Getnet DocsGetnet Docs

Create a 3DS Data Share Only Payment

3DS Data Share Only is a mode within EMV 3-D Secure (3DS) where transaction data is shared between the merchant, issuer, and card network for risk assessment purposes, but no cardholder authentication challenge is performed.

In this model:

  • The merchant sends transaction and customer data through the 3DS protocol.
  • The issuer receives the data and can use it for fraud detection, risk scoring, and authorization decisions.
  • The transaction proceeds without requiring the cardholder to complete an authentication step (such as entering a one-time password or using biometric verification).
  • The purpose is to improve fraud prevention while maintaining a frictionless customer experience.

Requirements

Before starting the integration, complete the following:

  • API Credentials: Contact the Integration Support Team to obtain your client_id and client_secret.
  • Access Token: Generate a Bearer token using your credentials via the Access Token endpoint.
  • Card Brand Support: Verify the card brand is Mastercard or Visa. These are currently supported for 3DS in Argentina, Chile, Mexico, Brazil, and Uruguay.

Payment facilitators: When Getnet enables your credential as a payment facilitator, you must also send the data.sub_merchant object when you create the payment. See Payment Facilitators.

Understanding the Data Share Only Process

Data Share Only sends transaction and cardholder data to the issuer so it can decide whether to approve the payment without presenting a challenge to the customer. Request this behavior by setting the EMV 3DS threeDSRequestorChallengeInd value through the requestor_challenge_indicator field to "06", inside extra_fields.data_only. Because the customer never leaves your checkout page, Data Share Only removes the redirect friction of a challenge.

After you initiate enrollment, the API returns the same status field used in the standard 3DS flow:

  1. Direct decision: The issuer approves or declines the transaction immediately, based on the shared data (status: Authenticated/3-D Secure Data Only or Denied).
  2. Pending Enrollment Continue: The issuer requires additional processing before reaching a final state (status: Pending Enrolment Continue). This step may ultimately result in the success of the workflow.

Implementation Steps

Step 1: Obtain Access Token and Tokenize Card

Request an access token using your API credentials.

Step 2: Initiate Enrollment with Data Share Only

Call the 3DS - Init Authentication endpoint. Include the same extra_fields.billing_address and extra_fields.shipping_address object you’d send for a standard 3DS enrollment, plus a data_only object with requestor_challenge_indicator set to "06".

curl --request POST \
  --url https://api-sbx.globalgetnet.com/dpm/security-gwproxy/v2/enrolments-initial \
  --header 'authorization: Bearer <your-token>' \
  --header 'content-type: application/json' \
  --data '{
  "currency": "CLP",
  "md": "NmQyZTQzODAtZDhhMy00Y2NiLTkxMzgtYzI4OTE4MjgxOGE0",
  "term_url": "123",
  "amount": 1,
  "payment_method": {
    "expiration_month": "05",
    "expiration_year": "25",
    "security_code": "282",
    "number": "5155901222280001"
  },
  "description": "TEST",
  "operation": "CREDIT",
  "extra_fields": {
    "billing_address": {
      "street": "Av. Brasil",
      "number": "1000",
      "complement": "Sala 1",
      "district": "São Geraldo",
      "city": "Porto Alegre",
      "state": "RS",
      "country": "BR",
      "postal_code": "90230060",
      "reference": "Near the hospital"
    },
    "shipping_address": {
      "street": "Av. Brasil",
      "number": "1000",
      "complement": "Sala 1",
      "district": "São Geraldo",
      "city": "Porto Alegre",
      "state": "RS",
      "country": "BR",
      "postal_code": "90230060",
      "reference": "Near the hospital"
    },
    "data_only": {
      "requestor_challenge_indicator": "06"
    }
  }
}'

Response (Authenticated):

{
  "transaction_id": "3729756321501820",
  "md": "",
  "tx_id": 48347501,
  "xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
  "protocol": "3DS2.3.1",
  "status": "Authenticated",
  "operation": "DEBIT",
  "redirect_html_template": "",
  "extra_fields": {
    "billing_address": {
      "street": "Av. Brasil",
      "number": "1000",
      "complement": "Sala 1",
      "district": "São Geraldo",
      "city": "Porto Alegre",
      "state": "RS",
      "country": "BR",
      "postal_code": "90230060",
      "reference": "Near the hospital"
    },
    "shipping_address": {
      "street": "Av. Brasil",
      "number": "1000",
      "complement": "Sala 1",
      "district": "São Geraldo",
      "city": "Porto Alegre",
      "state": "RS",
      "country": "BR",
      "postal_code": "90230060",
      "reference": "Near the hospital"
    },
    "data_only": {
      "requestor_challenge_indicator": "06"
    }
  },
  "ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
  "eci": 6,
  "cavv": "aglgsCXwXPJDRA1aTlXIMVQnQakX"
}

Response (Pending Enrolment Continue):

{
  "transaction_id": "3729756321501820",
  "md": "",
  "tx_id": 48347501,
  "xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
  "status": "Pending Enrolment Continue",
  "protocol": "3DS2.3.1",
  "operation": "DEBIT",
  "redirect_html_template": "",
  "ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
  "eci": 7,
  "cavv": "aglgsCXwXPJDRA1aTlXIMVQnQakX"
}

The exact eci value depends on the card brand and issuer. A value indicating no liability shift is common for Data Share Only, since the issuer approved the transaction without a full authentication challenge.

Step 3: Check Status

Check the status field in the response and follow the appropriate scenario:

Status: Authenticated

The issuer approved the transaction based on the shared data alone. Extract xid, eci, cavv, and ds_trans_id, skip Step 4 proceeding to Step 5: Create the Payment.

Status: Denied

The issuer declined the transaction based on the shared data. Don’t attempt to create the payment.

Status: Pending Enrolment Continue

If the initial enrollment returns Pending Enrolment Continue, proceed to Step 4: Continue Enrolment.

Step 4: Continue Enrolment

Call the 3DS - Continue Enrollment endpoint with the transaction_id from Step 2.

curl https://api.pre.globalgetnet.com/dpm/security-gwproxy/v2/enrolments-continue \
  --request POST \
  --header 'Content-Type: application/json' \
  --data '{
  "transaction_id": "3729756321501820",
  "xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA="
}'

Response (3-D Secure Data Only):

{
  "transaction_id": "84c05897-fbf1-4a91-90e8-d292a0fda1c8",
  "md": "",
  "tx_id": 48347501,
  "xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
  "status": "3-D Secure Data Only",
  "protocol": "3DS2.3.1",
  "operation": "DEBIT",
  "redirect_html_template": "",
  "ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
  "eci": 7,
  "cavv": "aglgsCXwXPJDRA1aTlXIMVQnQakX"
}

Step 5: Create the Payment

Once authentication completes (status Authenticated or 3-D Secure Data Only), call the Create - Authorize endpoint. Include the authentication data (xid, eci, cavv, ds_trans_id) in the payment object.

curl --request POST \
  --url https://api-sbx.globalgetnet.com/dpm/payments-gwproxy/v2/payments \
  --header 'authorization: Bearer '\
  --header 'content-type: application/json' \
  --header 'x-seller-id: 54f88e68-7764-4e87-8830-756b1e2c02f8' \
  --data '{
    "order_id": "123order",
    "data": {
      "amount": 118708,
      "currency": "CLP",
      "payment": {
        "payment_method": "CREDIT_AUTHORIZATION",
        "xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
        "eci": "24",
        "ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
        "card": { ... }
      }
    }
  }'

Next Steps