Skip to main content

Direct API Implementation


The Direct API integrates EMV 3-D Secure 2.x into your business's website. This integration uses an iframe to complete the device profiling and EMV 3-D Secure authentication requirements without including third-party JavaScript directly on your site.

This implementation requires the use of JavaScript to leverage the authentication. The JavaScript is hosted and contained inside the iframe and does not directly access your web page.

A website that provides a demo tool to help users understand how payer authentication works is available:

You can complete the steps required to implement payer authentication on your website and examine the code underlying the process. Use test card numbers to walk through the process and enter 123 as the security code.

Enable Merchant Account for EMV 3-D Secure

Partners and merchants use the to go online and view transaction activity and to generate reports about their transactions.

For each partner, an account is created, and a portfolio merchant ID (MID) is assigned. For each of the merchants within the partner's portfolio, an account is also created and assigned a merchant ID (MID). Access to the various functions in the is managed by the partner through the MID.

When the MID account is created, the various services that the merchant needs must be enabled.

For more information about configuring your account in the for payer authentication and other services, see the Merchant User Boarding Guide. Payer authentication is a service that might need to be turned on by support. To set up an account for payer authentication, you need this information:

For more information about configuring your account in the for payer authentication and other services, see the Merchant Boarding User Guide. Payer authentication is a service that might need to be turned on by support. To set up an account for payer authentication, you need this information:

  • MID.
  • Merchant website URL.
  • Two-character ISO code for your country.
  • Merchant category code.
  • EMV 3-D Secure requestor ID (optional).
  • EMV 3-D Secure requestor name (optional).
  • Name of merchant's bank.
  • Name, address, and email address of bank contact.

For each payment card that you accept, your acquirer must provide this information:

  • Eight-digit BIN number.
  • Merchant ID assigned by your acquirer.
  • List of all of the currencies that you can process.

Before You Begin

Notify your account representative that you want to implement payer authentication (3-D Secure) using the Direct API integration. Provide the merchant ID that you will use for testing. For more information, see Payer Authentication Merchant Workflow.

Before you can implement payer authentication services, your business team must contact to establish the service. Your software development team should become familiar with the REST API fields and technical details of this service.

Before you can implement payer authentication services, your business team must contact your acquirer and to establish the service. Your software development team should become familiar with the REST API fields and technical details of this service.

Implementation Steps

Setup Service

Call the Setup service to obtain the JWT and the device data collection URL needed to begin the enrollment check flow. See Authentication Setup.

Device Data Collection

Use the JWT and device data collection URL from the Setup response to collect data about the customer's device. See Device Data Collection.

Payer Authentication Check Enrollment Service

Verify that the card is enrolled in a card authentication program and determine whether the cardholder must complete a challenge. See Enrollment Check.

Step-Up Iframe

If a challenge is required, display the step-up iframe so the cardholder can complete authentication with the issuing bank. See Step-Up Authentication.

Payer Authentication Validation Service

Validate the authentication results after the cardholder completes the challenge, then proceed to authorization. See Validation.

After Implementation and Before Go Live

Use the test cases to test your preliminary code and make appropriate changes. See Testing Payer Authentication Services. Testing ensures that your account is configured for production and that your transactions are processed quickly and correctly.

Last published: September 29, 2026