Authentication Setup
Request the Setup service before selecting the button to submit payment. Request the Setup service separately without including other services. The Setup service response includes a JSON Web Token (JWT) that contains credentials to create a secure channel with you. The Setup response also includes a reference ID to use during the authentication and a URL to use when transferring the device data collected in the next step.
Run the Setup service as soon as the customer enters their card number to avoid any delay in the customer experience. The next step in the process, device data collection, cannot start until the Setup response is received because the response has the URL where the device data is sent.
Endpoint
POST /risk/v1/authentication-setups
POST /risk/v1/authentication-setups
POST /risk/v1/authentication-setups
Request Fields
When requesting the Setup service, you must send the customer's payment information. This can be either the actual encrypted card information or a token associated with the payment data.
These fields are required:
paymentInformation.card.expirationMonthpaymentInformation.card.expirationYearpaymentInformation.card.numberpaymentInformation.card.type
The paymentInformation.card.type field is required when the card type is JCB, Cartes Bancaires, or China UnionPay.
Besides the required fields, the request might also include any of these fields:
paymentInformation.tokenizedCard.numberpaymentInformation.customer.customerIdtokenInformation.transientToken
Response Fields
The response from the issuing bank might include these API fields:
consumerAuthenticationInformation.accessToken— used in Device Data Collection.consumerAuthenticationInformation.deviceDataCollectionUrl— used in Device Data Collection.consumerAuthenticationInformation.referenceId— used in Enrollment Check.
Thanks for your feedback!
Last published: September 29, 2026