Playground API
DocsStatsBlogStudio
Documentation Tree
Technical BlogFeature Deep Dives
  • Introduction
  • Quickstart
    5 min
  • How It Works
  • Recipes & Cookbooks
  • Platform Comparisons
  • Real-World Showcase
  • Interactive Studio
    Studio
  • GraphiQL IDE
    IDE
  • Session Quotas & Activity
  • Network Chaos Simulator
  • Atomic Sandbox Reset
  • Overview & Models
    Hub
  • Users Resource
  • Posts Resource
  • Comments Resource
  • Todos Resource
  • Custom Collections
    Custom
  • Multipart File Uploads
    Upload
  • Dynamic SVG Avatars
    SVG
  • Image Thumbnails
    CDN
  • Relational Filtering
  • Full-Text Search
  • Dynamic Sorting
  • Offset Pagination
  • Cursor Pagination
    Scroll
  • CSV & Excel Export & Import
    IO
  • Custom Collections
    CRUD
  • Overview & Architecture
    Hub
  • JWT Auth Flow
  • Refresh Token Rotation
    Mutex
  • RBAC Permission Matrix
    Roles
  • Expiry Simulation
  • Clock Skew Drift
  • Password Recovery Loop
  • Dual-Mode Sandboxing
  • GraphiQL IDE
    IDE
  • Relational Queries
  • Stateful Mutations
  • Realtime Subscriptions
  • Overview & Flowcharts
    Hub
  • Hosted Checkout
    Stripe
  • Payment Intents API
  • 3DS Challenge Modal
    Modal
  • Customers Vault
  • Charges & Refunds
  • Test Cards Catalog
  • Overview & Channels
    Hub
  • Virtual Email Mailbox
    Mailtrap
  • Virtual SMS Terminal
    Phone
  • In-App Notifications
  • Message Dispatcher
  • Realtime Studio
    Studio
  • Native WebSocket (/ws)
  • Socket.io Gateway
  • Presence & Echo Bot
  • Server-Sent Events (SSE)
    SSE
  • Analytics Telemetry
  • Webhook Subscriptions
  • HMAC SHA-256 Signatures
  • Delivery Logs
  • Manual Retry Simulator
  • Network Latency Delay
  • HTTP Status Codes
  • Rate-Limit Simulator
    429
  • Flaky Network & Jitter
    Chaos
  • Session Quotas & Activity
  • JSON Snapshots
    JSON
  • Headless CI/CD Testing
    CI
  • Mobile QR Code Sync
  • System Metrics & Health
  • Atomic Sandbox Reset
  • Official TypeScript SDK
  • Multi-Language Generators
  • DevTools Extension
  • OpenAPI 3.1 Spec
    JSON
  • Postman Collection v2.1
  • Bruno Collection
  • Insomnia Workspace
  • TypeScript .d.ts
    .d.ts
  • AI Prompt Rules
    Rules
  • Context Index (llms.txt)
  • Full Schema (llms-full.txt)
  • Manifest (product.json)
  • All Feature Articles
    Blog
  • React CRUD Without Backend
    Deep Dive
  • Why Static APIs Fail
  • Mocking Stateful Auth
  • WebSockets & SSE Guide
Technical Blog
Articles

In-depth articles explaining stateful mock APIs, WebSockets, payments, and frontend resilience.

Read Articles
PreviousPayment Intents API
NextCustomers Vault
Mock Commerce & Billing

3D Secure (3DS 2.0 / SCA) Challenge

Simulate Strong Customer Authentication (SCA) as mandated by European PSD2 regulations. Test how your application intercepts requires_action, mounts the issuer Access Control Server (ACS) modal or iframe, and finalizes authorization.

3DS Test CardsAPI Consoles

Live 3DS Challenge Sandbox

Trigger a realistic simulated ACS popup to test user approval and cancellation events.

Challenge Card
4000 0000 0000 0341

Triggers mandatory SCA OTP prompt.

Frictionless Card
4000 0000 0000 0317

Bypasses challenge; auto-authenticated.

Post-Challenge URL
POST /payments/intents/:id/confirm-3ds

Finalizes intent state to succeeded.

Interactive API Execution

Test the two-step 3DS API endpoints against your sandbox session.

1. Trigger 3DS Challenge Charge

Trigger 3DS Challenge

POST
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}

2. Confirm Challenge Result

Confirm 3DS Challenge

POST
response.json
1
{
2
// Click "Send" above to execute this request against the live server.
3
}

3DS 2.0 Architectural Flow: Challenge vs Frictionless

Modern 3DS 2.0 uses risk-based authentication to minimize checkout friction while shifting fraud liability to the card issuer.

Challenge Flow (...0341)

When the bank deems the transaction higher risk (or required by PSD2 SCA), the intent transitions to requires_action. The frontend must display an OTP entry or biometric prompt to the cardholder before charging the card.

Frictionless Flow (...0317)

Device telemetry, IP reputation, and behavioral analytics allow the issuer to verify identity passively in the background without prompting the customer. The payment transitions directly to succeeded with full liability shift.

Integration Handling Recipes

Handling 3DS actions with Stripe.js and vanilla JavaScript.

Handling requires_action in Frontend

javascript
1
// Process intent response from backend
2
async function handlePaymentResponse(intent) {
3
if (intent.status === 'requires_action') {
4
// 1. Bank requires 3DS SCA
5
const challengeUrl = intent.next_action?.redirect_to_url?.url;
6
7
// 2. Open popup modal or redirect
8
const popup = window.open(challengeUrl, '3ds-challenge', 'width=480,height=600');
9
10
// 3. Listen for postMessage or poll intent
11
window.addEventListener('message', async (event) => {
12
if (event.data === '3ds_complete') {
13
popup.close();
14
// Check final status
15
const refreshed = await fetch(/api/payments/intents/${intent.id});
16
const finalData = await refreshed.json();
17
if (finalData.status === 'succeeded') {
18
showSuccessScreen();
19
}
20
}
21
});
22
} else if (intent.status === 'succeeded') {
23
showSuccessScreen();
24
}
25
}

Stripe.js SDK Equivalent

typescript
1
import { useStripe } from '@stripe/react-stripe-js';
2
3
export function CheckoutButton({ clientSecret }: { clientSecret: string }) {
4
const stripe = useStripe();
5
6
const handleConfirm = async () => {
7
if (!stripe) return;
8
9
// stripe.js automatically detects requires_action
10
// and launches the bank challenge modal in an iframe
11
const { error, paymentIntent } = await stripe.confirmCardPayment(clientSecret);
12
13
if (error) {
14
console.error('3DS or Card Error:', error.message);
15
} else if (paymentIntent.status === 'succeeded') {
16
console.log('Payment authenticated and captured!');
17
}
18
};
19
20
return <button onClick={handleConfirm}>Pay Now</button>;
21
}