3DS Recommendation
The 3DS Recommendation integration offers access to Forter's Fraud Management and Payment Optimization if you are already integrated with a 3DS provider.
Integration Flow
flowchart TD
B["Send order data to Forter via Order API"] --> C{"Fraudulent transaction?"}
C -- Yes --> D["Forter declines"]
D --> E["Send decline message to buyer"]
C -- No --> F{"Authorization path"}
F -- Standard Authorization --> G["Forter approves"]
G --> H["Request authorization from PSP"]
H --> Z["Share order and authorization status with Forter"]
F -- PSD2 Exemption --> I["Forter approves + recommends exemption"]
I --> J["Request authorization with exemption from PSP"]
J --> Z
F -- 3DS Recommended --> K["Forter approves-or-declines + recommends 3DS"]
K --> L["Request authorization with 3DS from PSP"]
L --> ZIntegration Steps
Confirm 3DS Prerequisites
Verify that both Forter's and your PSP's integration requirements are met.
PSP supports 3DS requests
- Verify with your PSP that you can request to trigger 3DS in the Authorization call. Contact your PSP to enable such a request as it is not always activated by default.
- Get the relevant reference details from your PSP for calling the Authorization API with the 3DS request.
PSD2 Regulation Solution
When Forter recommends a PSD2 exemption, it will return a recommendation value such as REQUEST_SCA_EXEMPTION_LOW_VALUE, REQUEST_SCA_EXEMPTION_TRA, or REQUEST_SCA_EXEMPTION_CORP. Verify the following with your PSP before go-live:
- Exemption support in the authorization request Confirm that your PSP can accept and act on an exemption flag in the authorization call. This is not always enabled by default — contact your PSP to activate it and obtain the relevant API reference.
- Exemptions over the 3DS rails: Certain markets, such as France, require that SCA-exempt transactions be routed over the 3DS rails (i.e., the exemption is embedded within the 3DS message) rather than sent directly in the authorization request (DTA path).
- In case your processor supports it - Forter will pass REQUEST_SCA_EXEMPTION_LOW_VALUE_EMVCO ; REQUEST_SCA_EXEMPTION_TRA_EMVCO ; REQUEST_SCA_EXEMPTION_CORP_EMVCO as the recommendation value, indicating that this transaction needs to ask for an exemption over the 3DS rails.
- In case your processor does not support it - Forter will return the standard exemption recommendation value — the responsibility for routing French BIN traffic over the 3DS rails must be configured on your PSP side. Confirm with your PSP that it supports a rule to route exemption requests over the 3DS rails for French BINs, while defaulting all other traffic to the standard DTA path.
- ECI value in the authorization response Confirm that your PSP returns the ECI (Electronic Commerce Indicator) value as part of the authorization or authentication response, and that your system captures and forwards it to Forter via the post-authorization / status call update. The ECI value allows Forter to accurately assess liability shift, inform future decisioning, and determine whether the exemption was processed over the 3DS rails or via the standard DTA path.
Note for Merchants Using Forter 3DS Execution (Managed 3DS) If Forter is acting as your 3DS executor for PSD2 traffic, the exemption flow is managed as follows:
- French BIN traffic (3DS rails): Forter manages this flow end-to-end internally. No additional action is required on your side. This is a regulatory routing requirement only — no real 3DS authentication takes place and no challenge will be presented to the cardholder unless the exemption is declined by the bank (soft decline), which will trigger a 3DS authentication flow.
- All other traffic (DTA exemption): Forter will return the exemption recommendation in the order response as usual. Pass the exemption flag to your PSP in the authorization request as described above.
Japan Regulation Solution
Notify Forter which scenarios you are subject to under Japan's 3DS regulation:
- 3DS upon the merchant judgment, for high risk transactions and when preferred by issuers.
- 3DS when registering a card number to an account (either at checkout or via the account page) AND for high risk transactions. 3DS on transactions with a saved card is not required as long as fraud check at checkout is in place.
- 3DS on every transaction
BIN & Last 4
Verify that you can pass the card's BIN number & last four digits in Forter's Order API request. To cover both 6-digit and 8-digit BIN scenarios, we ask you to provide 8 digits in the BIN field.
Follow the instructions for front-end integration for Fraud Management, including installing Mobile SDKs on your mobile applications.
