---
title: "3DS result"
method: POST
path: "/v3/orders/{id}/results"
tags: ["3DS"]
---

# 3DS result

`POST /v3/orders/{id}/results`

Check the 3DS results using the managed order token returned in Forter's response to the order request.

## Path parameters

- `id` string, required

## Headers

- `api-version` string, required
- `x-forter-siteid` string, required
- `Authorization` string, required

## Request body

- V3OrderResultsRequest — Check the 3DS results using the managed order token returned in Forter's response to the order request.
  - `managedOrderToken` string, required — The managedOrderToken returned from the create endpoint

## Response `200`

Example v3OrderResultsResponse

- V3OrderResultsResponse
  - `decisionReason` string, required — The main reason behind the Forter decision
  - `forterDecision` 'APPROVE' | 'DECLINE' | 'NOT REVIEWED', required — The latest Forter decision regarding the attempted action
  - `linkToEventInDashboard` string, required — Link to the event in the decision dashboard
  - `merchantPolicyId` string, required — UID of the custom policy created in Forter's Policies tool that resulted in this decision
  - `orderId` string, required — Transaction/order ID. Note that Forter treats this ID as case-insensitive; Order123 and ORDER123 will be identified as the same order.
  - `paymentRecommendations` object, nullable — PaymentRecommendations contains all types of payment recommendations Forter sends as part of the Payment Routing Optimization solution
    - `action` 'no_processor_preference' | 'do_not_process' | 'process_payment', nullable — Action to take based on the recommendations
    - `processor_routing_reason` 'out_of_scope' | 'hard_fraud_decline' | 'model_recommendation' | 'exceeded_processing_attempts' | 'authorized_payment' | 'no_optional_processor', nullable — The reason for the processor routing decision
    - `processors` ProcessorRecommendation[], nullable — Processor routing recommendations
      - `priority` number, required — Recommendation with priority 1 should be tried first. Priority 2 should be tried if 1 fails.
      - `processorMid` string, required — Processor MID
      - `processorName` string, required — Processor Name
      - `recommend3DS` boolean, required — In case 3DS should be tried, this will be true
      - `recommendationId` string, required — Id of the recommendation - when merchants use our recommendation we expect them to report that by supplying this in the following request
  - `recommendation` string, required — A specific recommendation for an action that might help the customer to complete their transaction/action (e.g. verify phone via SMS, verify via push notification, verify email, perform a 3DS check, etc.)
  - `verificationMethod` VerificationMethod, required — A specific element that requires verification in order to approve a transaction, and its current status in the verification process
    - `correlationId` string, required — A forter unique identifier that was provided as part of a Forter API response recommending additional authentication measures. Used to correlate between the user action which triggered the recommendation and the authentication attempt result. Required when the additional authentication was triggered by Forter's recommendation.
    - `status` string, required — Verification status
    - `statusCode` string, required — Verification status code
    - `statusMessage` string, required — Text describes the verification status
    - `type` 'OTP_SMS' | 'OTP_EMAIL' | 'THREE_DS', required — Verification method type
    - `verificationId` string, required — A unique identifier assigned to that specific verification
    - `verificationSpecificData` VerificationData, required — Details of the specific element that requires verification
      - `ThreeDS` object, nullable — Complete 3DSecure payload
        - `ACSUrl` string, required — In case of challange, this url is needed to be passed to client side and trigger ftr__.init3DS function
        - `ECIValue` string, required — Electronic Commerce Indicator (ECI) is a value that is returned from the Directory Server (Visa, MasterCard, etc) to indicate the authentication results of your customer's credit card payment on 3D Secure. ECI only available when the challenge is not needed or after challenge had been completed. Possible values: 00, 01, 02, 04, 05, 06, 07
        - `acsChallengeMandated` string, required — Indication of whether a challenge is required for the transaction to be authorised due to local/regional mandates or other variable (Y - Challenge is mandated, N - Challenge is not mandated)
        - `acsReferenceNumber` string, required — Unique identifier assigned by the EMVCo Secretariat = required for mobile app implementation
        - `acsSignedContent` string, required — ACS Signed Content required for mobile app implementation
        - `acsTransID` string, required — Universally Unique transaction identifier assigned by the ACS to identify a single transaction - required for mobile app implementation
        - `authenticationType` string, required — Optional authentication type (01 - Static, 02 - Dynamic, 03 - OOB, 04 - Decoupled)
        - `authenticationValue` string, required — 3DS Authentication value (AV) should be sent to the payment gateway in the authorization call
        - `bankLiabilityShift` boolean, required — Indicates whether transaction is supposed to get liability shift from issuer
