# Continue with the payment after a 3DS challenge

Verify authentication challenge

Endpoint: POST /api/payments/{linkData}/3dsChallenges
Version: 2024-06-01
Security: BasicAuth

## Security:

  - `BasicAuth` (unknown)
    http basic

## Path parameters:

  - `linkData` (string, required)

## Header parameters:

  - `WP-Api-Version` (string, required)
    The API version

## Response 201:

  - `201` (unknown)
    Created

## Response 201 fields (application/json):

  - `outcome` (string)

  - `transactionReference` (string)
    A unique reference generated by you that is used to identify a payment throughout its lifecycle.

  - `paymentId` (string)
    Unique identifier generated by us for a single payment. Generated at authorization, and maintained through successive payment actions.

  - `commandId` (string)
    Unique identifier generated by us for a single instance of an interaction (command) with the Worldpay API.

  - `paymentInstrument` (object)
    Details of the paymentInstrument used.

  - `paymentInstrument.type` (string)

  - `paymentInstrument.cardBin` (string)
    The card BIN (Bank Identification Number) is the first six or eight digits of the card number, and you can use it to identify the card issuer, the card brand(s) (eg Visa, Cartes Bancaires) and the country. You can use card BINs to route transactions, check card capabilities and in fraud assessments.
    Example: 444433

  - `paymentInstrument.lastFour` (string)
    The last four digits of the card. Some characters may be obfuscated with a `*` if the PAN length is less than 16 characters.
    Example: 1111

  - `paymentInstrument.countryCode` (string)
    The [ISO 3166-1 Alpha-2 format](/products/reference/supported-countries-currencies#iso-country-codes) country code that the card was issued in. May return `N/A` where the country is unknown.
    Example: GB

  - `paymentInstrument.expiryDate` (object)
    Contains your customer's card or token expiry date.

  - `paymentInstrument.expiryDate.year` (integer, required)
    Example: 2028

  - `paymentInstrument.expiryDate.month` (integer, required)
    Example: 6

  - `paymentInstrument.cardBrand` (string)
    The card brand that the transaction was processed with. Sometimes referred to as the network or scheme.
    Enum: "visa", "mastercard", "amex", "maestro", "visaElectron", "diners", "discover", "jcb", "argencard", "cabal", "carteBleue", "cartesBancaires", "carnet", "cencosud", "coopeplus", "credimas", "dankort", "elo", "eftposAU", "hipercard", "italcred", "naranja", "nativa", "nevada", "nexo", "tarjeta", "unionPay"

  - `paymentInstrument.fundingType` (string)
    How the card is funded.
    Enum: "credit", "debit", "prepaid", "chargeCard", "deferredDebit", "unknown"

  - `paymentInstrument.category` (string)
    Whether the card is classed as a consumer card or a card for commercial use.
    Enum: "commercial", "consumer"

  - `paymentInstrument.issuerName` (string)
    The name of the card issuer.
    Example: AN ISSUING BANK LTD

  - `paymentInstrument.paymentAccountReference` (string)
    The Payment Account Reference (PAR) is a non-financial reference that uniquely identifies the underlying cardholder account. This allows you to correlate payments made from the same account with differing instruments, where the same account funds the transaction. You cannot use a PAR to initiate a payment.
    Example: Q1HJZ28RKA1EBL470G9XYG90R5D3E

  - `updatedPaymentInstrument` (object)

  - `updatedPaymentInstrument.type` (string, required)
    The type of updated instrument.

  - `updatedPaymentInstrument.appliedNetworkToken` (boolean)

  - `updatedPaymentInstrument.type` (string)
    Enum: "card/plain"

  - `updatedPaymentInstrument.cardNumber` (string)

  - `updatedPaymentInstrument.accountUpdaterMessage` (string)
    Details on the type of payment instrument update.
    Enum: "The merchant is not registered in the update program", "The account number was changed", "The account was closed", "The expiry was changed", "The issuing bank does not participate in the update program", "Contact the cardholder for updated information", "No match found", "No changes found"

  - `updatedPaymentInstrument.cardBrand` (string)
    The brand of the updated card. In rare circumstances a card may be reissued under a different brand.

