Skip to main content

Step-Up Authentication Methods


Overview

When a request to create tokenized card authentication options returns STEP_UP_AUTHENTICATE, the issuer requires additional verification before the device can be approved and passkey registration can proceed. This page compares the available step-up methods and walks through the complete flow for each one.

Authentication Step-Up Methods

This table lists every step-up method, the stepUpOptions.method value that identifies it, and which endpoints apply to it:

Step-Up Method TypeStep-Up Method DescriptionstepUpOptions.methodExample ValuestepUpOptions.platformTypestepUpOptions.subMethodOne-Time PasswordsValidateAuthentication Registrations
One-time password (OTP)Email OTPOTP_EMAIL[email protected]——YesYesYes
One-time password (OTP)Issuer account login OTPOTP_ONLINE_BANKING———YesYesYes
One-time password (OTP)SMS OTPOTP_SMS———YesYesYes
Issuer applicationIssuer application does not return an issuer authentication codeAPP_TO_APPMobile Banking Application——NoNoYes
Issuer applicationIssuer application returns an issuer authentication codeAPP_TO_APPMobile Banking Application——NoYesYes
IssuerIssuer 3-D SecureAPP_TO_APPMobile Banking ApplicationWEB3DSNoNoYes
PhoneCardholder calls issuer call centerCUSTOMER_SERVICE1-800-555-1212——NoNoYes
PhoneIssuer calls cardholderOUTBOUND_CALL———NoNoYes

The endpoint columns refer to:

  • One-Time Passwords: POST /tms/v2/tokenized-cards/{tokenId}/authentication-options/one-time-passwords
  • Validate: POST /tms/v2/tokenized-cards/{tokenId}/authentication-options/validate
  • Authentication Registrations: POST /tms/v2/tokenized-cards/{tokenId}/authentication-registrations

Select the step-up method that matches the stepUpOptions.method value returned in your authentication options response to see its complete registration flow.

Last published: September 29, 2026