---
title: "Retrieve Authentication"
method: GET
path: "/three-d-secure/authentications/{authentication-id}"
tags: ["3D Secure"]
---

# Retrieve Authentication

`GET /three-d-secure/authentications/{authentication-id}`

Retrieve an authentication by its authentication Id

## Response `200`

The authentication corresponding to the provided `authentication-id`

- ThreeDSecureAuthentication
  - `threeDSecureAuthenticationId` string, required — Used to identify API resources which may be required for future follow-on transactions; i.e. Refunds, Corrections, Completions, Reversals, etc.
  - `cardLookupId` string, nullable — Used to identify API resources which may be required for future follow-on transactions; i.e. Refunds, Corrections, Completions, Reversals, etc.
  - `merchantId` string, required — Thirteen character long identification provided to merchants by Moneris.
  - `orderId` string, nullable — Indicates the merchant-defined transaction identifer or order ID. Identifiers are unique for every Purchase, Pre-Authorization and Independent Refund transaction **Note**: No two transactions of these types may have the same order ID. Field only accepts alphanumerical characters, dashes and underscores.
  - `threeDSecureMessageType` 'AUTHENTICATION_RESPONSE_MESSAGE' | 'AUTHENTICATION_REQUEST_MESSAGE' | 'PREPARATION_RESPONSE_MESSAGE' | 'PREPARATION_REQUEST_MESSAGE' | 'CHALLENGE_RESPONSE_MESSAGE' | 'CHALLENGE_REQUEST_MESSAGE' | 'RESULTS_REQUEST_MESSAGE' | 'RESULTS_RESPONSE_MESSAGE' | 'ERROR_MESSAGE' | 'null', nullable — Indicates the response type in 3DS flow.
  - `threeDSecureTransactionStatus` 'AUTHENTICATED' | 'AUTHENTICATION_ATTEMPTED' | 'CHALLENGE_AUTHENTICATION_REQUIRED' | 'CHALLENGE_DECOUPLED_AUTHENTICATION_CONFIRMED' | 'TECHNICAL_ISSUE' | 'NOT_AUTHENTICATED' | 'REJECTED' | 'CHALLENGE_PREFERENCE_ACKNOWLEDGED', required — Indicates the Transaction result. For more information about this field, please review https://docs.3dsecure.io/3dsv2/specification_220.html#attr-ARes-transStatus - **AUTHENTICATED**: Authentication/ Account Verification Successful. - **AUTHENTICATION_ATTEMPTED**: Attempts Processing Performed; Not Authenticated/Verified , but a proof of attempted authentication/verification is provided. - **CHALLENGE_AUTHENTICATION_REQUIRED**: Challenge Required; Additional authentication is required using the `challengeUrl` and `challengeData`. - **CHALLENGE_DECOUPLED_AUTHENTICATION_CONFIRMED**: Challenge Required; Decoupled Authentication confirmed. - **TECHNICAL_ISSUE**: Authentication/ Account Verification Could Not Be Performed; Technical or other problem. - **NOT_AUTHENTICATED**: Not Authenticated /Account Not Verified; Transaction denied. - **REJECTED**: Authentication/ Account Verification Rejected; Issuer is rejecting authentication/verification and request that authorisation not be attempted. - **CHALLENGE_PREFERENCE_ACKNOWLEDGED**: Informational Only; 3DS Requestor challenge preference acknowledged.
  - `threeDSecureTransactionStatusReason` string, nullable — Provides information on why the Transaction Status field has the specified value.
  - `ecommerceIndicator` 'MAIL_TELEPHONE_ORDER_SINGLE' | 'MAIL_TELEPHONE_ORDER_RECURRING' | 'MAIL_TELEPHONE_ORDER_INSTALMENT' | 'MAIL_TELEPHONE_ORDER_UNKNOWN' | 'AUTHENTICATED_ECOMMERCE' | 'NON_AUTHENTICATED_ECOMMERCE' | 'SSL_MERCHANT', required — The ecommerce indicator (ECI) specifies the level of security that was used to obtain the cardholder's payment data. It is sent by the merchant and returned by the issuer. When returned in the response, it can be different from the value sent in the request in case transaction was downgraded by the issuer.
  - `threeDSecureChallengeUrl` string, uri, nullable — If the transStatus is “C” this field will be populated with the URL to POST the challengeData to create the cardholder challenge screen
  - `threeDSecureChallengeData` string, nullable — String that must be POSTed to the Challenge URL to create challenge screen
  - `threeDSecureAuthenticationValue` string, nullable — **CAVV**: Cardholder Authentication Verification Value Provided during a payment request to authenticate the card user.
  - `threeDSecureChallengeCompletionIndicator` 'YES' | 'NO' | 'null', nullable — Indicates if Challenge was completed. This is returned in CAVV Lookup Request.
  - `threeDSecureServerTransactionId` string, uuid, nullable — Indicates information required when sending a version 3-D Secure 2.0+ transaction. This data is obtained from a CAVV Lookup Request or MPI 3DS Authentication Request transaction.
  - `threeDSecureDirectoryServerTransactionId` string, uuid, nullable — Universally unique transaction identifier assigned by the 3DS Directory Server (DS) to identify a single transaction.
  - `threeDSecureAccessControlServerTransactionId` string, uuid, nullable — Required if sending a version 3-D Secure 2.0+ transaction. Data is obtained from a Cavv Lookup Request or MPI 3DS Authentication Request transaction
  - `paymentMethod` PaymentMethod, required — Payment method response object
    - `paymentMethodId` string, required — Unique Identifier of the payment method.
    - `merchantId` string, required — Thirteen character long identification provided to merchants by Moneris.
    - `cardholderInformation` CardholderInformation, nullable — Information about the holder of the card.
      - `cardholderName` string, required — Cardholder name
      - `companyName` string, nullable — Identifies the associated company name