  - `updatedPaymentInstrument.fundingType` (string)
    How the card is funded.

  - `updatedPaymentInstrument.countryCode` (string)

  - `updatedPaymentInstrument.cardBin` (string)
    The updated card BIN (Bank Identification Number).
    Example: 444433

  - `updatedPaymentInstrument.lastFour` (string)
    The four digits of the updated card. Some characters may be obfuscated with a * if the PAN length is less than 16 characters.
    Example: 1111

  - `issuer` (object)

  - `issuer.authorizationCode` (string)

  - `riskFactors` (array)
    Any risk factors which have been identified for the authorization. This section will not appear if no risks are identified.

  - `riskFactors.risk` (string)
    Enum: "notChecked", "notMatched", "notSupplied", "verificationFailed"

  - `riskFactors.detail` (string)
    Enum: "address", "postcode"

  - `riskFactors.type` (string)
    Enum: "avs", "cvc", "riskProfile"

  - `fraud` (object)
    Details of the outcome of the Fraud assessment

  - `fraud.outcome` (string)
    outcome of the fraud assessment. `highRisk` outcomes stop the transaction before payment.
    Enum: "lowRisk", "highRisk", "review", "lowRisk(silentMode)", "highRisk(silentMode)", "review(silentMode)"

  - `fraud.score` (number)
    The score calculated by the fraud assessment. Set score thresholds to define `lowRisk`, `highRisk` and `review` outcomes
    Example: 44

  - `threeDS` (object)

  - `threeDS.type` (string)
    Describes if the authentication was done by a third party or internally.
    Enum: "external", "integrated"

  - `threeDS.outcome` (string)
    Indicates the outcome of the authentication request. `authenticated` indicates a successful authentication.  The `authenticationOutage` outcome is not enabled by default. Please contact your Worldpay Implementation Manager if you would like to receive `authenticationOutage` responses. By applying the authentication outage exemption, the issuer is more likely to authorize the payment, but it will not be eligible for liability shift.
    Enum: "authenticated", "authenticationOutage"

  - `threeDS.issuerResponse` (string)
    If the issuer decides to challenge the customer (`challenged`) or proceed without a challenge (`frictionless`).
    Enum: "frictionless", "challenged"

  - `threeDS.version` (string)
    The version of 3DS used to process the transaction.

  - `threeDS.eci` (string)
    Electronic Commerce Indicator (ECI). Indicates the outcome of the 3DS authentication.
| ECI | Meaning |
|  --- | --- |
| 02 or 05 | Fully authenticated transaction. |
| 01 or 06 | Attempted authentication transaction. |
| 00 or 07 | Non 3D Secure transaction. |

| Scheme | Value |
|  --- | --- |
| Mastercard | 02, 01, 00 |
| Visa | 05, 06, 07 |
| Amex | 05, 06, 07 |
| JCB | 05, 06, 07 |
| Diners | 05, 06, 07 |

  - `threeDS.acsTransactionId` (string)
    An identifier assigned by the Access Control Server (ACS) to identify a single transaction. Used primarily for Mastercard 3RI subsequent transactions to link the subsequent transaction back to a previous cardholder authentication. Can be disregarded unless otherwise needed.

  - `threeDS.dsTransactionId` (string)
    The directory server transaction Id.

  - `threeDS.challengePreference` (string)
    Indicates the preferred challenge behavior. **We return this for Cartes Bancaires authentications only** and you must apply it in the following authorization request.
- `noPreference`
- `noChallengeRequested`
- `challengeRequested`
- `challengeMandated`
- `noChallengeRequestedTRAPerformed`

  - `exemption` (object)
    An object containing information about the exemption.

  - `exemption.granted` (boolean)
    Was an exemption returned by Worldpay's TRA assessment.

