Checkout Integration
Send Order API Request
The Order API is used to provide Forter with all relevant data points collected at checkout that will help Forter determine whether the entity conducting the transaction/engagement is legitimate or fraudulent.
For pre-authorization, the Order API should be called prior to the call made to your payment gateway to authorize customer funds. For post-authorization, the Order API should be called after an authorization response is received from your payment gateway, and must include the authorization response.
The full request and response data can be found in our Order API reference documentation, with the most critical data for the decision model outlined on the Important DataImportant Data page.
Handle Order API Response
The API response will contain Forter's decision and, if you are leveraging other Forter services, applicable recommendations such as abuse policy enforcements or 3DS recommendations.
For Fraud Management, the Forter decision is the important object and will be one of the following: Approve, Decline or Not Reviewed.
"Approve" Decision
Forter may return an "Approve" decision which means that Forter's evaluation is that the transaction can be approved and it is not fraudulent, so you can capture the transaction funds, send the customer confirmation and produce an invoice.
Depending on which version of the Order API you are using, you will receive the decision either in the action or forterDecision parameter.
v2 Response format
{
"action": "approve",
"message": "",
"reasonCode": "",
"status": "success",
"transaction": "123456"
}v3 Response format
{"forterDecision": "APPROVE", "recommendation": "","verificationMethod": {}}In order to test your handling of an "Approve" response, use the the email address [email protected] in the accountOwner object within the API request.
For pre-auth integrations, once you've moved forward with the payment request, you must also follow up with Forter to provide the payment authorization response from your payment gateway, either via a webhook or the Order Status API as described in the next step. This is important so that new information such as the AVS/CVV check and 3DS data are available for future decisions.
"Decline" Decision
As part of the Order API response, Forter may return an "Decline" decision which means that Forter's evaluation is that the transaction should be declined as there are indications it is fraudulent. Please cancel the transaction and communicate with the customer.
Depending on which version of the Order API you are using, you will receive the decision either in the action or forterDecision parameter.
v2 Response format
{
"action": "decline",
"message": "",
"reasonCode": "",
"status": "success",
"transaction": "123456"
}v3 Response format
{ "forterDecision": "DECLINE", "recommendation": "", "verificationMethod": {}}In order to test your handling of an "Decline" response, use the the email address [email protected] in the accountOwner object within the API request.
"Not Reviewed" Decision
Forter may return a "Not Reviewed" decision, for one of the following reasons:
- Listen Mode – during the ramp up period, while Forter is ensuring data accuracy.
- Integration add-ons - when new payment method that was not included in the initial integration is added.For example: if we start receiving PayPal orders after the integration of credit card orders has been completed but Paypal order data accuracy requires validation.
- Missing data – no BIN code / email / phone details.
- Merchant IP – cases when we receive your IP address instead of the customer IP address (e.g. phone orders / orders submitted through the merchant admin console).
- Cases when a decision is not needed for the payment method or no payment data is available for the payment method
If the decision was "Not Reviewed", Forter does not review the transaction, according to policy. Please act according to the policies in place prior to the integration with Forter.
Depending on which version of the Order API you are using, you will receive the decision either in the action or forterDecision parameter.
v2 Response format
{
"action": "not reviewed",
"message": "",
"reasonCode": "",
"status": "success",
"transaction": "123456"
}v3 Response format
{ "forterDecision": "NOT REVIEWED", "recommendation": "", "verificationMethod": {}}In order to test your handling of an "Not Reviewed" response, use the the email address [email protected] in the accountOwner object within the API request.