Send Order API Request
As with the Checkout Integration for Fraud Management, send Forter the complete order details in the Order API to get real-time fraud decisions along with payment optimization recommendation for the authorization call. The request should be sent before calling the payment gateway to authorize funds (pre-auth flow). The full request and response data can be found in our Order API reference documentation.
For Japan Solution Only
When saving a card, separately or during checkout, include in the Order Request:
- At the event of saving the card (either separately or during checkout):
- payment[0].savedData.choseToSaveData: true
- payment[0].savedData.usedSavedData: false
- payment[0].creditCard.threeDSecure.acquirerData.acquirerName
- payment[0].creditCard.threeDSecure.acquirerData.acquirerCountry
- At the event of transaction with the saved card:
- payment[0].savedData.choseToSaveData: false
- payment[0].savedData.usedSavedData: true
- payment[0].tokenizedCard.threeDSecure.acquirerData.acquirerName
- payment[0].tokenizedCard.threeDSecure.acquirerData.acquirerCountry
Handle Order API Response
The response will include Forter's fraud decision, along with a recommendation regarding whether to execute 3DS during the authorization call. In situations where a PSD2 solution or Japan solution is applicable, the response may include a recommendation to request an exemption from 3DS during the authorization call.
Outcome | Call to Action | Order Response Fields |
|---|---|---|
Forter Approved Transaction is approved by Forter, 3DS was not recommended | Standard Authorization | "forterDecision": "APPROVE", "verificationMethod": {} To simulate this response, use [email protected] in the accountOwner object in the Order API request. |
Forter Declined Transaction is declined by Forter, 3DS was not recommended | Do not Authorize | "forterDecision": "DECLINE", "verificationMethod": {} To simulate this response, use [email protected] in the accountOwner object in the Order API request. |
Forter Declined & Recommends 3DS Borderline transaction which was declined by Forter, and 3DS is recommended in order to approve it | Capture only following a successful 3DS | "forterDecision": "DECLINE", "recommendation": "VERIFICATION_REQUIRED_3DS_CHALLENGE" To simulate this response, use the email address [email protected] in the accountOwner object in the Order API request. |
Forter Did Not Review Transaction was not reviewed for a fraud decision. | Act according to policy prior to Forter integration | "forterDecision": "NOT_REVIEWED", "recommendation": "", "verificationMethod": {} To simulate this response, use [email protected] in the accountOwner object in the Order API request. |
Additional Outcomes Applicable Only to Frictionless 3DS Solution
Outcome | Call to Action | Order Response Fields |
|---|---|---|
Forter Approved & Recommends Frictionless 3DS | Authorize with 3DS | "forterDecision": "APPROVE" "recommendation": "VERIFICATION_REQUIRED_3DS_CHALLENGE" |
Additional Outcomes Applicable Only to PSD2 Solution
Outcome | Call to Action | Order Response Fields |
|---|---|---|
Forter Approved & Recommends requesting an exemption from PSD2 Transaction is approved by Forter and Forter recommends asking for an exemption from 3DS when requesting payment authorization | Authorize with exemption request Please note that not all processors support all types of exemptions. Forter will recommend specific exemptions only if they are supported by the processor specified in the Order request. Note: For French BIN traffic, your PSP must be configured to route this exemption over the 3DS rails. See PSP Exemption Routing Capabilities in Step 1. | "forterDecision": "APPROVE", "recommendation": "REQUEST_SCA_EXEMPTION_TRA" To simulate, use card number 5222220000000006 and mailto:[email protected] in the Order API request "forterDecision": "APPROVE", "recommendation": "REQUEST_SCA_EXEMPTION_LOW_VALUE" To simulate, use card number 5222220000000006 and mailto:[email protected] in the Order API request "forterDecision": "APPROVE", "recommendation": "REQUEST_SCA_EXEMPTION_CORP" To simulate, use card number 5222220000000006 and mailto:[email protected] in the Order API request. |
Forter Approved & Recommends 3DS to comply with PSD2 PSD2 transaction is approved by Forter, and 3DS is recommended in order to comply with PSD2. | Authorize with 3DS request | "forterDecision": "APPROVE", "recommendation": "VERIFICATION_REQUIRED_3DS_CHALLENGE" To simulate, use mailto:[email protected] in the accountOwner object with in the Order API request. |