  - `exemption.placement` (string)
    Indicates whether the exemption has been placed in a payment authorization request or 3DS authentication request.
    Enum: "authorization"

  - `exemption.type` (string)
    The type of applied exemption.
    Enum: "lowRisk", "lowValue"

  - `exemption.result` (string)
    The result of the exemption placement request.
    Enum: "honored", "outOfScope", "rejected", "unknown"

  - `exemption.reason` (string)
    The reason returned by the card issuer.
    Enum: "issuerHonored", "merchantInitiatedTransaction", "oneLegOut", "issuerHonored", "moto", "contactless", "issuerRejected", "highRisk", "invalid", "unsupportedScheme", "unsupportedAcquirer", "unknown"

  - `schemeReference` (string)
    An object containing information returned by the scheme.

  - `token` (object)
    An object including the token details you have asked us to create.

  - `token.href` (string)
    The token href you can save for use in future payment requests.
    Example: https://try.access.worldpay-bsh.securedataplatform.co.uk/tokens/eyJrIjoxLCJkIjoiUW5rZHBXZDZ1MzBBY0I0MTVJQUdPeGE3ZkFobE1lTjJyYk05eDZxQUJ2RT0ifQ

  - `token.tokenId` (string)
    The unique ID of the token.
    Example: 9997095516055002467

  - `token.tokenExpiryDateTime` (string)
    The date and time the token expires.
    Example: 2024-04-12T11:49:56Z

  - `token.cardNumber` (string)
    The masked card number associated with this token.
    Example: 4000********1091

  - `token.cardHolderName` (string)
    The name of the cardholder.
    Example: Sherlock Holmes

  - `token.bin` (string)
    Example: 400000

  - `token.fundingType` (string)
    Example: debit

  - `token.countryCode` (string)

  - `token.schemeReference` (string)
    Example: 060720116005060

  - `token.conflicts` (object)

  - `token.conflicts.conflictsExpiryDateTime` (string)

  - `token.conflicts.schemeReference` (string)

  - `token.conflicts.paymentInstrument` (object)

  - `token.conflicts.paymentInstrument.type` (string)

  - `token.conflicts.paymentInstrument.cardNumber` (string)

  - `token.conflicts.paymentInstrument.cardHolderName` (string)

  - `token.conflicts.paymentInstrument.billingAddress` (object)
    Contains the billing address information.

  - `token.conflicts.paymentInstrument.billingAddress.address1` (string, required)
    Address line 1

  - `token.conflicts.paymentInstrument.billingAddress.address2` (string)
    Address line 2

  - `token.conflicts.paymentInstrument.billingAddress.address3` (string)
    Address line 3

  - `token.conflicts.paymentInstrument.billingAddress.postalCode` (string)
    Required for all countries except the following: IE

  - `token.conflicts.paymentInstrument.billingAddress.city` (string, required)
    Address City

  - `token.conflicts.paymentInstrument.billingAddress.state` (string)
    Address State

  - `token.conflicts.paymentInstrument.billingAddress.countryCode` (string, required)
    Must be provided in [ISO 3166-1 alpha-2 format](/products/reference/supported-countries-currencies#iso-country-codes).

  - `merchant` (object)

  - `merchant.downstreamIdentity` (string)
    Merchant identity returned in the API response when `merchant.downstreamIdentityInResponse` is set to `true`.

  - `amounts` (object)
    An object containing transaction amounts. Returned for partial authorizations.

  - `amounts.requested` (integer)
    The requested amount.
    Example: 1000

  - `amounts.totalAuthorized` (integer)
    The total amount authorized by the card issuer.
    Example: 700

  - `amounts.currency` (string)
    The three character currency code. See list of supported currencies.
    Example: GBP

  - `amounts.partialAuthorization` (boolean)
    Indicates that the authorized amount is less than what you have requested.

  - `_links` (object)
    Return details about the status of the payment.

  - `_links.self` (object)

  - `_links.self.href` (string)

  - `_actions` (object)

  - `_actions.cancelPayment` (object)
    Cancel the payment. See [details](/products/payments/openapi/manage-payments/cancel)

  - `_actions.cancelPayment.href` (string)

  - `_actions.cancelPayment.method` (string)

  - `_actions.partiallyCancelPayment` (object)
    Partially cancel the payment. See [details](/products/payments/openapi/manage-payments/partialcancel)

  - `_actions.partiallyCancelPayment.href` (string)

  - `_actions.partiallyCancelPayment.method` (string)

  - `_actions.settlePayment` (object)
    Fully settle the payment. See [details](/products/payments/openapi/manage-payments/settle).

