---
title: "Authentication result"
method: POST
path: "/v2/accounts/authentication-result/{id}"
tags: ["Accounts"]
---

# Authentication result

`POST /v2/accounts/authentication-result/{id}`

Inform of authentication results after an attempted login or profile access request, using the provided correlation ID. While no decision is provided on this request, it improves the decision model for login and access.

## Path parameters

- `id` string, required

## Headers

- `api-version` string, required
- `x-forter-siteid` string, required
- `Authorization` string, required

## Request body

- AccountAuthenticationRequest — Inform of authentication results after an attempted login or profile access request, using the provided correlation ID. While no decision is provided on this request, it improves the decision model for login and access.
  - `accountId` string, required — Customer's account UID in merchant's site. Should not be the user email.
  - `additionalAuthenticationMethod` object, nullable — Details and status of advanced authentication methods used for MFA and OTP. When this object is sent, at least one of the verifications should be provided
    - `correlationId` string, required — A forter unique identifier that was provided as part of a Forter API response recommending additional authentication measures. Used to correlate between the user action which triggered the recommendation and the authentication attempt result. Required when the additional authentication was triggered by Forter's recommendation.
    - `documentVerification` object, nullable — Additional Verification Documents includes any details gained from identifying documents or materials which the customer has shared.
      - `address` object, nullable — Address description
        - `address1` string, nullable — Street-level address. Required when full address details are available
        - `address2` string, nullable — Unit-level address
        - `city` string, nullable — City. Required when full address details are available
        - `company` string, nullable — Company
        - `country` string, required — Country, two-letter ISO 3166-1 alpha-2 country code
        - `region` string, nullable — Top-level administrative subdivision - state/province/department/etc. Can be either abbreviated format or full name (NY/New York)
        - `savedData` object, nullable — Saved Data refers to information which persists in the account settings, such as address or payment information.
          - `choseToSaveData` boolean, nullable — True if customer chose to save data in the account for future use
          - `usedSavedData` boolean, nullable — True if customer chose to use data saved in the account
        - `zip` string, nullable — Zipcode
      - `documentDateOfBirth` string, date, nullable — Date of birth as appears on the document. Use YYYY-MM-DD format.
      - `documentExpiration` string, date, nullable — Document's exipration date. Use YYYY-MM-DD format.
      - `documentFirstName` string, nullable — First name as appears on the document
      - `documentIssuingState` string, nullable — Document issuing state or region
      - `documentLastName` string, nullable — Last name as appears on the document
      - `documentNumber` string, nullable — Official document's number (e.g. passport number, driving license number, etc.)
      - `documentSource` 'CAMERA_CAPTURED' | 'UPLOADED_FILE' | 'TYPED' | 'OTHER', required — Source of document (e.g. uploaded file, captured by camera, typed in by customer, etc.)
      - `documentStatus` 'SENT_TO_CLIENT' | 'RECEIVED_FROM_CLIENT' | 'ABANDONED_BY_CLIENT' | 'RECEIVED_FROM_CLIENT_FAULTY', nullable — Status of verification document (e.g. sent to customer, received by customer, abandoned by customer ).
      - `documentType` string, required — Type of document (Passport, ID, Driving license)
      - `documentVerificationServiceAnswer` string, nullable — Answer received from 3rd party document verification services
      - `documentVerificationServiceName` string, nullable — Name of 3rd party document verifcation service
      - `documentVerificationServiceResponsePayload` object, nullable — General payload object
      - `documentVerified` boolean, nullable — True if document was verified as authentic by merchant or 3rd party service
      - `eventTime` number, nullable — Time of event in seconds since unix epoch (UTC, Jan 1, 1970). For example, 01/01/2015 00:00 is 1420070400
      - `nationality` string, nullable — Document holder's nationality
