In the HTML UI the SDK hosts ACS-supplied HTML in a web view as an extension of its own UI: it keeps the processing screen up after each CReq until the CRes or timeout (Req 4.19), extracts and displays the ACS HTML from the CRes (Req 4.26), intercepts and blocks every request the web view makes for outside resources or navigate away (Req 4.27), places the 3DS Requestor header above the ACS HTML (Req 4.28), uses a web view to display it (Req 4.29), processes Cancel and returns control to the app (Req 4.30, 4.31), and on submit passes the cardholder's input back to the ACS, carried in the ACS HTML data element, unchanged. The ACS supplies a complete responsive HTML document with CSS, images and logos embedded and no external references (Req 4.20 to 4.23), signals submission by a location change to the specified HTTPS://EMV3DS/challenge URL (Req 4.24) and never bypasses the SDK or connects back to itself directly (Req 4.25). The HTML Other rendering type allows issuer methods beyond the native options, subject to DS rules.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.