    - `contactDetails` ContactDetails, nullable — Contact details
      - `phoneNumber` string, nullable — Phone number.
      - `email` string, email, nullable — Contains the customer's email address. For standard email protocols, visit: https://www.rfc-editor.org/rfc/rfc5322
    - `billingAddress` object, nullable — The postal address including street, town/city, province, and postal code. Optionally an unit number can be provided.
      - `unitNumber` string, nullable — Unit number
      - `streetNumber` string, nullable — Street number
      - `streetName` string, nullable — Street name
      - `city` string, nullable — Identifies the city.
      - `province` string, iso-3166-2, nullable — Province or state ISO 3166-2 code
      - `postalCode` string, nullable — Postal or zip code
      - `country` string, iso-3166, nullable — Provides the two letter country code according the ISO 3166-1 alpha-2 standard. For a complete list of country codes, visit: https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2.
    - `paymentMethodInformation` CardPaymentMethodInformation, required — Details about the card used in the payment method.
      - `paymentMethodType` 'CARD', required — The type of Payment Method being used. It can be: - Card.
      - `paymentMethodSource` 'CARD' | 'TEMPORARY_TOKEN' | 'PERMANENT_TOKEN' | 'APPLE_PAY_ENCRYPTED' | 'APPLE_PAY_DECRYPTED' | 'GOOGLE_PAY_ENCRYPTED' | 'GOOGLE_PAY_DECRYPTED', required — The source of Payment Method being used. It can be: - The Id of a Payment Method already created. - Permanent Token. - Temporary Token. - Card. - E-Wallet.
      - `cardInformation` CardInformation, required — Information about the card being used for the transaction
        - `bankIdentificationNumber` string, nullable — **BIN**: Bank Identification Number Consists of the first six to eight digits of the Primary Account Number (PAN) and identifies the relevant payment network and the specific payment issuing institution.
        - `lastFour` string, nullable — Last 4 digits of the card.
        - `expiryMonth` integer — Card expiration month. Format must be MM
        - `expiryYear` integer — Displays the card expiration year. Accepted format: YYYY
        - `cardBrand` 'MASTERCARD' | 'VISA' | 'AMERICAN_EXPRESS' | 'JCB' | 'DISCOVER' | 'INTERAC' | 'UNIONPAY' | 'GIFT_MONERIS' | 'GIFT_DATACANDY' | 'GIFT_GIVEX' | 'null', nullable — Displays the card brand name associated with the card type.
        - `cardType` 'CREDIT' | 'DEBIT' | 'DOMESTIC_DEBIT' | 'PREPAID_RELOADABLE' | 'PREPAID_NON_RELOADABLE' | 'UNKNOWN' | 'GIFT' | 'LOYALTY' | 'FLEET' | 'CORPORATE', nullable — Specifies the intended card use; i.e. debit or credit.
        - `cardFingerprint` string, nullable — Unique card identifier. Fingerprinting randomly assigns identfiers for cards that share the same Primary Account Number (PAN) to easily identify when multiple payments methods are attached to the same underlying card, and assists merchants identify individual customers across various channels; i.e. loyalty programs.
        - `issuer` string, nullable — Card issuer.
      - `paymentAccountReference` string, nullable — Used to link Primary Account Number (PAN) based transactions and transactions on associated payment tokens without using the PAN as the linking mechanism.
      - `storePaymentMethod` 'DO_NOT_STORE' | 'CARDHOLDER_INITIATED' | 'MERCHANT_INITIATED', required — Store this payment method created through this payment for future use. - DO_NOT_STORE: Payment method will not be stored. - CARDHOLDER_INITIATED: Payment method to be stored and can only re-used with cardholder's consent. Limited to store, pre-authorisation, and card validations." - MERCHANT_INITIATED: Payment method to be stored and can be reused without the cardholder's consent. For example, subscriptions.
    - `createdAt` string, date-time, required — Time at which the object was created
    - `modifiedAt` string, date-time, nullable — Time at which the object was modified
    - `customData` CustomData, nullable — Merchant can send custom meta data with the transaction in this object. Moneris will echo these values back in response.
  - `threeDSecureCardholderInformation` string, nullable — Text provided by the ACS/Issuer to Cardholder during a Frictionless or Decoupled transaction. The Issuer can provide information to Cardholder.
  - `threeDSecureVersion` string, required — Required when sending a 3-D Secure version 2.0+ transaction. If no value is provided, default to V1.
  - `threeDSecureAuthenticationType` 'STATIC' | 'DYNAMIC' | 'OUT_OF_BAND' | 'DECOUPLED' | 'null', nullable — Indicates the type of authentication method the Issuer will use to challenge the Cardholder, whether in the ARes message or what was used by the ACS when in the RReq message.
  - `threeDSecureAuthenticationTimestamp` string, date-time, nullable — Date and time in UTC of the cardholder authentication.

## Other responses

- `401` — Not authorized. The user does not have a valid API Key or Access Token.
- `403` — Forbidden. The user does not have permission to access the requested resource.
- `404` — Not Found.
- `429` — Too Many Requests
- `500` — Unexpected error.
- `503` — Service Temporarily Unavailable

---

[API](https://skmtc.net/moneris/apis/moneris-api.md) · [All operations](https://skmtc.net/moneris/apis/moneris-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/moneris/moneris-api/revisions/edefcc925b74/schema)