    - `emailVerification` object, nullable — This refers to the email address associated with the customer or transaction, giving details about the address and any role it has played in the customer's being on or interacting with the site.
      - `email` string, required — Email address
      - `emailVerification` object, nullable — This object contains information about steps taken to verify the customer's identity such as email or phone verifcations.
        - `sent` boolean, nullable — True if verification email was sent to email address or verification SMS was sent to phone number
        - `timeSent` number, nullable — Date verification email or SMS was sent in seconds since unix epoch (UTC, Jan 1, 1970)
        - `verified` boolean, required — True if customer received email verification message to this address and clicked-through back to merchant's site, or received SMS message and enterd code in merchant's site (two-factor authentication)
    - `oneTimePasswordVerification` object, nullable — This object contains information about steps taken to verify a customer's identity.
      - `timeVerified` number, nullable — Date user was verified in seconds since unix epoch(UTC, Jan 1, 1970)
      - `verificationMethod` string, required — Type of one time verification method
      - `verified` boolean, required — Was the user verified via the chosen verification method
    - `paymentInstrumentVerification` object, nullable — Details and status of advanced payment instrument authentication methods used for MFA and OTP. When this object is sent, at least one of the verifications should be provided
      - `cameraCaptured` boolean, nullable — The user successfully took a photo of their credit card using an OCR feature of the mobile app
      - `creditCardManuallyTypedIn` boolean, nullable — The user successfully typed in the full number of the credit card that was saved in the account
      - `cvvManuallyTypedIn` boolean, nullable — The user successfully typed in the CVV of the credit card that was saved in the account
      - `lastFourDigits` string, nullable — Last 4 digits of the credit card that was verified
      - `token` string, nullable — Token of the credit card that was verified
    - `phoneVerification` object, nullable — This provides information about the telephone number associated with the customer or transaction.
      - `phone` string, required — Phone number including all country and local access codes
      - `smsVerified` object, nullable — This object contains information about steps taken to verify the customer's identity such as email or phone verifcations.
        - `sent` boolean, nullable — True if verification email was sent to email address or verification SMS was sent to phone number
        - `timeSent` number, nullable — Date verification email or SMS was sent in seconds since unix epoch (UTC, Jan 1, 1970)
        - `verified` boolean, required — True if customer received email verification message to this address and clicked-through back to merchant's site, or received SMS message and enterd code in merchant's site (two-factor authentication)
    - `verificationOutcome` 'SUCCESS' | 'FAILURE' | 'NONE_ATTEMPTED', required — Outcome of verification attempt
  - `additionalInformation` object, nullable — General payload object
  - `bankTransferVerificationResults` object, nullable — This object contains information regarding bank transfer payment methods.
    - `accountHolderFirstName` string, nullable — Bank account holder first name
    - `accountHolderLastName` string, nullable — Bank account holder last name
    - `achProcessingType` string, nullable — Type of ACH processing used in the transaction
    - `bankAccountIdentifier` string, required — Bank account unique identifier (IBAN or equivalent)
    - `bankAccountType` string, nullable — Type of bank account payment is made from (e.g. savings/checking, etc.)
    - `bankName` string, nullable — Name of bank payment is made from
    - `paymentGatewayData` object, nullable — This provides information about the payment gateway
      - `gatewayName` string, nullable — Payment gateway name
      - `gatewayTransactionId` string, nullable — Unique transaction identifier (sent by gateway)
    - `paymentSuccessStatus` string, nullable — Response text as received from the service provider
    - `serviceName` string, nullable — Payment method name
  - `connectionInformation` object, nullable — This object contains connection info which is usually found in the HTTP request header.
    - `checkoutToolsSessionId` string, nullable — CheckoutToolsSessionId received from the SDK
    - `customerIP` string, required — Customer IP address in IPv4 or IPv6 format. If missing should be populated with 127.0.0.1