  - `_actions.settlePayment.href` (string)

  - `_actions.settlePayment.method` (string)

  - `_actions.partiallySettlePayment` (object)
    Partially settle the payment. See [details](/products/payments/openapi/manage-payments/partialsettle) including what to add in the request body.

  - `_actions.partiallySettlePayment.href` (string)

  - `_actions.partiallySettlePayment.method` (string)

  - `_actions.increaseAuthorizedAmount` (object)
    Increase the authorized amount. See [details](/products/payments/openapi/manage-payments/increaseauthorizedamount)

  - `_actions.increaseAuthorizedAmount.href` (string)

  - `_actions.increaseAuthorizedAmount.method` (string)

  - `_actions.reversePayment` (object)
    Reverse the payment. See [details](/products/payments/openapi/manage-payments/reversal)

  - `_actions.reversePayment.href` (string)

  - `_actions.reversePayment.method` (string)

  - `commandId` (string)
    Unique identifier generated by us for a single instance of an interaction (command) with our API.

  - `refusalDescription` (string)
    Additional context on the refusal.

  - `refusalCode` (string)
    Response code for the request.

  - `advice` (object)

  - `advice.code` (string)

  - `authentication` (object)

  - `authentication.version` (string)
    The version of 3DS used to process the transaction.
    Example: 2.2.0

  - `authentication.type` (string)

  - `authentication.authenticationValue` (string)

  - `authentication.eci` (string)
    Electronic Commerce Indicator (ECI). Indicates the outcome of the 3DS authentication.

  - `authentication.transactionId` (string)
    A transaction identifier.

  - `authentication.cryptogramAlgorithm` (string)

  - `authentication.challengePreference` (string)

  - `authentication.authenticationFlow` (string)

  - `authentication.networkScore` (string)

  - `authentication.brand` (string)

## Response 202:

  - `202` (unknown)
    Accepted

## Response 202 fields (application/json):

  - `outcome` (string)

  - `paymentId` (string)
    Unique identifier generated by us for a single payment. Generated at authorization, and maintained through successive payment actions.

  - `commandId` (string)
    Unique identifier generated by us for a single instance of an interaction (command) with our API.

  - `transactionReference` (string)
    A unique reference generated by you that is used to identify a payment throughout its lifecycle.

  - `paymentInstrument` (object)
    Details of the paymentInstrument used.

  - `paymentInstrument.type` (string)

  - `paymentInstrument.cardBin` (string)
    The card BIN (Bank Identification Number) is the first six or eight digits of the card number, and you can use it to identify the card issuer, the card brand(s) (eg Visa, Cartes Bancaires) and the country. You can use card BINs to route transactions, check card capabilities and in fraud assessments.
    Example: 444433

  - `paymentInstrument.lastFour` (string)
    The last four digits of the card. Some characters may be obfuscated with a `*` if the PAN length is less than 16 characters.
    Example: 1111

  - `paymentInstrument.countryCode` (string)
    The [ISO 3166-1 Alpha-2 format](/products/reference/supported-countries-currencies#iso-country-codes) country code that the card was issued in. May return `N/A` where the country is unknown.
    Example: GB

  - `paymentInstrument.expiryDate` (object)
    Contains your customer's card or token expiry date.

  - `paymentInstrument.expiryDate.year` (integer, required)
    Example: 2028

  - `paymentInstrument.expiryDate.month` (integer, required)
    Example: 6

  - `paymentInstrument.cardBrand` (string)
    The card brand that the transaction was processed with. Sometimes referred to as the network or scheme.
    Enum: "visa", "mastercard", "amex", "maestro", "visaElectron", "diners", "discover", "jcb", "argencard", "cabal", "carteBleue", "cartesBancaires", "carnet", "cencosud", "coopeplus", "credimas", "dankort", "elo", "eftposAU", "hipercard", "italcred", "naranja", "nativa", "nevada", "nexo", "tarjeta", "unionPay"

