# 3DS


{% admonition type="danger" name="Preview only" %}
This is a preview of the next major version and is subject to change.

Estimated availability: Late 2026
{% /admonition %}

Verify your customer's identity to minimize fraud. Use our Strong Customer Authentication (SCA) to benefit from liability shift.

__Authentication__

Set your headers

```
Authorization: {your_credentials} 
Content-Type: application/json  
WP-Api-Version: 2026-10-01
```
Replace `{your_credentials}` with your base64-encoded Basic Auth username and password.

__DNS whitelisting__

Whitelist the following URLs: 
* `https://try.access.worldpay-bsh.securedataplatform.co.uk/`
* `https://access.worldpay-bsh.securedataplatform.co.uk/`

Please ensure you use DNS whitelisting, not explicit IP whitelisting. When you make a request within Access Worldpay, you should always cache the response returned.

Version: 2026-10-01

## Servers

Test (Try)
```
https://try.access.worldpay-bsh.securedataplatform.co.uk/3ds
```

Live
```
https://access.worldpay-bsh.securedataplatform.co.uk/3ds
```

## Security

### BasicAuth

Type: http
Scheme: basic

## Download OpenAPI description

 - [3DS](https://docs.worldpay-bsh.securedataplatform.co.uk/access/_bundle/products/3ds/@20261001/openapi.yaml)

## 3DS Authentication

 - [POST /authentications](https://docs.worldpay-bsh.securedataplatform.co.uk/access/products/3ds/20261001/openapi/authentication/authenticate.md): Authenticate your customer by submitting order and risk data.
 - [GET /authentications/{authenticationId}](https://docs.worldpay-bsh.securedataplatform.co.uk/access/products/3ds/20261001/openapi/authentication/authenticationquery.md): Query for the latest authentication state.
## Internal

 - [POST /deviceData/{key}/initialization](https://docs.worldpay-bsh.securedataplatform.co.uk/access/products/3ds/20261001/openapi/internal/devicedatainitialize.md): Details required for device data collection
 - [POST /deviceData/{key}/complete](https://docs.worldpay-bsh.securedataplatform.co.uk/access/products/3ds/20261001/openapi/internal/devicedatacomplete.md): Provide the `sessionId` or `consumerSessionId` from device data collection to continue the 3DS authentication. **This endpoint is not used for the `redirect` flow.**
 - [POST /challenges/{key}/complete](https://docs.worldpay-bsh.securedataplatform.co.uk/access/products/3ds/20261001/openapi/internal/challengecomplete.md): Verify the results of a challenged authentication.
