Skip to main content

Authenticate with Passkey


When a request to create tokenized card authentication options returns AUTHENTICATE, a passkey already exists for the device and card combination, and the cardholder authenticates using their existing passkey. No issuer challenge or step-up is required.

Response

{  "action": "AUTHENTICATE",  "authenticationContext": {    "id": "de5ecf36-2a5c-4f66-b01f-15d6e5b73715",    "endpoint": "/vts-auth/authenticate",    "payload": "aGVsbG8",    "platformType": "WEB"  }}

Follow these steps to create a cryptogram that supplies authenticated Payment Passkey credentials:

Step 1: Cardholder Authentication with FIDO

The cardholder authenticates with FIDO using the URL from the merchantInformation.merchantDescriptor.url field sent to the /tms/v2/tokenized-cards/{tokenId}/authentication-options endpoint.

Step 2: Create Payment Credentials with FIDO Data

Create a cryptogram that supplies authenticated Passkey Service credentials.

Endpoint

POST /tms/v2/tokens/{tokenId}/payment-credentials

POST /tms/v2/tokens/{tokenId}/payment-credentials

Example

{  "clientCorrelationId": "aB3cD4eF5gH6iJ7kL8mN9oP0qR1sT2uV3wX",  "transactionType": "ECOM",  "orderInformation": {    "amountDetails": {      "totalAmount": "102.21",      "currency": "USD"    },    "billTo": {      "firstName": "John",      "lastName": "Smith",      "email": "[email protected]",      "address1": "123 Fake Street",      "locality": "Austin",      "administrativeArea": "TX",      "postalCode": "78751",      "country": "US"    }  },  "merchantInformation": {    "merchantDescriptor": {      "name": "Merchants Name",      "url": "http://www.example.com"    }  },  "buyerInformation": {    "language": "en_US"  },  "authenticatedIdentities": [    {      "id": "HmP8qo_aBOGemJEV_VoC@KaolERq_rL>95dfJV[vtYvDkwf]MchKrItaM2^sGI0",      "provider": "string",      "data": "@=TFf@Xhj[Vl\\tpf3zJ=bl@E0HCqVcPlxFz]3yRLbG3bTpBzDJtHNMlnP6pL",      "relyingPartyId": "<Base64URL encoded string>",      "userAuthenticationMethod": "USERNAME_PASSWORD"    }  ],  "deviceInformation": {    "ipAddress": "127.0.0.1",    "httpAcceptContent": "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36",    "httpBrowserLanguage": "en-US",    "httpBrowserJavaEnabled": true,    "httpBrowserJavaScriptEnabled": true,    "httpBrowserColorDepth": "24",    "httpBrowserScreenHeight": "1080",    "httpBrowserScreenWidth": "1920",    "httpBrowserTimeDifference": "-480",    "userAgentBrowserValue": "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36"  }}
{  "_links": {    "self": {      "href": "/tms/v2/tokens/7010000000016241111/payment-credentials"    }  },  "tokenizedCard": {    "state": "ACTIVE",    "enrollmentId": "c2d1b36fad46aed1ca8318dca5ed1e02",    "tokenReferenceId": "168661ada5115ca3589b1ba3dabdb102",    "number": "4895370016750801",    "expirationMonth": "12",    "expirationYear": "2023",    "type": "visa",    "cryptogram": "AwAAAADggP/Ce5+ZciCXQUUAAAA=",    "eci": "05",    "requestorId": "40010052236",    "card": {      "suffix": "0394",      "expirationMonth": "12",      "expirationYear": "2023"    }  },  "card": {    "number": "411111XXXXXX1111"  },  "issuer": {    "paymentAccountReference": "V0010013022298169667504231315"  },  "processingInformation": {    "authorizationOptions": {      "initiator": {        "merchantInitiatedTransaction": {          "previousTransactionId": "123456789619999"        }      }    },    "commerceIndicator": "vbv"  }}
{  "_links": {    "self": {      "href": "/tms/v2/tokens/7010000000016241111/payment-credentials"    }  },  "tokenizedCard": {    "state": "ACTIVE",    "enrollmentId": "c2d1b36fad46aed1ca8318dca5ed1e02",    "tokenReferenceId": "168661ada5115ca3589b1ba3dabdb102",    "number": "4895370016750801",    "expirationMonth": "12",    "expirationYear": "2023",    "type": "visa",    "cryptogram": "AwAAAADggP/Ce5+ZciCXQUUAAAA=",    "eci": "07",    "requestorId": "40010052236",    "card": {      "suffix": "0394",      "expirationMonth": "12",      "expirationYear": "2023"    }  },  "card": {    "number": "411111XXXXXX1111"  },  "issuer": {    "paymentAccountReference": "V0010013022298169667504231315"  },  "processingInformation": {    "authorizationOptions": {      "initiator": {        "merchantInitiatedTransaction": {          "previousTransactionId": "123456789619999"        }      }    },    "commerceIndicator": "internet"  }}
FieldTypeDescription
authenticatedIdentities.datastringThe FIDO authentication response data (fidoResponse.fidoBlob).
authenticatedIdentities.idstringA unique identifier for the authenticated identity (fidoResponse.identifier).
authenticatedIdentities.providerstringThe identity provider that performed the authentication.
authenticatedIdentities.relyingPartyIdstringThe FIDO relying party identifier, Base64URL encoded (fidoResponse.rpID).
clientCorrelationIdstringA unique identifier for the client request.
deviceInformation.httpAcceptContentstringThe HTTP Accept header from the device browser.
deviceInformation.httpBrowserColorDepthstringThe color depth of the device browser.
deviceInformation.httpBrowserJavaEnabledbooleanWhether Java is enabled on the device browser.
deviceInformation.httpBrowserJavaScriptEnabledbooleanWhether JavaScript is enabled on the device browser.
deviceInformation.httpBrowserLanguagestringThe language setting of the device browser.
deviceInformation.httpBrowserScreenHeightstringThe screen height of the device browser.
deviceInformation.httpBrowserScreenWidthstringThe screen width of the device browser.
deviceInformation.httpBrowserTimeDifferencestringThe time zone offset of the device browser.
deviceInformation.ipAddressstringThe IP address of the device.
deviceInformation.platformTypestringThe platform type of the device.
deviceInformation.userAgentBrowserValuestringThe user agent string of the device browser.
merchantInformation.merchantDescriptor.namestringThe merchant display name.
merchantInformation.merchantDescriptor.urlstringThe merchant URL.
orderInformation.amountDetails.currencystringThe currency code.
orderInformation.amountDetails.totalAmountstringThe total transaction amount.
orderInformation.billTo.address1stringThe cardholder's street address.
orderInformation.billTo.administrativeAreastringThe cardholder's state or province.
orderInformation.billTo.countrystringThe cardholder's country.
orderInformation.billTo.emailstringThe cardholder's email address.
orderInformation.billTo.firstNamestringThe cardholder's first name.
orderInformation.billTo.lastNamestringThe cardholder's last name.
orderInformation.billTo.localitystringThe cardholder's city. Required for countries where billing address information is available.
orderInformation.billTo.postalCodestringThe cardholder's postal code.
transactionTypestringThe type of transaction, for example ECOM for e-commerce.

Last published: September 29, 2026