Create 3DS Authenticated Payment
POST/payment/authorize
This method initiates a 3D Secure payment authorization.
This endpoint contains PCI data and requires forwarding through /forwarding/tokenize.
Request
Header Parameters
Must be application/json
Must be be en-US
The origin of the request
The client making the request
Basic M2lwN2Yx...OGU3Mg==
{baseUrl}/payment/authorize
{{pci_base64_public_private}}
cardDetails.cardToken
- application/json
- Body
- Example
Bodyrequired
payment objectrequired
The financial attributes of a transaction, required for all payment operations.
Description of the payment transaction shown to the customer.
Possible values: <= 127 characters
Total amount to be authorized.
Possible values: >= 0.01
ISO 4217 three-letter currency code.
Possible values: <= 3 characters, Value must match regular expression ^[A-Z]{3}$
billingAddress objectrequired
Street name.
Possible values: <= 60 characters
Max-Planck-StraßeApartment, suite, unit, building, floor or other secondary address information.
Possible values: <= 60 characters
Specific delivery instructions, department names, or additional floor information.
Possible values: <= 60 characters
The city or localitly of the address.
Possible values: <= 50 characters
BerlinISO-3 code of the address country (e.g., DEU for Germany).
Possible values: >= 3 characters and <= 3 characters
DEUThe house or building number corresponding to the street address.
Possible values: <= 10 characters
30The postal or ZIP code of the address.
Possible values: <= 10 characters
144733-letter code of the address state. Mandatory when countryCode corresponds to Canada or USA.
Possible values: <= 3 characters
shippingAddress object
Street name.
Possible values: <= 60 characters
Max-Planck-StraßeApartment, suite, unit, building, floor or other secondary address information.
Possible values: <= 60 characters
Specific delivery instructions, department names, or additional floor information.
Possible values: <= 60 characters
The city or localitly of the address.
Possible values: <= 50 characters
BerlinISO-3 code of the address country (e.g., DEU for Germany).
Possible values: >= 3 characters and <= 3 characters
DEUThe house or building number corresponding to the street address.
Possible values: <= 10 characters
30The postal or ZIP code of the address.
Possible values: <= 10 characters
144733-letter code of the address state. Mandatory when countryCode corresponds to Canada or USA.
Possible values: <= 3 characters
consumer objectnullablerequired
Consumer's personal data, in case the consumer is a physical person.
Mandatory, unless businessConsumer is provided.
consumer and businessConsumer objects may not be submitted together.
Consists of ISO 639-1 language code and ISO 3166-1 alpha-2 country code separated by dash. If this value is not provided the browser culture is used. Default culture is English (e.g., en-de). This field is not case sensitive.
Possible values: <= 5 characters
en-ENDate of birth. Format - YYYY-MM-DD. Mandatory for payment option registration flow. Minimum date allowed is 1900-01-01
Possible values: <= 10 characters, Value must match regular expression ^\d{4}-\d{2}-\d{2}$
1989-11-08Customer email address for any notification
Possible values: <= 255 characters
john.doe@gmail.comPerson first name
Possible values: <= 60 characters
JohnPerson gender
Possible values: <= 6 characters
MrPerson's home phone number (including the country code)
Possible values: <= 30 characters
496912345678Person last name
Possible values: <= 60 characters
DoeConsumer/Customer Account Id in the merchant system. When provided into the Create Checkout API, SmartPay will request e-wallet account creation which will have external account reference equals to the given merchantCustomerId value.
Possible values: <= 255 characters
abcd123The customer's middle name
Possible values: <= 60 characters
RobertPerson's mobile phone number (including the country code)
Possible values: <= 30 characters
496912345678Person's tax identification number
Possible values: <= 30 characters
123456789Person title
Possible values: <= 3 characters
MrPerson's work phone number (including the country code)
Possible values: <= 30 characters
496912345678Transaction identifier provided by the merchant. Must be unique per transaction.
Possible values: <= 64 characters, Value must match regular expression ^[a-zA-Z0-9._:-]+$
If provided, the payment is processed in favour of the indicated submerchant account, and the main merchant account number is ignored.
Possible values: <= 127 characters
paymentOption objectrequired
The customer's selected payment option. This object is used to define the method and necessary data required to complete a transaction. It supports cards and other types (e.g., SEPA, PayPal) depending on context.
card objectrequired
Card-specific information used to process a card payment.
cardDetails objectrequired
Contains the tokenized cardholder information used for payment authorization. All values must be obtained and tokenized securely via the Web SDK or a PCI-compliance environemnt.
Full name of the cardholder.
Possible values: <= 50 characters
Tokenized representation of the card number.
Possible values: <= 64 characters
Tokenized CVV for the card.
Possible values: <= 4 characters
Two-digit month of card expiry.
Possible values: <= 2 characters, Value must match regular expression ^(0[1-9]|1[0-2])$
Four-digit year of card expiry.
Possible values: <= 4 characters, Value must match regular expression ^[0-9]{4}$
Card brand code.
Possible values: <= 16 characters, [AMEX, BNKACCT, CRTBANCAIR, DISCOVER, GIROPAY, IDEAL, JCB, MSTRCRD, MSTRO, PAYPAL, PAYU, PAYUBLK, PAYUTWST, PAYUINST, PREPMNT, SEPADDB2B, SEPADDCORE, VISA, VISADBIT]
3ds objectrequired
Wraps the authentication data to prove that Strong Customer Authentication (SCA) has been performed.
3ds2 object
Holds the 3-D Secure version 2.x authentication details.
