Step-Up Authentication
Initiate step-up authentication on the front end after you receive the response as discussed in Enrollment Check. Frictionless authentication does not require this step-up iframe step. This step is only for step-up authentication when the issuing bank wants to challenge the cardholder.
When a challenge is needed to prove a customer's identity, a JSON Web Token is returned to you that contains a step-up URL. You open an iframe where the access token to the step-up URL (also known as the endpoint) is posted. The iframe must be sized appropriately to enable the cardholder to complete the challenge. The iframe manages customer interaction with the card-issuing bank's access control server. The bank asks the customer to provide identifying information. After the customer completes the challenge, the process moves to validating the information that the customer sent.
Build the iFrame Parameters
The iframe you display should be sized to enable the customer bank to exchange authentication information between itself and the customer. Because a bank can use various methods to authenticate, the iframe has four size options. The bank requests that you ensure the iframe size provides room to display the bank logo and the card network being used, the amount of the transaction, and a brief explanation of what the customer needs to do. You manage the size of the challenge window to ensure that the challenge window matches with your presentation screen. You choose the iframe parameters and pass the window size to the issuer.
- Use the JWT POST Parameter value from the
consumerAuthenticationInformation.accessTokenresponse field and do a form POST within the iframe to the step-up URL value passed by theconsumerAuthenticationInformation.stepUpUrlresponse field. - MD POST Parameter: Merchant-defined data returned in the response. This field is optional.
- Iframe height and width: EMV 3-D Secure 2.x offers multiple size options:
- Use the
consumerAuthenticationInformation.acsWindowSizerequest field to request a specific window size. - Use the
consumerAuthenticationInformation.pareqresponse field to determine iframe dimensions by Base64 decoding the string and cross-referencing a Challenge Window Size value with its corresponding size.
- Use the
This table lists the possible values for iframe size and the sizes associated with the value.
| Challenge Window Size Value | Step-Up Iframe Dimensions (Width x Height in pixels) |
|---|---|
| 01 | 250 x 400 |
| 02 | 390 x 400 |
| 03 | 500 x 600 |
| 04 | 600 x 400 |
| 05 | Full screen |
This is an example of the decoded value:
{ "messageType": "CReq", "messageVersion": "2.2.0", "threeDSServerTransID": "c4b911d6-1f5c-40a4-bc2b-51986a98f991", "acsTransID": "47956453-b477-4f02-a9ef-0ec3f9f779b3", "challengeWindowSize": "02"}Create the iFrame
Create an iframe that is the same size as the Challenge Window Size to send a POST request to the step-up URL.
<iframe name="step-up-iframe" height="400" width="400"></iframe><form id="step-up-form" target="step-up-iframe" method="post" action="https://centinelapistag.cardinalcommerce.com/V2/Cruise/StepUp"> <input type="hidden" name="JWT" value="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJqdGkiOiJmNmFmMTRmOS04YWRjLTRiNzktOGVkYS04YWVlMTI2NTkzZTEiLCJpYXQiOjE1OTYwNTEyNzYsImlzcyI6IjVkZDgzYmYwMGU0MjNkMTQ5OGRjYmFjYSIsImV4cCI6MTU5NjA1NDg3NiwiT3JnVW5pdElkIjoiNTVlZjNmNTZmNzIzYWE0MzFjOTlkNTRiIiwiUGF5bG9hZCI6eyJBQ1NVcmwiOiJodHRwczovLzBtZXJjaGFudGFjc3N0YWcuY2FyZGluYWxjb21tZXJjZS5jb20vTWVyY2hhbnRBQ1NXZWIvY3JlcS5qc3AifX0.H8j-VYCJK_7ZEHxGz82_IwZGKBODzPaceJNNC99xZRo" /> <input type="hidden" name="MD" value="optionally_include_custom_data_that_will_be_returned_as_is" /></form>Use JavaScript to Invoke the iFrame
Add JavaScript to invoke the iframe form POST. Place the JavaScript after the closing </body> tag. The JavaScript invokes the iframe form POST automatically when the window loads. While you can submit the form at a different time, you must submit the form before requesting the validation service.
<script>window.onload = function() { var stepUpForm = document.querySelector('#step-up-form'); if(stepUpForm) // Step-Up form exists stepUpForm.submit();}</script>Receive the Step-Up Results
After the customer interacts with the issuing bank, the customer is returned to the consumerAuthenticationInformation.returnUrl within the iframe as specified in Enrollment Check. Because you host the return URL, you can close the iframe after redirection.
The response sent back to the return URL contains these values:
- Transaction ID: (
consumerAuthenticationInformation.authenticationTransactionIdresponse field). This value is used in Validation. - MD: merchant data returned if present in the POST to step-up URL; otherwise, null.
TransactionId=BwNsDeDPsQV4q8uy1Kq1&MD=nullThanks for your feedback!
Last published: September 29, 2026