Forter Approved & Transaction is excluded from PSD2 Transaction is approved by Forter and the transaction is excluded from PSD2 requirements, even if it involves an EU merchant and an EU consumer. The exclusion recommendation serves as an informative indicator explaining the reason why the transaction is not considered for PSD2. | Standard Authorization The exclusion message is informative only, and you do not need to include any specific value in the payment authorization request. | "forterDecision": "APPROVE", "recommendation": "REQUEST_SCA_EXCLUSION_ANONYMOUS" To simulate, use card number 5222220000000006 and mailto:[email protected] in the Order API request. "forterDecision": "APPROVE", "recommendation": "REQUEST_SCA_EXCLUSION_MOTO" To simulate, use card number 5222220000000006 and mailto:[email protected] in the Order API Request. "forterDecision": "APPROVE", "recommendation": "REQUEST_SCA_EXCLUSION_ONE_LEG_OUT" To simulate, use card number 5222220000000006 and mailto:[email protected] in the Order API request. |
Additional Outcomes Applicable Only to Japan Solution
Outcome | Call to Action | Order Response Fields |
|---|---|---|
Forter Approved & Recommends avoiding 3DS with exemption | Standard Authorization without 3DS | "forterDecision": "APPROVE", "recommendation": "REQUEST_SCA_EXEMPTION" A response with an exemption is optional. You may choose not to receive any recommendation in such cases, as unlike PSD2, Japan’s regulation does not require adding any exemption flag to the authorization request. To simulate, use mailto:[email protected] in the Order API request. |
Forter Approved & 3DS is recommended | Authorize with 3DS request | "forterDecision": "APPROVE", "recommendation": "VERIFICATION_REQUIRED_3DS_CHALLENGE" To simulate, use mailto:[email protected] in the Order API request. |
Forter Approved & Transaction is excluded from Japan 3DS regulation | Standard Authorization without 3DS | "forterDecision": "APPROVE", "recommendation": "" No recommendation will be returned, only a fraud decision. |
Request authorization with 3DS
Pass the bank a request to trigger 3DS following Forter's recommendation in the Order Response. You should adjust your integration with the PSP and include 3DS request flag in the PSP Authorization request.
As an example, Adyen documentation describes how to flag the request in the payment request.
For PSD2 exemption recommendations, follow the same instructions as in 3DS Execution PSP Authorization
As you receive payment authentication updates, including 3DS results, and the order fulfillment status changes, it's important to keep Forter notified so that this information can be used in future decisions.
We strongly recommend using a webhook to send notifications about payment authorization and disputes if your PSP is supported.
Notifying Forter of disputes (also called claims, chargebacks, or fraud alerts) is extremely important because it enables Forter's system to learn and continually improve future decisions, tailoring our system to your company's needs. You can send these updates to Forter via a webhook from your PSP or via Forter's Dispute API endpoint.
Complete Integration Tests
The purpose of Forter's integration tests is to make sure that your integration covers all relevant use cases, while still in the sandbox or test environment. Each use case may need a different combination of attributes and values.
To make sure you have covered each of the use cases we expect in your integration, please go through the test scenario list in the Integration Tests section of Portal. For each, you'll need to create the scenario in your sandbox site that will generate a call to Forter's API. Then, select the corresponding API request that Forter received and click Run to verify that the sample request meets the criteria.
Deploy to Production
Once the Integration tests have passed, and you've reviewed any gaps with a Forter Implementation Engineer please, deploy your code to your production environment, with two critical adjustments:
- Replace your Site ID and secret key with your production credentials.
- Update your Javascript snippet and Mobile SDKs to use your production Site ID and the production hash keys, if relevant.
Please note that this does not yet complete your integration. Until Forter has switched your site to Live (after Data Validation), all Forter decisions will return "Not Reviewed".
Once in production, Forter uses a Data Validation tool to execute a set of automated tests across your live data in aggregation. The test outputs are daily reports that validate the accuracy and completeness of the production data we receive from you. You can monitor this output in Forter Portal under Integration Center Tools. We recommend checking the report daily to identify any failed tests.
Go Live
As Forter begins to send decisions and recommendations, confirm that your production site is handling responses as expected.
Verify 3DS recommendations with PSP
Confirm that your PSP is correctly receiving authorization requests with 3DS recommendations on live transactions.