Electronic Commerce Indicator provided by the ACS.
Possible values: <= 2 characters
02Token confirming successful 3DS challenge.
Possible values: <= 64 characters
Y: Success, N: Failure, U: Unavailable, A: Attempted, R: Rejected.
Possible values: <= 1 characters, [Y, N, U, A, R]
3DS protocol version used.
Possible values: <= 8 characters, [2.1.0, 2.2.0]
Transaction ID assigned by Directory Server.
Possible values: <= 36 characters
Transaction ID assigned by ACS.
Possible values: <= 36 characters
{
"payment": {
"description": "OEM APIs Test",
"amount": 49.99,
"currencyCode": "EUR"
},
"billingAddress": {
"addressLine1": "Max-Planck-Straße",
"number": "30",
"city": "Berlin",
"postCode": "14473",
"countryCode": "DE"
},
"consumer": {
"merchantCustomerId": "ID-",
"firstName": "John",
"lastName": "Doe",
"middleName": "Robert",
"emailAddress": "test@test.de",
"title": "Mr",
"culture": "en-EN",
"timezone": "CET",
"dateOfBirth": "1982-03-03",
"gender": "Mr",
"mobilePhone": "496912345678",
"homePhone": "496912345678",
"workPhone": "496912345678",
"taxId": "123456789"
},
"partnerReference": "9AS9EdK1ySZL5E1bbG",
"shippingAddress": {
"addressLine1": "Max-Planck-Straße",
"number": "30",
"city": "Berlin",
"postCode": "14473",
"countryCode": "DE"
},
"paymentOption": {
"card": {
"cardDetails": {
"cardHolder": "JOHN DOE",
"cardToken": "5123450000000008",
"cvvToken": "123",
"cardExpiryMonth": "09",
"cardExpiryYear": "2029",
"cardBrand": "MSTRCRD"
},
"3DS": {
"3DS2": {
"acsEci": "02",
"authenticationToken": "kHyn+7YFi1EUAREAAAAvNUe6Hv8=",
"transactionStatus": "Y",
"protocolVersion": "2.1.0",
"dsTransactionId": "68f92ff6-c417-40df-bfaf-6518c43f40fb",
"acsTransactionId": "0571d1c1-df05-4a6b-83c9-b6d1617a64f6"
}
}
}
}
}
Responses
- 201
- 400
- 401
- 403
- 404
- 500
Payment authorization successfully created
- application/json
- Schema
- Example (auto)
- Example
Schema
Unique reference ID sent by the merchant and echoed back.
Possible values: <= 64 characters
Description of the transaction.
Possible values: <= 127 characters
Current status of the payment.
Possible values: <= 16 characters, [CREATED, CAPTURED, AUTHORIZATION_PENDING, AUTHORIZATION_COMPLETED, FAILED, CAPTURE_PENDING, CANCELLATION_PENDING, EXPIRED, CANCELLED, SETTLED, CHARGEBACK]
Timestamp when the transaction was created.
Timestamp when the payment status was last updated.
transactionOverview object
SmartPay-assigned ID for the transaction.
Possible values: <= 36 characters
Method used to complete the payment.
Possible values: <= 16 characters, [CARDS, SEPA, PAYPAL]
Final authorized or captured amount.
ISO currency code.
Possible values: <= 3 characters, Value must match regular expression ^[A-Z]{3}$
Unique identifier from the payment provider used for settlement and reconciliation.
Possible values: <= 64 characters
ID of the latest modification (e.g., capture) applied to the transaction.
Possible values: <= 36 characters
{
"partnerReference": "string",
"description": "string",
"paymentStatus": "CREATED",
"creationDate": "2024-07-29T15:51:28.071Z",
"lastStatusDate": "2024-07-29T15:51:28.071Z",
"transactionOverview": {
"transactionId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"paymentMethod": "CARDS",
"amount": 0,
"currencyCode": "string"
},
"reconciliationReferenceId": "string",
"modificationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}
{
"partnerReference": "SOwS1Ir7UluDoJJF0p",
"description": "OEM APIs Test",
"paymentStatus": "CAPTURED",
"creationDate": "2024-03-28T10:02:43.272Z",
"lastStatusDate": "2024-03-28T10:02:47.507Z",
"transactionOverview": {
"transactionId": "a7dd1c65-847e-4b4f-8284-5ed7bed2c84b",
"paymentMethod": "CARDS",
"amount": 49.99,
"currencyCode": "EUR"
},
"reconciliationReferenceId": "SdsEh9hCGI434teXG3abz",
"modificationId": "a7dd1c65-847e-4b4f-8284-5ed7bed2c84b"
}
Bad Request
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "Value out of bounds. Value must be between 1 and 100",
"code": "value_out_of_bounds",
"property": "someField",
"context": {
"minimum": 1,
"maximum": 100
}
}
]
}
Unauthenticated
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "You are not authenticated to perform this request.",
"code": "unauthorized"
}
]
}
Forbidden
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "You do not have permissions to perform this request.",
"code": "forbidden"
}
]
}
Not Found
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "Resource not found.",
"code": "not_found"
}
]
}
Internal Server Error
For error handling, please refer to this section.
- application/json
- Schema
- Example (auto)
- Example
Schema
- string
- string[]
errorDetails object
message object
{
"error": "string",
"errorDetails": {
"context": {},
"gatewayDescription": "string",
"paymentProviderDescription": "string"
},
"message": "string"
}
{
"traceId": "00-1234567890abcdef0123456789abcdef-0123456789abcdef-00",
"errors": [
{
"message": "Internal server error."
}
]
}