  - `paymentInstrument.fundingType` (string)
    How the card is funded.
    Enum: "credit", "debit", "prepaid", "chargeCard", "deferredDebit", "unknown"

  - `paymentInstrument.category` (string)
    Whether the card is classed as a consumer card or a card for commercial use.
    Enum: "commercial", "consumer"

  - `paymentInstrument.issuerName` (string)
    The name of the card issuer.
    Example: AN ISSUING BANK LTD

  - `paymentInstrument.paymentAccountReference` (string)
    The Payment Account Reference (PAR) is a non-financial reference that uniquely identifies the underlying cardholder account. This allows you to correlate payments made from the same account with differing instruments, where the same account funds the transaction. You cannot use a PAR to initiate a payment.
    Example: Q1HJZ28RKA1EBL470G9XYG90R5D3E

  - `updatedPaymentInstrument` (object)

  - `updatedPaymentInstrument.type` (string, required)
    The type of updated instrument.

  - `updatedPaymentInstrument.appliedNetworkToken` (boolean)

  - `updatedPaymentInstrument.type` (string)
    Enum: "card/plain"

  - `updatedPaymentInstrument.cardNumber` (string)

  - `updatedPaymentInstrument.accountUpdaterMessage` (string)
    Details on the type of payment instrument update.
    Enum: "The merchant is not registered in the update program", "The account number was changed", "The account was closed", "The expiry was changed", "The issuing bank does not participate in the update program", "Contact the cardholder for updated information", "No match found", "No changes found"

  - `updatedPaymentInstrument.cardBrand` (string)
    The brand of the updated card. In rare circumstances a card may be reissued under a different brand.

  - `updatedPaymentInstrument.fundingType` (string)
    How the card is funded.

  - `updatedPaymentInstrument.countryCode` (string)

  - `updatedPaymentInstrument.cardBin` (string)
    The updated card BIN (Bank Identification Number).
    Example: 444433

  - `updatedPaymentInstrument.lastFour` (string)
    The four digits of the updated card. Some characters may be obfuscated with a * if the PAN length is less than 16 characters.
    Example: 1111

  - `issuer` (object)

  - `issuer.authorizationCode` (string)

  - `riskFactors` (array)
    Any risk factors which have been identified for the authorization. This section will not appear if no risks are identified.

  - `riskFactors.risk` (string)
    Enum: "notChecked", "notMatched", "notSupplied", "verificationFailed"

  - `riskFactors.detail` (string)
    Enum: "address", "postcode"

  - `riskFactors.type` (string)
    Enum: "avs", "cvc", "riskProfile"

  - `fraud` (object)
    Details of the outcome of the Fraud assessment

  - `fraud.outcome` (string)
    outcome of the fraud assessment. `highRisk` outcomes stop the transaction before payment.
    Enum: "lowRisk", "highRisk", "review", "lowRisk(silentMode)", "highRisk(silentMode)", "review(silentMode)"

  - `fraud.score` (number)
    The score calculated by the fraud assessment. Set score thresholds to define `lowRisk`, `highRisk` and `review` outcomes
    Example: 44

  - `threeDS` (object)

  - `threeDS.type` (string)
    Describes if the authentication was done by a third party or internally.
    Enum: "external", "integrated"

  - `threeDS.outcome` (string)
    Indicates the outcome of the authentication request. `authenticated` indicates a successful authentication.  The `authenticationOutage` outcome is not enabled by default. Please contact your Worldpay Implementation Manager if you would like to receive `authenticationOutage` responses. By applying the authentication outage exemption, the issuer is more likely to authorize the payment, but it will not be eligible for liability shift.
    Enum: "authenticated", "authenticationOutage"

  - `threeDS.issuerResponse` (string)
    If the issuer decides to challenge the customer (`challenged`) or proceed without a challenge (`frictionless`).
    Enum: "frictionless", "challenged"

  - `threeDS.version` (string)
    The version of 3DS used to process the transaction.

