EMV 3-D Secure (3DS) - Payment Authentication Protocol
Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol

EMV 3-D Secure (3DS) - Payment Authentication Protocol V.9: V.9 Out-of-band authentication: requirements and automatic app switching

For an out-of-band challenge (ACS UI Type 04 native or 06 HTML) the ACS learns the result from the OOB interaction, not from the CReq, and the SDK sets the OOB Continuation Indicator to 01 when the cardholder presses the continuation button and to 02 when the requestor app returns to the foreground, then sends the CReq without cardholder action. Two optional switches exist: the OOB App URL in the CRes, which the SDK uses to open the issuer's authentication app, and the 3DS Requestor App URL in the CReq, which that app uses to hand control back. The ACS sets the OOB App URL to the universal link registered at the authentication app's installation; for UI Type 06 its HTML triggers a location change to the reserved openoobApp address; for Type 04 the SDK shows a button with the OOB App Label. The SDK checks the URL uses HTTPS and reports an error otherwise, tries to open the app, and on failure sets OOB App Status 01, continuation 02 and sends the CReq automatically (the issuer serves a web page at that URL for devices without the app). The ACS likewise rejects a 3DS Requestor App URL that is not HTTPS. The SDK declares support in the OOB App URL Indicator (01 supported, 02 not by the device, 03 not by the requestor) and the ACS in the 3DS Requestor App URL Indicator. Switching cannot work when the authentication app is on another device.

Maintained by Gerard BlokdykControl text last updated

Other controls in Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.