Create a 3DS Data Share Only Payment
3DS Data Share Only is a mode within EMV 3-D Secure (3DS) where transaction data is shared between the merchant, issuer, and card network for risk assessment purposes, but no cardholder authentication challenge is performed.
In this model:
- The merchant sends transaction and customer data through the 3DS protocol.
- The issuer receives the data and can use it for fraud detection, risk scoring, and authorization decisions.
- The transaction proceeds without requiring the cardholder to complete an authentication step (such as entering a one-time password or using biometric verification).
- The purpose is to improve fraud prevention while maintaining a frictionless customer experience.
Requirements
Before starting the integration, complete the following:
- API Credentials: Contact the Integration Support Team to obtain your
client_idandclient_secret. - Access Token: Generate a Bearer token using your credentials via the Access Token endpoint.
- Card Brand Support: Verify the card brand is Mastercard or Visa. These are currently supported for 3DS in Argentina, Chile, Mexico, Brazil, and Uruguay.
Payment facilitators: When Getnet enables your credential as a payment facilitator, you must also send the
data.sub_merchantobject when you create the payment. See Payment Facilitators.
Understanding the Data Share Only Process
Data Share Only sends transaction and cardholder data to the issuer so it can decide whether to approve the payment without presenting a challenge to the customer. Request this behavior by setting the EMV 3DS threeDSRequestorChallengeInd value through the requestor_challenge_indicator field to "06", inside extra_fields.data_only. Because the customer never leaves your checkout page, Data Share Only removes the redirect friction of a challenge.
After you initiate enrollment, the API returns the same status field used in the standard 3DS flow:
- Direct decision: The issuer approves or declines the transaction immediately, based on the shared data (status:
Authenticated/3-D Secure Data OnlyorDenied). - Pending Enrollment Continue: The issuer requires additional processing before reaching a final state (status:
Pending Enrolment Continue). This step may ultimately result in the success of the workflow.
Implementation Steps
Step 1: Obtain Access Token and Tokenize Card
Request an access token using your API credentials.
Step 2: Initiate Enrollment with Data Share Only
Call the 3DS - Init Authentication endpoint. Include the same extra_fields.billing_address and extra_fields.shipping_address object you’d send for a standard 3DS enrollment, plus a data_only object with requestor_challenge_indicator set to "06".
curl --request POST \
--url https://api-sbx.globalgetnet.com/dpm/security-gwproxy/v2/enrolments-initial \
--header 'authorization: Bearer <your-token>' \
--header 'content-type: application/json' \
--data '{
"currency": "CLP",
"md": "NmQyZTQzODAtZDhhMy00Y2NiLTkxMzgtYzI4OTE4MjgxOGE0",
"term_url": "123",
"amount": 1,
"payment_method": {
"expiration_month": "05",
"expiration_year": "25",
"security_code": "282",
"number": "5155901222280001"
},
"description": "TEST",
"operation": "CREDIT",
"extra_fields": {
"billing_address": {
"street": "Av. Brasil",
"number": "1000",
"complement": "Sala 1",
"district": "São Geraldo",
"city": "Porto Alegre",
"state": "RS",
"country": "BR",
"postal_code": "90230060",
"reference": "Near the hospital"
},
"shipping_address": {
"street": "Av. Brasil",
"number": "1000",
"complement": "Sala 1",
"district": "São Geraldo",
"city": "Porto Alegre",
"state": "RS",
"country": "BR",
"postal_code": "90230060",
"reference": "Near the hospital"
},
"data_only": {
"requestor_challenge_indicator": "06"
}
}
}'Response (Authenticated):
{
"transaction_id": "3729756321501820",
"md": "",
"tx_id": 48347501,
"xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
"protocol": "3DS2.3.1",
"status": "Authenticated",
"operation": "DEBIT",
"redirect_html_template": "",
"extra_fields": {
"billing_address": {
"street": "Av. Brasil",
"number": "1000",
"complement": "Sala 1",
"district": "São Geraldo",
"city": "Porto Alegre",
"state": "RS",
"country": "BR",
"postal_code": "90230060",
"reference": "Near the hospital"
},
"shipping_address": {
"street": "Av. Brasil",
"number": "1000",
"complement": "Sala 1",
"district": "São Geraldo",
"city": "Porto Alegre",
"state": "RS",
"country": "BR",
"postal_code": "90230060",
"reference": "Near the hospital"
},
"data_only": {
"requestor_challenge_indicator": "06"
}
},
"ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
"eci": 6,
"cavv": "aglgsCXwXPJDRA1aTlXIMVQnQakX"
}Response (Pending Enrolment Continue):
{
"transaction_id": "3729756321501820",
"md": "",
"tx_id": 48347501,
"xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
"status": "Pending Enrolment Continue",
"protocol": "3DS2.3.1",
"operation": "DEBIT",
"redirect_html_template": "",
"ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
"eci": 7,
"cavv": "aglgsCXwXPJDRA1aTlXIMVQnQakX"
}The exact
ecivalue depends on the card brand and issuer. A value indicating no liability shift is common for Data Share Only, since the issuer approved the transaction without a full authentication challenge.
Step 3: Check Status
Check the status field in the response and follow the appropriate scenario:
Status: Authenticated
The issuer approved the transaction based on the shared data alone. Extract xid, eci, cavv, and ds_trans_id, skip Step 4 proceeding to Step 5: Create the Payment.
Status: Denied
The issuer declined the transaction based on the shared data. Don’t attempt to create the payment.
Status: Pending Enrolment Continue
If the initial enrollment returns Pending Enrolment Continue, proceed to Step 4: Continue Enrolment.
Step 4: Continue Enrolment
Call the 3DS - Continue Enrollment endpoint with the transaction_id from Step 2.
curl https://api.pre.globalgetnet.com/dpm/security-gwproxy/v2/enrolments-continue \
--request POST \
--header 'Content-Type: application/json' \
--data '{
"transaction_id": "3729756321501820",
"xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA="
}'Response (3-D Secure Data Only):
{
"transaction_id": "84c05897-fbf1-4a91-90e8-d292a0fda1c8",
"md": "",
"tx_id": 48347501,
"xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
"status": "3-D Secure Data Only",
"protocol": "3DS2.3.1",
"operation": "DEBIT",
"redirect_html_template": "",
"ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
"eci": 7,
"cavv": "aglgsCXwXPJDRA1aTlXIMVQnQakX"
}Step 5: Create the Payment
Once authentication completes (status Authenticated or 3-D Secure Data Only), call the Create - Authorize endpoint. Include the authentication data (xid, eci, cavv, ds_trans_id) in the payment object.
curl --request POST \
--url https://api-sbx.globalgetnet.com/dpm/payments-gwproxy/v2/payments \
--header 'authorization: Bearer '\
--header 'content-type: application/json' \
--header 'x-seller-id: 54f88e68-7764-4e87-8830-756b1e2c02f8' \
--data '{
"order_id": "123order",
"data": {
"amount": 118708,
"currency": "CLP",
"payment": {
"payment_method": "CREDIT_AUTHORIZATION",
"xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
"eci": "24",
"ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
"card": { ... }
}
}
}'