    - `forterMobileUID` string, nullable — mobile UID. The device identifier such as IMEI in android or identifier for vendor in iOS. This should match the deviceId sent via the mobile events API (for mobile transactions only)
    - `forterTokenCookie` string, nullable — Forter token cookie from request headers
    - `merchantDeviceIdentifier` string, nullable — A unique device identifier generated by merchant
    - `merchantProvidedSessionId` string, nullable — An identifier of the merchant session
    - `userAgent` string, required — Customer's User agent
  - `eventTime` number, required — The time that the trigger event occurred in MILLISECONDS since unix epoch (Jan 1, 1970)
  - `merchantIdentifiers` object, nullable — If a merchant operates a number of sites, Merchant Identifiers help Forter's system to identify the right transactions with the right sites.
    - `merchantDomain` string, nullable — Use if merchant operates several sites (such as a regular site and a related discount brand)
    - `merchantName` string, nullable — Use if merchant operates several sites (such as a regular site and a related discount brand)
  - `paymentAuthorizationResults` object, nullable — Credit card CVV and AVS results
    - `authorizationCode` string, nullable — Card authorization code from payment gateway. Required if both processorResponseText and processorResponseCode are not provided.
    - `authorizationProcessedWith3DS` boolean, nullable — 3DSecure - indicating that the 3DS results were sent to processor and have been used during the authorization
    - `avsFullResult` string, nullable — Procesor response code for AVS. Only required in cases where all AVS results (zipcode, street address, and name when available) arrive as one string
    - `avsNameResult` string, nullable — Name portion of card's AVS result (when available)
    - `avsStreetResult` string, nullable — Street address portion of card's AVS result
    - `avsZipResult` string, nullable — Zipcode portion of card's AVS result
    - `cavvResult` string, nullable — 3DSecure - Authentication Value (CAVV / AAV for 3DS1) recieved from authorization/Authentication response
    - `cvvResult` string, nullable — CVV result (if no data please send the value U)
    - `eciValue` string, nullable — 3DSecure - ECI value recieved from authorization/authentication response
    - `exemptionStatus` string, nullable — Exemption status as received from the processor
    - `external3dsVendorPayload` object, nullable — General payload object
    - `issuerResponseCode` string, nullable — Response code received from issuer
    - `issuerResponseText` string, nullable — Response text received from issuer
    - `liabilityShift` boolean, nullable — 3DSecure - liability shift - indicate whether the chargeback liability shifted to the card issuer
    - `partyExecuted3DS` 'PSP' | 'FORTER' | 'BOTH', nullable — 3DSecure - Party executed the 3DS authentication
    - `processorResponseCode` string, nullable — Response code received from processor. Required if both processorResponseText and authorizationCode are not provided.
    - `processorResponseText` string, nullable — Response text received from processor. Required if both processorResponseCode and authorizationCode are not provided.
    - `threeDsInteractionMode` 'FRICTIONLESS' | 'CHALLENGED', nullable — 3DSecure - Indication of the friction that the user experienced
    - `threeDsStatus` string, nullable — 3DSecure - Status text received from 3D secure vendor
    - `threeDsVersion` string, nullable — 3DSecure - Version used in the transaction
  - `paypalVerificationResults` object, nullable
    - `authorizationId` string, nullable — PayPal authorization ID
    - `fullPaypalResponsePayload` object, nullable — General payload object
    - `payerAccountCountry` string, nullable — PayPal account country, two-letter ISO 3166-1 alpha-2 country code
    - `payerAddressStatus` string, nullable — PayPal payer address status
    - `payerEmail` string, required — PayPal payer Email address
    - `payerId` string, required — PayPal payer ID
    - `payerStatus` string, nullable — PayPal payer status
    - `paymentGatewayData` object, nullable — This provides information about the payment gateway
      - `gatewayName` string, nullable — Payment gateway name
      - `gatewayTransactionId` string, nullable — Unique transaction identifier (sent by gateway)
    - `paymentId` string, nullable — PayPal payment ID
    - `paymentStatus` string, required — PayPal payment status
    - `protectionEligibility` string, nullable — PayPal protection eligibility