  - `threeDS.eci` (string)
    Electronic Commerce Indicator (ECI). Indicates the outcome of the 3DS authentication.
| ECI | Meaning |
|  --- | --- |
| 02 or 05 | Fully authenticated transaction. |
| 01 or 06 | Attempted authentication transaction. |
| 00 or 07 | Non 3D Secure transaction. |

| Scheme | Value |
|  --- | --- |
| Mastercard | 02, 01, 00 |
| Visa | 05, 06, 07 |
| Amex | 05, 06, 07 |
| JCB | 05, 06, 07 |
| Diners | 05, 06, 07 |

  - `threeDS.acsTransactionId` (string)
    An identifier assigned by the Access Control Server (ACS) to identify a single transaction. Used primarily for Mastercard 3RI subsequent transactions to link the subsequent transaction back to a previous cardholder authentication. Can be disregarded unless otherwise needed.

  - `threeDS.dsTransactionId` (string)
    The directory server transaction Id.

  - `threeDS.challengePreference` (string)
    Indicates the preferred challenge behavior. **We return this for Cartes Bancaires authentications only** and you must apply it in the following authorization request.
- `noPreference`
- `noChallengeRequested`
- `challengeRequested`
- `challengeMandated`
- `noChallengeRequestedTRAPerformed`

  - `exemption` (object)
    An object containing information about the exemption.

  - `exemption.granted` (boolean)
    Was an exemption returned by Worldpay's TRA assessment.

  - `exemption.placement` (string)
    Indicates whether the exemption has been placed in a payment authorization request or 3DS authentication request.
    Enum: "authorization"

  - `exemption.type` (string)
    The type of applied exemption.
    Enum: "lowRisk", "lowValue"

  - `exemption.result` (string)
    The result of the exemption placement request.
    Enum: "honored", "outOfScope", "rejected", "unknown"

  - `exemption.reason` (string)
    The reason returned by the card issuer.
    Enum: "issuerHonored", "merchantInitiatedTransaction", "oneLegOut", "issuerHonored", "moto", "contactless", "issuerRejected", "highRisk", "invalid", "unsupportedScheme", "unsupportedAcquirer", "unknown"

  - `schemeReference` (string)
    An object containing information returned by the scheme.

  - `token` (object)
    An object including the token details you have asked us to create.

  - `token.href` (string)
    The token href you can save for use in future payment requests.
    Example: https://try.access.worldpay-bsh.securedataplatform.co.uk/tokens/eyJrIjoxLCJkIjoiUW5rZHBXZDZ1MzBBY0I0MTVJQUdPeGE3ZkFobE1lTjJyYk05eDZxQUJ2RT0ifQ

  - `token.tokenId` (string)
    The unique ID of the token.
    Example: 9997095516055002467

  - `token.tokenExpiryDateTime` (string)
    The date and time the token expires.
    Example: 2024-04-12T11:49:56Z

  - `token.cardNumber` (string)
    The masked card number associated with this token.
    Example: 4000********1091

  - `token.cardHolderName` (string)
    The name of the cardholder.
    Example: Sherlock Holmes

  - `token.bin` (string)
    Example: 400000

  - `token.fundingType` (string)
    Example: debit

  - `token.countryCode` (string)

  - `token.schemeReference` (string)
    Example: 060720116005060

  - `token.conflicts` (object)

  - `token.conflicts.conflictsExpiryDateTime` (string)

  - `token.conflicts.schemeReference` (string)

  - `token.conflicts.paymentInstrument` (object)

  - `token.conflicts.paymentInstrument.type` (string)

  - `token.conflicts.paymentInstrument.cardNumber` (string)

  - `token.conflicts.paymentInstrument.cardHolderName` (string)

  - `token.conflicts.paymentInstrument.billingAddress` (object)
    Contains the billing address information.

  - `token.conflicts.paymentInstrument.billingAddress.address1` (string, required)
    Address line 1

  - `token.conflicts.paymentInstrument.billingAddress.address2` (string)
    Address line 2

  - `token.conflicts.paymentInstrument.billingAddress.address3` (string)
    Address line 3

  - `token.conflicts.paymentInstrument.billingAddress.postalCode` (string)
    Required for all countries except the following: IE

  - `token.conflicts.paymentInstrument.billingAddress.city` (string, required)
    Address City

  - `token.conflicts.paymentInstrument.billingAddress.state` (string)
    Address State

  - `token.conflicts.paymentInstrument.billingAddress.countryCode` (string, required)
    Must be provided in [ISO 3166-1 alpha-2 format](/products/reference/supported-countries-currencies#iso-country-codes).

