Skip to content

Query

Request

Query for the latest authentication state.

Security
BasicAuth
Path
authenticationIdstringrequired

Unique identifier for a single 3ds authentication. Generated by us.

Headers
WP-Api-Versionstringrequired

The API version.

Value:"2026-12-01"
Example:2026-12-01
curl -i -X GET \
  -u '<username>:<password>' \
  'https://try.access.worldpay-bsh.securedataplatform.co.uk/3ds/authentications/{authenticationId}' \
  -H 'WP-Api-Version: 2026-12-01'

Responses

The authentication has been created

Bodyapplication/json
outcomestringrequired

The latest outcome state for a given request authenticationId.

Enum ValueDescription
3dsAuthenticated

Cardholder successfully authenticated by card issuer.

3dsAttempted

3DS attempted but card issuer not participating. Stand-in authentication by the scheme.

3dsRejected

Issuer rejects the authentication, do not proceed with payment.

3dsNotAuthenticated

Authentication failure by card issuer (system issue).

3dsUnavailable

Authentication unavailable at this current time.

3dsChallengeFailed

Failed cardholder challenge.

3dsOutage

Issuer recognized outage. Can attempt authentication outage exemption.

3dsBypassed

3DS bypassed based on rules or recommendation from authentication optimization service.

3dsExempted

Successful exemption in 3DS authentication.

3dsAlreadyAuthenticated

The provided token is already SCA compliant. E.g. the google encrypted payload provided is 3DS_CRYPTOGRAM (authenticated) and not PAN_ONLY.

3dsRedirect

3DS hosted redirect Url provided by Worldpay for clientside interaction.

Discriminator
statusstring, [ 1 .. 2 ] characters

Indicates the outcome of the authentication or verification request.

  • Y - Successful authentication
  • N - Failed authentication
  • U - Unable to complete authentication
  • A - Successful attempts authentication
  • C - Challenged authentication
  • R - Authentication rejected (merchant must not submit for authorization)
  • I - Exemption acknowledged
enrolledstring, = 1 characters

Status of authentication eligibility.

  • Y - Bank is participating in 3DS
  • N - Bank is not participating in 3DS
  • U - The Directory Server (DS) or Access Control Server (ACS) were not available at the time of the request
  • B - Merchant authentication rule is triggered to bypass authentication (3DS premium only)
versionstring, [ 1 .. 10 ] characters

The version of 3DS used to process the transaction.

authenticationValuestring, [ 1 .. 64 ] characters

A cryptographic value that provides evidence of the outcome of a 3DS verification.

  • Visa - Cardholder Authentication Verification Value (CAVV)
  • Mastercard - Universal Cardholder Authentication Field (UCAF)
ecistring, [ 1 .. 2 ] characters

Commerce Indicator (ECI). Indicates the outcome of the 3DS authentication.

ECIMeaning
02 or 05Fully Authenticated Transaction
01 or 06Attempted Authentication Transaction
00 or 07Non 3-D Secure Transaction
SchemeValue
Mastercard02, 01, 00
Visa05, 06, 07
Amex05, 06, 07
JCB05, 06, 07
Diners05, 06, 07
dsTransactionIdstring, [ 1 .. 64 ] characters

Directory server transaction ID, if provided should be used in the payment authorization authentication object.

acsTransactionIdstring, [ 1 .. 64 ] characters

ACS transaction ID, if provided should be used in the payment authorization authentication object.

cryptogramAlgorithmstring, [ 1 .. 99999 ] characters

Indicates the algorithm used to generate the cryptogram. Returned for Cartes Bancaires authentications only and must be applied in the following authorization request.

challengePreferencestring, [ 1 .. 64 ] characters

Indicates the preferred challenge behavior. Returned for Cartes Bancaires authentications only and must be applied in the following authorization request.

  • noPreference
  • noChallengeRequested
  • challengeRequested
  • challengeMandated
authenticationFlowstring, [ 1 .. 64 ] characters

Indicates which flow the customer has been directed to. Returned for Cartes Bancaires authentications only and must be applied in the following authorization request.

Enum:"challenge""frictionless"
statusReasonstring, [ 1 .. 2 ] characters

Provides further information relating to the outcome of the authentication. Returned for failed authentications only. Returned for Cartes Bancaires authentications only.

cancellationIndicatorstring, [ 0 .. 2 ] characters

An indicator as to why the authentication was cancelled. Returned for Cartes Bancaires authentications only.

  • 01 - Cardholder selected cancel
  • 02 - Reserved for future use
  • 03 - Authentication timed out
  • 04 and 05 - Authentication timed out at ACS provider
  • 06 - Transaction error
  • 07 - Unknown
  • 08 - Transaction timed out at SDK
networkScorestring, [ 0 .. 2 ] characters

The global score calculated by the Cartes Bancaires scoring platform. Returned for Cartes Bancaires authentications only.

brandstring, [ 0 .. 64 ] characters

The card brand used in the authentication. Returned for Cartes Bancaires authentications only and must be applied in the following authorization.

Response

Successful frictionless authentication

{ "outcome": "3dsAuthenticated", "status": "Y", "enrolled": "Y", "version": "2.2.0", "authenticationValue": "MAAAAAAAAAAAAAAAAAAAAAAAAAA=", "eci": "05", "dsTransactionId": "c5b808e7-1de1-4069-a17b-f70d3b3b1645", "acsTransactionId": "fe007a6e-315f-4cdf-98ca-28a9e40e3581", "_links": { "self": { "href": "https://try.access.worldpay-bsh.securedataplatform.co.uk/3ds/authentications/LfC-Tuhv7J2nEw2m9ca_e" } } }