Skip to main content

3D Secure

3D Secure (3DS) is an authentication protocol that adds a layer of security to online card transactions by letting the card's issuer verify the cardholder — typically through an OTP or their banking app. A successful authentication also shifts fraud liability from the merchant to the issuer.

Moyasar gives you several ways to run 3DS, depending on how much control you need.

warning

Standalone 3D Secure is enabled only for selected merchants.

Most integrations should not use it. Use 3DS in a Payment — Moyasar runs 3DS for you and no card_auth calls are needed. Use standalone 3DS only if you need to bring 3DS values from another provider, or you want to separate the 3DS steps from the payment.

The ways to do 3DS​

ApproachHowWhen to use it
Inside a payment (default)Create a payment; Moyasar runs 3DS for you.The common case — let Moyasar handle authentication and authorization together.
Standalone authenticationPOST /v1/card_authsOnly if you want to run the 3DS steps separately from the payment — authenticate a card without (or before) charging it.
Reuse an authenticationsource.card_auth_id on a paymentCharge a card you already authenticated with a Moyasar standalone card_auth.
Bring your own valuessource.card_auth_data on a paymentOnly if you ran 3DS with another provider and want to pass the resulting values into a payment.
note

The standalone and bring-your-own flows are opt-in: a payment uses them only when you include source.card_auth_id or source.card_auth_data. A normal card payment that omits both still runs 3DS automatically — see 3DS in a Payment.

Reference​

Amounts throughout are in the currency's smallest unit (e.g. 10000 is 100.00 SAR).