  - `merchant` (object)

  - `merchant.downstreamIdentity` (string)
    Merchant identity returned in the API response when `merchant.downstreamIdentityInResponse` is set to `true`.

  - `amounts` (object)
    An object containing transaction amounts. Returned for partial authorizations.

  - `amounts.requested` (integer)
    The requested amount.
    Example: 1000

  - `amounts.totalAuthorized` (integer)
    The total amount authorized by the card issuer.
    Example: 700

  - `amounts.currency` (string)
    The three character currency code. See list of supported currencies.
    Example: GBP

  - `amounts.partialAuthorization` (boolean)
    Indicates that the authorized amount is less than what you have requested.

  - `_links` (object)
    Return details about the status of the payment.

  - `_links.self` (object)

  - `_links.self.href` (string)

  - `_actions` (object)

  - `_actions.refundPayment` (object)
    Fully refund the payment. See [details](/products/payments/openapi/manage-payments/refund)

  - `_actions.refundPayment.href` (string)

  - `_actions.refundPayment.method` (string)

  - `_actions.partiallyRefundPayment` (object)
    Partially refund the payment. See [details](/products/payments/openapi/manage-payments/partialrefund)

  - `_actions.partiallyRefundPayment.href` (string)

  - `_actions.partiallyRefundPayment.method` (string)

  - `_actions.reversePayment` (object)
    Reverse the payment. See [details](/products/payments/openapi/manage-payments/reversal)

  - `_actions.reversePayment.href` (string)

  - `_actions.reversePayment.method` (string)

## Response 400:

  - `400` (unknown)
    Bad request

## Response 400 fields (application/json):

  - `errorName` (string)

  - `message` (string)

  - `jsonPath` (string)

  - `validationErrors` (array)

  - `validationErrors.errorName` (string)

  - `validationErrors.message` (string)

  - `validationErrors.jsonPath` (string)

  - `validationErrors.validationErrors` (array)

## Response 401:

  - `401` (unknown)
    Unauthorized

## Response 401 fields (application/json):

  - `errorName` (string)

  - `message` (string)

## Response 406:

  - `406` (unknown)
    Not acceptable

## Response 406 fields (application/json):

  - `errorName` (string)

  - `message` (string)

  - `headerName` (string)

## Response 415:

  - `415` (unknown)
    Unsupported media type

## Response 415 fields (application/json):

  - `errorName` (string)

  - `message` (string)

## Response 500:

  - `500` (unknown)
    Internal server error

## Response 500 fields (application/json):

  - `errorName` (string)

  - `message` (string)

## Response 201 examples:

  - `authorized` (unknown)
    Example of a authorized response following a successful 3DS challenge, use the action `settlePayment` to complete the transaction
* includes fraud, token and threeDS objects

  - `refused` (unknown)
    Example of a refused response.

  - `3dsUnavailable` (unknown)
    3DS is unavailable when attempting authentication. If `/3dsChallenges` is called without completing the challenge this response may also be returned.

  - `3dsAuthenticationFailed` (unknown)
    Authentication failed by the issuer as part of a frictionless flow or the challenge (identity check) was attempted but failed by the customer

## Response 202 examples:

  - `sentForSettlement` (unknown)
    Example of a sentForSettlement response following a successful 3DS challenge
* auto settlement was enabled in the payments request
* includes fraud, token and threeDS objects

  - `sentForCancellation` (unknown)

## Response 400 examples:

  - `Bad request` (unknown)

## Response 401 examples:

  - `Unauthorized` (unknown)

## Response 406 examples:

  - `Not acceptable` (unknown)

## Response 415 examples:

  - `Unsupported media type` (unknown)

## Response 500 examples:

  - `Internal server error` (unknown)