        - `cardEnrolled` string, required — 3DS transaction card Enrolled status - should be sent to the payment gateway in the authorization call in some payment gateways
        - `cavvAlgorithm` string, required — 3DS Authentication value algorithm - should be sent to the payment gateway in the authorization call in some payment gateways. Possible values (3DS1 only): 0, 1, 2, 3, 4, 7
        - `challengeCancel` string, required — Indicator informing the ACS and the DS that the authentication has been canceled. Possible values: 01-99
        - `challengeStatus` string, required — Ares transStatus value (Possible values: U, N, Y, A, C, D, R, I)
        - `dsTransID` string, required — Universally unique transaction identifier assigned by the DS to identify a single transaction
        - `encodedChallengeRequest` string, required — This value will only be available when challenge is needed, in the challenge flow - this must be passed to browser in order to trigger the challenge
        - `exemption` 'LOW_VALUE' | 'TRANSACTION_RISK_ANALYSIS' | 'SECURE_CORPORATE' | 'TRUSTED_BENEFICIARY', nullable — Exemption that should be used during the authorization process
        - `interactionCounter` string, required — Indicates the number of authentication cycles attempted by the Cardholder
        - `isFallback` boolean, required — Indication of whether a 3DS1 challenge was performed as a fallback to 3DS2 error
        - `messageCategory` string, required — Identifies the category of the message for a specific use case (01 - PA, 02 - NPA)
        - `outOfScopeForPSD2` 'ANONYMOUS_PREPAID_CARD' | 'MERCHANT_INITIATED_TRANSACTIONS' | 'ONE_LEG_OUT_EEA' | 'MAIL_ORDER_TELEPHONE_ORDER', nullable — This field indicate if transaction is out of scope for PSD2 and exclusion should be requested
        - `threeDSServerTransID` string, required — Universally unique transaction identifier assigned by the 3DS Server to identify a single transaction (in 3DS1 equal to XID)
        - `threeDSecureMode` string, required — Indicate if the transaction is Frictionless or SCA. Being used by some payment gateways. Possible values: sca, frictionless
        - `threeDSecurePreference` string, required — The challenge indicator used. Being used by some payment gateways. Possible values: nopref, frictionless, sca, scamandate
        - `threeDSecureResult` string, required — This field is relevant for 3DS1 and being used by some payment gateways
        - `transStatus` string, required — 3DS transStatus value - Indicates whether a transaction qualifies as an authenticated transaction or account verification. should be sent to the payment gateway in the authorization call (Possible values: U, N, Y, A, C, D, R, I)
        - `transStatusReason` string, required — Provides information on why the Transaction Status field has the specified value. Possible values: 01-99
        - `verifyStatus` string, required — Cres transStatus value (Possible values: U, N, Y, A, C, D, R, I, null)
        - `version` string, required — Version. Possible values: 1.0.2, 2.1.0, 2.2.0
      - `email` object, nullable — This refers to the email address associated with the customer or transaction, giving details about the address and any role it has played in the customer's being on or interacting with the site.
        - `email` string, required — Email address
        - `emailVerification` object, nullable — This object contains information about steps taken to verify the customer's identity such as email or phone verifcations.
          - `sent` boolean, nullable — True if verification email was sent to email address or verification SMS was sent to phone number
          - `timeSent` number, nullable — Date verification email or SMS was sent in seconds since unix epoch (UTC, Jan 1, 1970)
          - `verified` boolean, required — True if customer received email verification message to this address and clicked-through back to merchant's site, or received SMS message and enterd code in merchant's site (two-factor authentication)
      - `phone` object, nullable — This provides information about the telephone number associated with the customer or transaction.
        - `phone` string, required — Phone number including all country and local access codes
        - `smsVerified` object, nullable — This object contains information about steps taken to verify the customer's identity such as email or phone verifcations.
          - `sent` boolean, nullable — True if verification email was sent to email address or verification SMS was sent to phone number
          - `timeSent` number, nullable — Date verification email or SMS was sent in seconds since unix epoch (UTC, Jan 1, 1970)
          - `verified` boolean, required — True if customer received email verification message to this address and clicked-through back to merchant's site, or received SMS message and enterd code in merchant's site (two-factor authentication)

## Other responses

- `400` — Bad Request (Often missing a required parameter)
- `401` — Unauthorized (No valid API key provided)
- `404` — Not Found (The requested item doesn't exist)
- `429` — Too Many Requests (The client exceeded a rate limit). Honor Retry-After before retrying.
- `500` — Server Error (Something went wrong on Forter's end)
- `default` — Typed error envelope for any undeclared 4xx / 5xx status.

---

[API](https://skmtc.net/forter/apis/forter-api.md) · [All operations](https://skmtc.net/forter/apis/forter-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/forter/forter-api/revisions/d7b02e919b34/schema)