## Response `200`

Example adaptiveAuthAccountsResponse

- AdaptiveAuthAccountsResponse — Response structure for adaptive auth account requests
  - `accountId` string, required — When applicable, the customer's account UID in merchant's site
  - `correlationId` string, required — A forter unique identifier that should be sent to Forter as part of the AdvancedAuthenticationMethod object to correlate the MFA recommendation given in this response with the relevant additional authentication attempt result
  - `decisionReason` string, required — The main reason behind the Forter decision
  - `forterDecision` 'APPROVE' | 'DECLINE' | 'VERIFICATION_REQUIRED' | 'NOT_REVIEWED', required — The latest Forter decision regarding the attempted action
  - `merchantPolicyId` string, required — UID of the custom policy created in Forter's Policies tool that resulted in this decision
  - `recommendation` string, required — A specific recommendation for an action that might help the customer to complete their transaction/action (e.g. verify phone via SMS, verify via push notification, verify email, perform a 3DS check, etc.)
  - `verificationMethod` VerificationMethod, required — A specific element that requires verification in order to approve a transaction, and its current status in the verification process
    - `correlationId` string, required — A forter unique identifier that was provided as part of a Forter API response recommending additional authentication measures. Used to correlate between the user action which triggered the recommendation and the authentication attempt result. Required when the additional authentication was triggered by Forter's recommendation.
    - `status` string, required — Verification status
    - `statusCode` string, required — Verification status code
    - `statusMessage` string, required — Text describes the verification status
    - `type` 'OTP_SMS' | 'OTP_EMAIL' | 'THREE_DS', required — Verification method type
    - `verificationId` string, required — A unique identifier assigned to that specific verification
    - `verificationSpecificData` VerificationData, required — Details of the specific element that requires verification
      - `ThreeDS` object, nullable — Complete 3DSecure payload
        - `ACSUrl` string, required — In case of challange, this url is needed to be passed to client side and trigger ftr__.init3DS function
        - `ECIValue` string, required — Electronic Commerce Indicator (ECI) is a value that is returned from the Directory Server (Visa, MasterCard, etc) to indicate the authentication results of your customer's credit card payment on 3D Secure. ECI only available when the challenge is not needed or after challenge had been completed. Possible values: 00, 01, 02, 04, 05, 06, 07
        - `acsChallengeMandated` string, required — Indication of whether a challenge is required for the transaction to be authorised due to local/regional mandates or other variable (Y - Challenge is mandated, N - Challenge is not mandated)
        - `acsReferenceNumber` string, required — Unique identifier assigned by the EMVCo Secretariat = required for mobile app implementation
        - `acsSignedContent` string, required — ACS Signed Content required for mobile app implementation
        - `acsTransID` string, required — Universally Unique transaction identifier assigned by the ACS to identify a single transaction - required for mobile app implementation
        - `authenticationType` string, required — Optional authentication type (01 - Static, 02 - Dynamic, 03 - OOB, 04 - Decoupled)
        - `authenticationValue` string, required — 3DS Authentication value (AV) should be sent to the payment gateway in the authorization call
        - `bankLiabilityShift` boolean, required — Indicates whether transaction is supposed to get liability shift from issuer
        - `cardEnrolled` string, required — 3DS transaction card Enrolled status - should be sent to the payment gateway in the authorization call in some payment gateways
        - `cavvAlgorithm` string, required — 3DS Authentication value algorithm - should be sent to the payment gateway in the authorization call in some payment gateways. Possible values (3DS1 only): 0, 1, 2, 3, 4, 7
        - `challengeCancel` string, required — Indicator informing the ACS and the DS that the authentication has been canceled. Possible values: 01-99
        - `challengeStatus` string, required — Ares transStatus value (Possible values: U, N, Y, A, C, D, R, I)
        - `dsTransID` string, required — Universally unique transaction identifier assigned by the DS to identify a single transaction
