Using the cached PRes data the 3DS Requestor and 3DS Server determine whether the card range has a 3DS Method URL and, if so, the 3DS Requestor invokes the 3DS Method before the AReq: it creates a JSON object with the 3DS Server Transaction ID and the 3DS Method Notification URL, Base64-encodes it and posts it from a hidden iframe to the 3DS Method URL of the ACS; the ACS gathers browser information in the iframe, stores it against the 3DS Server Transaction ID, and posts completion to the notification URL without affecting the user experience.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.