Skip to main content

Authentication Setup


Request the Setup service before selecting the button to submit payment. Request the Setup service separately without including other services. The Setup service response includes a JSON Web Token (JWT) that contains credentials to create a secure channel with you. The Setup response also includes a reference ID to use during the authentication and a URL to use when transferring the device data collected in the next step.

Run the Setup service as soon as the customer enters their card number to avoid any delay in the customer experience. The next step in the process, device data collection, cannot start until the Setup response is received because the response has the URL where the device data is sent.

Endpoint

POST /risk/v1/authentication-setups

POST /risk/v1/authentication-setups

POST /risk/v1/authentication-setups

Request Fields

When requesting the Setup service, you must send the customer's payment information. This can be either the actual encrypted card information or a token associated with the payment data.

These fields are required:

  • paymentInformation.card.expirationMonth
  • paymentInformation.card.expirationYear
  • paymentInformation.card.number
  • paymentInformation.card.type

The paymentInformation.card.type field is required when the card type is JCB, Cartes Bancaires, or China UnionPay.

Besides the required fields, the request might also include any of these fields:

  • paymentInformation.tokenizedCard.number
  • paymentInformation.customer.customerId
  • tokenInformation.transientToken

Response Fields

The response from the issuing bank might include these API fields:

Last published: September 29, 2026