SPC is a browser-channel challenge using FIDO credentials registered earlier, on condition that the ACS holds a registered authenticator for the cardholder and the browser supports the SPC API; the DS may act as FIDO relying party for some or all ACS steps. Requestor-initiated: the requestor shows the processing screen until it calls the API; a 3DS Server that sees SPC support in the ACS Information Indicator sets 3DS Requestor SPC Support to Y; an ACS choosing SPC returns status S with the WebAuthn Credential List (1 to 10 relying party and credential IDs) and SPC Transaction Data (a random challenge of 43 to 100 characters against replay, amount and currency, card display name and icon, optional issuer and payment system images, payee name or origin, a timeout of 60,000 to 500,000 milliseconds); the 3DS Server passes these on, and the requestor must neither alter nor store them; after the cardholder authenticates the requestor sends a second AReq under a fresh 3DS Server Transaction ID, carrying the assertion as requestor authentication method 09 and the prior reference set to the ACS Transaction ID with prior method 05. A DS that checks the assertion records the result in its verification indicator. The ACS checks the signature, the consistency of the two AReqs and of the assertion with the transaction, and returns a status (Y expected, C for a further challenge). An SPC Incompletion Indicator reports failure, cancellation or timeout. ACS-initiated: the ACS returns C with Authentication Method 14 and runs SPC inside the browser challenge.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.