Skip to main content

Device Data Collection


Device data collection starts on the merchant end after you receive the server-side Setup service response as described in Authentication Setup and pass the access token and the device data collection URL to the front end. When device data gets to the data collection URL, a Method URL defined in the 3-D Secure protocol captures the entire card number to identify the issuing bank.

A hidden 10 x 10 pixel iframe is rendered in the browser, and using the access token, you send the customer device data to the device data collection URL. The device data collection can take up to 10 seconds. If you proceed with the check enrollment service as described in Enrollment Check before a response is received, the collection process stops and an error occurs. Despite the error, as long as you include the data from the eleven browser fields as explained in Enrollment Check, you can still proceed with the EMV authentication.

Start device data collection immediately after you receive the customer card number to ensure that the data collection runs in the background while the customer continues with the checkout process, ensuring a minimum of waiting. When a customer changes to a different card number, begin the Setup and device data collection process again as soon as the new card number is entered.

Which Device Data Is Collected

One of the key components to authenticating a cardholder during an online transaction is to compare information about the device that the customer is currently using to the information in the bank's database about devices the customer used in past transactions. This information is maintained in the access control server (ACS) at the issuing bank. This device information focuses on the web browser and includes these types of data:

  • IP address
  • Browser language
  • Browser type
  • Browser version
  • Computer operating system
  • System time zone
  • Screen dimensions
  • Color depth

A successful device data collection process that includes the 11 browser fields listed in the check enrollment step increases the chances of a frictionless authentication. See Enrollment Check for the list of 11 browser fields. Business rules evaluate whether a transaction is risky enough to require the buyer to authenticate their identity. These business rules are configured in the issuer's risk analysis software that evaluates each transaction.

Build the iFrame

The iframe has these parameters:

  • Form POST Action: The POST goes to the URL that is opened within an iframe. This URL is the value provided by the consumerAuthenticationInformation.deviceDataCollectionUrl response field discussed in Authentication Setup.
  • JWT POST Parameter: Use the value from the consumerAuthenticationInformation.accessToken response field discussed in Authentication Setup.

Initiate the Device Data Collection iFrame

Initiate a form POST in a hidden 10 x 10 pixel iframe and send it to the device data collection URL (consumerAuthenticationInformation.deviceDataCollectionUrl).

Place the HTML anywhere inside the <body> element of the checkout page. Dynamically replace the value of the form action attribute and JWT POST parameter with the response values discussed in Authentication Setup.

<iframe id="cardinal_collection_iframe" name="collectionIframe" height="10" width="10" style="display: none;"></iframe><form id="cardinal_collection_form" method="POST" target="collectionIframe" action=https://centinelapistag.cardinalcommerce.com/V1/Cruise/Collect>  <input id="cardinal_collection_form_input" type="hidden" name="JWT" value="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJSZWZlcmVuY2VJZCI6ImE0NjVlYzU1LTMwNTEtNGYwZC05MGE0LWZjMDNlMGE2MWQxOSIsIlJldHVyblVybCI6Imh0dHA6XC9cL2xvY2FsaG9zdDo4MDgyXC9yZXF1ZXN0LWNhdGNoZXJcL2NhdGNoLXJlcXVlc3QucGhwIiwianRpIjoianRpXzVmMDVkM2VkY2U0MjYzLjc5MjQwNzMzIiwiaWF0IjoxNTk0MjE3NDUzLCJpc3MiOiI1YjIzZjhjMGJmOWUyZjBkMzQ3ZGQ1YmEiLCJPcmdVbml0SWQiOiI1NWVmM2YwY2Y3MjNhYTQzMWM5OWI0MzgifQ.Yw9cB9Hdrg71GPL40oAC0g3CVKYElNGe0uvN9JAaw2E"></form>

Add JavaScript to Submit the Device Data

Add JavaScript to invoke the iframe form POST. Place the JavaScript after the closing </body> element as shown in this example. The JavaScript invokes the iframe form POST automatically when the window loads. You must submit it before requesting the Check Enrollment service.

<script>window.onload = function() {var cardinalCollectionForm = document.querySelector('#cardinal_collection_form');if(cardinalCollectionForm) // form existscardinalCollectionForm.submit();}</script>

Listen for the URL Response

The response confirms that the device data collection URL completed its processing. The response is an event callback that contains a message with the status of the device data collection process.

Use the event.origin URL that corresponds to your environment:

https://centinelapi.cardinalcommerce.com

https://centinelapistag.cardinalcommerce.com

Add JavaScript to receive the response from the device data collection iframe. Place the JavaScript after the closing </body> element.

window.addEventListener("message", function(event) {  if (event.origin === "https://centinelapistag.cardinalcommerce.com") {    console.log(event.data);  }}, false);

This example shows a response payload from the event. None of the returned data needs to be stored for future use.

{  "MessageType": "profile.completed",  "Session Id": "f54ea591-51ac-48de-b908-eecf4ff6beff",  "Status": true}

Last published: September 29, 2026