "pointOfSaleInformation": {    "terminalId": "111111"  },  "processorInformation": {    "approvalCode": "888888",    "authIndicator": "1",    "networkTransactionId": "123456789619999",    "transactionId": "123456789619999",    "responseCode": "100",    "avs": {      "code": "X",      "codeRaw": "I1"    }  },  "reconciliationId": "71183995FDU0YRTK",  "status": "AUTHORIZED",  "submitTimeUtc": "2023-02-08T23:31:15Z"}

Required Fields

Default Required Fields

These API fields are required specifically for processing an authorization using Mastercard Identity Check.

FieldDescription
consumerAuthenticationInformation.directoryServerTransactionIdSet this field to the transaction ID returned by Mastercard Identity Check during the authentication process.
consumerAuthenticationInformation.paSpecificationVersionSet this field to the Mastercard Identity Check version returned by Mastercard Identity Check during the authentication process.
consumerAuthenticationInformation.ucafCollectionIndicatorSet to the last digit of the raw ECI value returned from authentication. For example, if ECI=02, this value is 2.
For data only authorizations in Brazil using the Cielo, Getnet, and Rede processors, set this field to 4.
orderInformation.amountDetails.currency
For RuPay, set the value to INR. Vero supports Brazilian real (BRL) currency only.
orderInformation.amountDetails.totalAmount—
orderInformation.billTo.address1—
orderInformation.billTo.administrativeArea—
orderInformation.billTo.country—
orderInformation.billTo.email—
orderInformation.billTo.firstName—
orderInformation.billTo.lastName—
orderInformation.billTo.locality—
orderInformation.billTo.postalCode—
paymentInformation.card.expirationMonth—
paymentInformation.card.expirationYear—
paymentInformation.card.number—
processingInformation.commerceIndicatorSet this field to one of these values: spa for successful authentication (3-D Secure value of 02), spa when authentication was attempted (3-D Secure value of 01), or spa or internet when authentication failed or was not attempted (3-D Secure value of 00).

Brazil-Specific Field for Data Only Authorizations

FieldDescription
consumerAuthenticationInformation.ucafCollectionIndicatorFor data only authorizations in Brazil, set this field to 4.

Last published: September 29, 2026