Authenticate with Passkey
When a request to create tokenized card authentication options returns AUTHENTICATE, a passkey already exists for the device and card combination, and the cardholder authenticates using their existing passkey. No issuer challenge or step-up is required.
Response
{ "action": "AUTHENTICATE", "authenticationContext": { "id": "de5ecf36-2a5c-4f66-b01f-15d6e5b73715", "endpoint": "/vts-auth/authenticate", "payload": "aGVsbG8", "platformType": "WEB" }}Follow these steps to create a cryptogram that supplies authenticated Payment Passkey credentials:
Step 1: Cardholder Authentication with FIDO
The cardholder authenticates with FIDO using the URL from the merchantInformation.merchantDescriptor.url field sent to the /tms/v2/tokenized-cards/{tokenId}/authentication-options endpoint.
Step 2: Create Payment Credentials with FIDO Data
Create a cryptogram that supplies authenticated Passkey Service credentials.
Endpoint
POST /tms/v2/tokens/{tokenId}/payment-credentials
POST /tms/v2/tokens/{tokenId}/payment-credentials
Example
{ "clientCorrelationId": "aB3cD4eF5gH6iJ7kL8mN9oP0qR1sT2uV3wX", "transactionType": "ECOM", "orderInformation": { "amountDetails": { "totalAmount": "102.21", "currency": "USD" }, "billTo": { "firstName": "John", "lastName": "Smith", "email": "[email protected]", "address1": "123 Fake Street", "locality": "Austin", "administrativeArea": "TX", "postalCode": "78751", "country": "US" } }, "merchantInformation": { "merchantDescriptor": { "name": "Merchants Name", "url": "http://www.example.com" } }, "buyerInformation": { "language": "en_US" }, "authenticatedIdentities": [ { "id": "HmP8qo_aBOGemJEV_VoC@KaolERq_rL>95dfJV[vtYvDkwf]MchKrItaM2^sGI0", "provider": "string", "data": "@=TFf@Xhj[Vl\\tpf3zJ=bl@E0HCqVcPlxFz]3yRLbG3bTpBzDJtHNMlnP6pL", "relyingPartyId": "<Base64URL encoded string>", "userAuthenticationMethod": "USERNAME_PASSWORD" } ], "deviceInformation": { "ipAddress": "127.0.0.1", "httpAcceptContent": "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36", "httpBrowserLanguage": "en-US", "httpBrowserJavaEnabled": true, "httpBrowserJavaScriptEnabled": true, "httpBrowserColorDepth": "24", "httpBrowserScreenHeight": "1080", "httpBrowserScreenWidth": "1920", "httpBrowserTimeDifference": "-480", "userAgentBrowserValue": "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" }}{ "_links": { "self": { "href": "/tms/v2/tokens/7010000000016241111/payment-credentials" } }, "tokenizedCard": { "state": "ACTIVE", "enrollmentId": "c2d1b36fad46aed1ca8318dca5ed1e02", "tokenReferenceId": "168661ada5115ca3589b1ba3dabdb102", "number": "4895370016750801", "expirationMonth": "12", "expirationYear": "2023", "type": "visa", "cryptogram": "AwAAAADggP/Ce5+ZciCXQUUAAAA=", "eci": "05", "requestorId": "40010052236", "card": { "suffix": "0394", "expirationMonth": "12", "expirationYear": "2023" } }, "card": { "number": "411111XXXXXX1111" }, "issuer": { "paymentAccountReference": "V0010013022298169667504231315" }, "processingInformation": { "authorizationOptions": { "initiator": { "merchantInitiatedTransaction": { "previousTransactionId": "123456789619999" } } }, "commerceIndicator": "vbv" }}{ "_links": { "self": { "href": "/tms/v2/tokens/7010000000016241111/payment-credentials" } }, "tokenizedCard": { "state": "ACTIVE", "enrollmentId": "c2d1b36fad46aed1ca8318dca5ed1e02", "tokenReferenceId": "168661ada5115ca3589b1ba3dabdb102", "number": "4895370016750801", "expirationMonth": "12", "expirationYear": "2023", "type": "visa", "cryptogram": "AwAAAADggP/Ce5+ZciCXQUUAAAA=", "eci": "07", "requestorId": "40010052236", "card": { "suffix": "0394", "expirationMonth": "12", "expirationYear": "2023" } }, "card": { "number": "411111XXXXXX1111" }, "issuer": { "paymentAccountReference": "V0010013022298169667504231315" }, "processingInformation": { "authorizationOptions": { "initiator": { "merchantInitiatedTransaction": { "previousTransactionId": "123456789619999" } } }, "commerceIndicator": "internet" }}| Field | Type | Description |
|---|---|---|
authenticatedIdentities.data | string | The FIDO authentication response data (fidoResponse.fidoBlob). |
authenticatedIdentities.id | string | A unique identifier for the authenticated identity (fidoResponse.identifier). |
authenticatedIdentities.provider | string | The identity provider that performed the authentication. |
authenticatedIdentities.relyingPartyId | string | The FIDO relying party identifier, Base64URL encoded (fidoResponse.rpID). |
clientCorrelationId | string | A unique identifier for the client request. |
deviceInformation.httpAcceptContent | string | The HTTP Accept header from the device browser. |
deviceInformation.httpBrowserColorDepth | string | The color depth of the device browser. |
deviceInformation.httpBrowserJavaEnabled | boolean | Whether Java is enabled on the device browser. |
deviceInformation.httpBrowserJavaScriptEnabled | boolean | Whether JavaScript is enabled on the device browser. |
deviceInformation.httpBrowserLanguage | string | The language setting of the device browser. |
deviceInformation.httpBrowserScreenHeight | string | The screen height of the device browser. |
deviceInformation.httpBrowserScreenWidth | string | The screen width of the device browser. |
deviceInformation.httpBrowserTimeDifference | string | The time zone offset of the device browser. |
deviceInformation.ipAddress | string | The IP address of the device. |
deviceInformation.platformType | string | The platform type of the device. |
deviceInformation.userAgentBrowserValue | string | The user agent string of the device browser. |
merchantInformation.merchantDescriptor.name | string | The merchant display name. |
merchantInformation.merchantDescriptor.url | string | The merchant URL. |
orderInformation.amountDetails.currency | string | The currency code. |
orderInformation.amountDetails.totalAmount | string | The total transaction amount. |
orderInformation.billTo.address1 | string | The cardholder's street address. |
orderInformation.billTo.administrativeArea | string | The cardholder's state or province. |
orderInformation.billTo.country | string | The cardholder's country. |
orderInformation.billTo.email | string | The cardholder's email address. |
orderInformation.billTo.firstName | string | The cardholder's first name. |
orderInformation.billTo.lastName | string | The cardholder's last name. |
orderInformation.billTo.locality | string | The cardholder's city. Required for countries where billing address information is available. |
orderInformation.billTo.postalCode | string | The cardholder's postal code. |
transactionType | string | The type of transaction, for example ECOM for e-commerce. |
Thanks for your feedback!
Last published: September 29, 2026