        - `encodedChallengeRequest` string, required — This value will only be available when challenge is needed, in the challenge flow - this must be passed to browser in order to trigger the challenge
        - `exemption` 'LOW_VALUE' | 'TRANSACTION_RISK_ANALYSIS' | 'SECURE_CORPORATE' | 'TRUSTED_BENEFICIARY', nullable — Exemption that should be used during the authorization process
        - `interactionCounter` string, required — Indicates the number of authentication cycles attempted by the Cardholder
        - `isFallback` boolean, required — Indication of whether a 3DS1 challenge was performed as a fallback to 3DS2 error
        - `messageCategory` string, required — Identifies the category of the message for a specific use case (01 - PA, 02 - NPA)
        - `outOfScopeForPSD2` 'ANONYMOUS_PREPAID_CARD' | 'MERCHANT_INITIATED_TRANSACTIONS' | 'ONE_LEG_OUT_EEA' | 'MAIL_ORDER_TELEPHONE_ORDER', nullable — This field indicate if transaction is out of scope for PSD2 and exclusion should be requested
        - `threeDSServerTransID` string, required — Universally unique transaction identifier assigned by the 3DS Server to identify a single transaction (in 3DS1 equal to XID)
        - `threeDSecureMode` string, required — Indicate if the transaction is Frictionless or SCA. Being used by some payment gateways. Possible values: sca, frictionless
        - `threeDSecurePreference` string, required — The challenge indicator used. Being used by some payment gateways. Possible values: nopref, frictionless, sca, scamandate
        - `threeDSecureResult` string, required — This field is relevant for 3DS1 and being used by some payment gateways
        - `transStatus` string, required — 3DS transStatus value - Indicates whether a transaction qualifies as an authenticated transaction or account verification. should be sent to the payment gateway in the authorization call (Possible values: U, N, Y, A, C, D, R, I)
        - `transStatusReason` string, required — Provides information on why the Transaction Status field has the specified value. Possible values: 01-99
        - `verifyStatus` string, required — Cres transStatus value (Possible values: U, N, Y, A, C, D, R, I, null)
        - `version` string, required — Version. Possible values: 1.0.2, 2.1.0, 2.2.0
      - `email` object, nullable — This refers to the email address associated with the customer or transaction, giving details about the address and any role it has played in the customer's being on or interacting with the site.
        - `email` string, required — Email address
        - `emailVerification` object, nullable — This object contains information about steps taken to verify the customer's identity such as email or phone verifcations.
          - `sent` boolean, nullable — True if verification email was sent to email address or verification SMS was sent to phone number
          - `timeSent` number, nullable — Date verification email or SMS was sent in seconds since unix epoch (UTC, Jan 1, 1970)
          - `verified` boolean, required — True if customer received email verification message to this address and clicked-through back to merchant's site, or received SMS message and enterd code in merchant's site (two-factor authentication)
      - `phone` object, nullable — This provides information about the telephone number associated with the customer or transaction.
        - `phone` string, required — Phone number including all country and local access codes
        - `smsVerified` object, nullable — This object contains information about steps taken to verify the customer's identity such as email or phone verifcations.
          - `sent` boolean, nullable — True if verification email was sent to email address or verification SMS was sent to phone number
          - `timeSent` number, nullable — Date verification email or SMS was sent in seconds since unix epoch (UTC, Jan 1, 1970)
          - `verified` boolean, required — True if customer received email verification message to this address and clicked-through back to merchant's site, or received SMS message and enterd code in merchant's site (two-factor authentication)

## Other responses

- `400` — Bad Request (Often missing a required parameter)
- `401` — Unauthorized (No valid API key provided)
- `404` — Not Found (The requested item doesn't exist)
- `429` — Too Many Requests (The client exceeded a rate limit). Honor Retry-After before retrying.
- `500` — Server Error (Something went wrong on Forter's end)
- `default` — Typed error envelope for any undeclared 4xx / 5xx status.

---

[API](https://skmtc.net/forter/apis/forter-api.md) · [All operations](https://skmtc.net/forter/apis/forter-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/forter/forter-api/revisions/d7b02e919b34/schema)
