3DS Execution
The 3DS Execution integration grants full access to Forter's Fraud Management and Payment Optimization in a streamlined approach that reduces your development effort. It transparently manages the entire 3DS challenge flow, minimizing the communication needed between frontend and backend for a more efficient integration process.
Integration Flow
flowchart TD
B["Send order data to Forter via Order API"] --> C{"Fraudulent transaction?"}
C -- Yes --> D["Forter declines"]
D --> E["Send decline message to buyer"]
C -- No --> F{"Authorization path"}
F -- Standard Authorization --> G["Forter approves"]
G --> H["Request authorization from PSP"]
H --> Z["Share order and authorization status with Forter"]
F -- PSD2 exemption over Authorization --> I["Forter approves + recommends exemption"]
I --> J["Request authorization with exemption from PSP"]
J --> Z
F -- PSD2 exemption over 3DS --> Q["Fetch 3DS exemption results from Order API response"]
Q --> R["Request authorization with 3DS results (ECI, CAVV) from PSP"]
R --> Z
F -- 3DS Recommended --> K["Forter returns managedOrderToken"]
K --> L["Call Forter JS with managedOrderToken"]
L --> M["Forter JS executes 3DS flow and triggers your JS on completion"]
M --> N["Trigger your backend to fetch results from Forter"]
N --> O["Fetch results via Results API"]
O --> P["Request authorization with 3DS results (ECI, CAVV) from PSP"]
P --> ZIntegration Steps
Confirm 3DS Prerequisites
Verify that both Forter's and your PSP's integration requirements are met.
PSD2 Regulation Solution
- Exemption support in the authorization request Confirm that your PSP can accept and act on an exemption flag in the authorization call. This is not always enabled by default — contact your PSP to activate it and obtain the relevant API reference. Forter will return the exemption recommendation in the order response (REQUEST_SCA_EXEMPTION_LOW_VALUE, REQUEST_SCA_EXEMPTION_TRA, or REQUEST_SCA_EXEMPTION_CORP). Pass the exemption flag to your PSP in the authorization request as described above.
- Exemptions over the 3DS rails: Certain markets, such as France, require that SCA-exempt transactions be routed over the 3DS rails (i.e., the exemption is embedded within the 3DS message) rather than sent directly in the authorization request (DTA path). Forter manages this flow end-to-end internally. No additional action is required on your side. This is a regulatory routing requirement only — no real 3DS authentication takes place and no challenge will be presented to the cardholder unless the exemption is declined by the bank (soft decline), which will trigger a 3DS authentication flow.
- ECI value in the authorization response Confirm that your PSP returns the ECI (Electronic Commerce Indicator) value as part of the authorization or authentication response, and that your system captures and forwards it to Forter via the post-authorization / status call update. The ECI value allows Forter to accurately assess liability shift, inform future decisioning, and determine whether the exemption was processed over the 3DS rails or via the standard DTA path.
Japan Regulation Solution
Notify Forter which scenarios you are subject to under Japan's 3DS regulation:
- 3DS upon the merchant judgment, for high risk transactions and when preferred by issuers.
- 3DS when registering a card number to an account (either at checkout or via the account page) AND for high risk transactions. 3DS on transactions with a saved card is not required as long as fraud check at checkout is in place.
- 3DS on every transaction
BIN & Last 4
Verify that you can pass the card's BIN number & last four digits in Forter's Order API request. To cover both 6-digit and 8-digit BIN scenarios, we ask you to provide 8 digits in the BIN field.
In addition to the Forter's Javascript snippet and Mobile SDKs that share user behavior information, you'll need to icorporate Forter's 3DS client components into the front-end of your website and mobile applications. These are used in the 3DS Initialization and 3DS Challenge phases for easier integration
Send Forter the complete order details in the Order API to get real time fraud decision, or alternatively an indication to process the response in your checkout page using Forter JS SDK in order to execute 3DS for the transaction.
For the Forter PSD2 solution, a recommendation to request an exemption may be provided in addition to the fraud decision.
Request 3DS Results
After processing the Order response in your checkout page using Forter JS SDK, call Forter to get the fraud decision and 3DS results. Note this phase is required only in case 3DS is executed for the transaction.
In cases where Forter approved the transaction, call your PSP Authorization API with the 3DS results (or PSD2 exemption request) provided by Forter.
As you receive payment authentication updates and the order fulfillment status changes, it's important to keep Forter notified, so that this information can be used in future decisions.
We strongly recommend using a webhook to send notifications about payment authorization and disputes if your PSP is supported.
Notifying Forter of disputes (also called claims, chargebacks, or fraud alerts) is extremely important because it enables Forter's system to learn and continually improve future decisions, tailoring our system to your company's needs. You can send these updates to Forter via a webhook from your PSP or via Forter's Dispute API endpoint.
Complete Integration Tests
The purpose of Forter's integration tests is to make sure that your integration covers all relevant use cases, while still in the sandbox or test environment. Each use case may need a different combination of attributes and values.
To make sure you have covered each of the use cases we expect in your integration, please go through the test scenario list in the Integration Tests section of Portal. For each, you'll need to create the scenario in your sandbox site that will generate a call to Forter's API. Then, select the corresponding API request that Forter received and click Run to verify that the sample request meets the criteria.
Deploy to Production
Once the Integration tests have passed, and you've reviewed any gaps with a Forter Implementation Engineer please, deploy your code to your production environment, with two critical adjustments:
- Replace your Site ID and secret key with your production credentials.
- Update both Javascript snippets and both Mobile SDKs to use your production Site ID and the production hash keys, if relevant.
Please note that this does not yet complete your integration. Until Forter has switched your site to Live (after Data Validation), all Forter decisions will return "Not Reviewed".
Once in production, Forter uses a Data Validation tool to execute a set of automated tests across your live data in aggregation. The test outputs are daily reports that validate the accuracy and completeness of the production data we receive from you. You can monitor this output in Forter Portal under Integration Center Tools. We recommend checking the report daily to identify any failed tests.
Go Live
As Forter begins to send decisions and executing 3DS on live transactions, confirm that your production site is handling responses as expected.
If you are rolling out gradually, work with your Implementation Engineer to coordinate ramp-up.
Verify 3DS results received by PSP
Confirm that your PSP is correctly receiving authorization requests with 3DS results on live transactions.