Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Table of Contents


3DS Authentication and Liability Shift



Tip

The use of 3D Secure authentication helps protect merchants against the non-payment reason "cardholder dispute."

We refer to "liability shift" when the responsibility for non-payments due to fraud (stolen or counterfeit cards) is transferred from the merchant to the card-issuing bank (the bank of the end customer) used for the payment.

All Axepta merchantsare registered in the 3D-Secure program. This operation is performed by the Axepta Online platform when creating the MID.




Warning

Enrollment in the 3D Secure program does not protect against all non-payment and fraud reasons.

The protection related to 3D Secure authentication does not apply to :

  • MOTO payments or those manually entered in the back office by the merchant

  • Recurring payments or installments of a payment in installments (excluding the first transaction)

  • Payments made in batch

Matrice : Transfert de responsabilité lié au 3DSV1 et 3DSV2

Le tableau ci-dessous indique les cas où le marchand bénéfice du transfert de responsabilité :





Matrix: Liability Shift Related to 3DSV1 and 3DSV2


The table below indicates the cases where the merchant benefits from liability shift :



LIABILITY SHIFT TO THE ISSUING BANK
NetworkCard Type3DS Authentication Result
TRANSFERT DE RESPONSABILITE VERS LA BANQUE EMETTRICERéseau
Type de carte
Résultat de l'authentification 3DS

3D SUCCESS*


3D ATTEMPT3D NOT ENROLLED3D ERROR3D FAILURE
Avec CryptogrammeSans cryptogramme
With CryptogramWithout cryptogram
CB
Tous
All
OUI

YES

OUI
YES
OUI
YES
OUI
YES
NON
NO
NON
NO
VISA
Tous
All
OUI
YES
OUI
YES
NON
NO
NON
NO
NON
NO
NON
NO
MASTERCARD
Tous
All
OUI
YES
OUI
YES
NON
NO
NON
NO
NON
NO
NON
NO
TOUS
ALL
Pré-payés
Prepaid
NON
NO
NON
NO
NON
NO
NON
NO
NON
NO
NON

*Dans le cas d'une demande d'authentification forte sans demande de frictionless ou d'exemption. cf. Le tableau 'Transfert de responsabilité & Frictionless" ci dessous

NO

*In the case of a request for strong authentication without a request for frictionless or exemption. See the table "Liability Shift & Frictionless" below.



When consulting payments in the Axepta Back-Office, the following data allows identifying the result of the authentication :

Field in BOCard Type3DS Authentication Result

Lors de la consultation des paiements dans le Back-Office Axepta, les données suivantes permettent d'identifier le résultat de l'authentification :

Champ dans le BOType de carteRésultat de l'authentification 3DS

3D SUCCESS


3D ATTEMPT3D NOT ENROLLED3D ERROR3D FAILURE
With CryptogramWithout cryptogramAvec CryptogrammeSans cryptogramme
Transaction StatusToutes cartesAll cardsYAA-NU
ECIVisa ou CB (co-badgée branded Visa)

05

06-070707
Mastercard ou CB (co-badgée branded Mastercard)0201-000000





Matrice : Transfert de responsabilité

Matrix: Liability Shift & Frictionless


Lors d'une transaction soumise à authentification forte During a transaction subject to strong authentication (3DS), le marchand peut choisir une préférence pour le type d'authentification qu'il souhaite effectuer.

Pour cela, le marchand ajoute à sa requête de paiement l'objet JSON threeDSPolicy EN qui permettra de :

  • Forcer une authentification
  • Demander une authentification passive (frictionless)
  • Demander une

    the merchant can choose a preference for the type of authentication they wish to perform.

    To do this, the merchant adds the JSON object threeDSPolicy to their payment request, which will allow them to :

    • Force authentication

    • Request passive authentication (frictionless)

    • Request an exemption



    Info

    Important :

    Le choix final de l'authentification est effectué par la banque émettrice (la banque du porteur du carte - le client final).

    The final choice of authentication is made by the issuing bank (the bank of the cardholder - the end customer).




    In case of 3DS Success, the liability shift depends on the card brand used for the payment and any potential request from the merchant (frictionless, exemption, etc.) :


    LIABILITY SHIFT TO THE ISSUING BANK - BASED ON MERCHANT'S REQUEST

    Merchant's Request - Value for "challengePreference" 

    Challenge Indicator

    Authentication Method

    En cas de 3DS Success, le transfert de responsabilité dépend de la marque de la carte utilisée pour le paiement et d'une éventuelle demande du marchand (frictionless, exemption...) :

    TRANSFERT DE RESPONSABILITE VERS LA BANQUE EMETTRICE - EN FONCTION DE LA DEMANDE DU MARCHAND

    Demande du marchand -

    Valeur pour "challengePreference"

    Challenge Indicator

    Méthode d'authentification

    (DS/ACS)

    CB

    Mastercard

    (ECI = 05)

    Visa

    (ECI = 02)

    American Express
    No preference01Frictionless* / ChallengeBanque émettriceIssuing Bank

    No challenge

    02Frictionless*MarchandMerchantBanque émettriceIssuing Bank
    ChallengeBanque émettriceIssuing Bank
    Request challenge03Frictionless* / ChallengeBanque émettriceIssuing Bank
    Challenge Requested (mandate)04ChallengeBanque émettriceIssuing Bank
    Acquirer's TRA exemption requestDemande d'exemption TRA acquérer05Frictionless*MarchandMerchantN.A.
    ChallengeBanque émettriceIssuing BankN.A.

    Demande d'exemption Petit montantLow-Value Exemption Request

    02Frictionless*MarchandMerchantBanque émettriceIssuing BankN.A.
    ChallengeÉmetteurIssuerN.A.

    * Frictionless ou or Frictionless délégationDelegation