v2
latestOpenAPI 3.1.02026-07-262279731.3 MBCreate a Card Validation
Create a Card Validation
Path parameters
Platform's API account identifier, associated with the API key.
The unique identifier of the Card object, obtained during the card registration process.
Headers
Bearer authentication of the form Bearer <token>, where token is your auth token.
If your platform is using a proxy to take SCA-triggering action on behalf of users, you also need to integrate mTLS authentication and use the api-mtls base URL.
Request body
The unique identifier of the user at the source of the transaction.
Max. length: 255 characters
The URL to which users are automatically returned after 3DS2 if it is triggered (i.e., if the SecureModeNeeded parameter is set to true).
The IP address of the end user initiating the transaction, in IPV4 or IPV6 format.
Max. length: 255 characters
Custom data that you can add to this object.
Allowed values: VISA, MASTERCARD, CB, MAESTRO
The card network to use, as chosen by the cardholder, in case of <a href="/guides/payment-methods/card/co-branded">co-branded cards</a>.
Default value: ECommerce
Allowed values: ECommerce, TelephoneOrder
The channel through which the user provided their card details, used to indicate mail-order and telephone-order (MOTO) payments:
- ECommerce – Payment received online.
- TelephoneOrder – Payment received via mail order or telephone order (MOTO).
Allowed values: DEFAULT, FORCE, NO_CHOICE
Default value: DEFAULT
The mode applied for the <a href="/guides/payment-methods/card/3ds">3DS2 protocol</a> for CB, Visa, and Mastercard. The options are:
- DEFAULT – Requests an exemption to strong customer authentication (SCA), and thus a frictionless payment experience, if allowed by your Mangopay contract and accepted by the issuer.
- FORCE – Requests SCA.
- NO_CHOICE – Leaves the choice to the issuer whether to allow for a frictionless payment experience or to enforce SCA.
Note: Sending the FORCE value automatically sets the ValidationUsage value to MIT.
Default value: MIT
Allowed values: MIT, CIT
Indicates the intended usage of the card:
- CIT – For customer-initiated transactions (CITs), meaning 3DS is less likely to be required on the card validation.
- MIT – For merchant-initiated transactions (MITs), meaning 3DS is more likely to be required on the card validation.
Note: The MIT value is returned automatically if the SecureMode value is FORCE, even if CIT is sent.
The unique reference generated for the profiling session, used by the <a href="/guides/fraud-prevention">fraud prevention</a> solution to produce recommendations for the transaction using the profiling data.
Note: Parameter not returned by the API. Profiling feature available on request – contact Mangopay <a href="https://hub.mangopay.com/" target="_blank">via the Dashboard</a> for more information.
Response
Success
Max length: 128 characters (see data formats for details)
The unique identifier of the object.
The unique identifier of the user at the source of the transaction.
Returned values: CREATED, SUCCEEDED, FAILED
The status of the transaction.
Max. length: 255 characters
The URL to which users are automatically returned after 3DS2 if it is triggered (i.e., if the SecureModeNeeded parameter is set to true).
Max. length: 255 characters
The URL to which to redirect the user to proceed to 3DS2 validation.
Whether or not the SecureMode was used.
The IP address of the end user initiating the transaction, in IPV4 or IPV6 format.
Allowed values: VISA, MASTERCARD, CB, MAESTRO
The card network to use, as chosen by the cardholder, in case of <a href="/guides/payment-methods/card/co-branded">co-branded cards</a>.
Default value: ECommerce
Allowed values: ECommerce, TelephoneOrder
The channel through which the user provided their card details, used to indicate mail-order and telephone-order (MOTO) payments:
- ECommerce – Payment received online.
- TelephoneOrder – Payment received via mail order or telephone order (MOTO).
Default value: DEFAULT
Allowed values: DEFAULT, FORCE, NO_CHOICE
The mode applied for the 3DS protocol for CB, Visa, and Mastercard. The options are:
- DEFAULT – Requests an exemption to strong customer authentication (SCA), and thus a frictionless payment experience, if allowed by your Mangopay contract and accepted by the issuer.
- FORCE – Requests SCA.
- NO_CHOICE – Leaves the choice to the issuer whether to allow for a frictionless payment experience or to enforce SCA.
Note: Sending the FORCE value automatically sets the ValidationUsage value to MIT.
Default value: MIT
Allowed values: MIT, CIT
Indicates the intended usage of the card:
- CIT – For customer-initiated transactions (CITs), meaning 3DS is less likely to be required on the card validation.
- MIT – For merchant-initiated transactions (MITs), meaning 3DS is more likely to be required on the card validation.
Note: The MIT value is returned automatically if the SecureMode value is FORCE, even if CIT is sent.
Returned values: UNKNOWN, VALID, INVALID
Whether the card is valid or not.
- UNKNOWN – No payment or card validation has been processed, so the validity of the card remains unknown.
- VALID – The first payment or card validation using the card was processed successfully within 24 hours of the initial card registration.
- INVALID – The first payment or card validation using the card was attempted and failed, or the status of the corresponding card registration was CREATED for more than 24 hours. Once a card is set to INVALID, it cannot be set back to VALID. A new card registration will be necessary to make a payment.
Unix timestamp (UTC) of the date and time the object was created.
Returned values: CARD_VALIDATION
The type of the card validation.
Returned values: V1, V2_1
The 3DS protocol version applied to the transaction.
The code indicating the result of the operation. This information is mostly used to <a href="/errors/codes">handle errors</a> or for filtering purposes.
The explanation of the result code.
Max. length: 255 characters
Custom data that you can add to this object.