How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Silverflow 3DS Authentication API

3DS Authentication Endpoints

Silverflow 3DS Authentication API is one of 50 APIs that Silverflow publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include 3DS Authentication. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, a getting-started guide, authentication docs, and rate-limit docs.

This API exposes 5 operations across 4 paths, and defines 158 schemas. It is described by OpenAPI 3.2.0, at version 1.417.0.

Requests are made against 3 base URLs: https://eu-west-1.api.silverflow.com/v1, https://us-east-2.api.silverflow.com/v1, https://eu-west-1.api-sbx.silverflow.com/v1.

5 operations 4 paths 158 schemas 2 GET3 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.417.0
Base URL
https://eu-west-1.api.silverflow.com/v1
Authentication
HTTP Basic, HTTP Bearer, API Key
License
Commercial
Resource Areas
1

Authentication & Security 3

Silverflow 3DS Authentication API declares 3 security schemes for authenticating requests. It accepts HTTP basic authentication (ApiKey). It accepts HTTP bearer tokens (JWT) (BearerToken). An API key is passed in the header as - (MutualTLS). By default, every request must be authenticated.

  • ApiKey — The primary method of authenticating to the Silverflow API is through API keys. API keys can be created by calling the [createApiKey](operation/createApiKey) e…
  • BearerToken — Bearer tokens are temporary security credentials that can be used to authorize 'third parties' (bearers) access to the Silverflow API on behalf of the agent. T…
  • MutualTLS — The client must set up mTLS connection with a valid X.509 client certificate signed by a customer-provided CA (certificate authority) that is registered to a s…

Paths & Operations 5

Across 4 paths, the API surfaces 5 operations — 2 GET, 3 POST. Each is listed below with its method, path, parameters, and response codes.

3DS Authentication 5

3DS Authentication Endpoints

POST
/3ds
Create 3DS Authentication
create3dsAuthentication body → 201400401409422429500
GET
/3ds
List 3DS Authentications
get3dsAuthentications 3 params → 200400401429500
POST
/3ds/3ri
Create 3RI Authentication
create3riAuthentication body → 201400401409422429500
GET
/3ds/{threedsKey}
Get 3DS Authentication
get3dsAuthentication 1 param → 200401404429500
POST
/3ds/cardRanges
Retrieve Card Ranges
3dsCardRanges body → 200400401409429500

Schemas 158

The contract defines 158 schemas that model the data the API accepts and returns. The most detailed are ThreeDsChallengeFinished (17 properties), ThreeDsChallengeFinishedWithoutAuthValue (17 properties), ThreeDsNoFlowNoAuth (15 properties), PublicCreate3dsRequestWithMerchantAcceptor (15 properties). Each schema is shown below with its type and property counts.

browserScreenWidth
string
Total width of the cardholder's screen in pixels. Value is returned from the screen.width property from the HTML DOM API.
interactionCounter
string
The number of interactions for each transaction tracked by the ACS.
holderName
string
The name of the cardholder as displayed on the card. It will be truncated if longer than 45 characters. The name needs to comply with the following regular exp…
acsUrl
string
The merchant or PSP needs to send the base64 encoded CReq message as a form to this URL using an HTTP POST, from the cardholder challenge window. The content t…
order
string
The method used to place the order. When set to recurring or installment, you are also required to set recurringExpiry and recurringFrequency.
sdkTransID
string
Universally unique transaction identifier assigned upon the activation of 3DS SDK.
components-schemas-stateOrProvince
string
The state (US) or province (non-US) of the address.
ThreeDsCardRangesCardNumberRequest
object
2 properties 1 required
schemas-CountryCodeAlpha2
object
1 property 1 required
schemas-created
string
The date and time this object was created
browserLanguage
string
Value representing the browser language as defined in IETF BCP47. Returned from navigator.language property from the HTML DOM API.
ThreeDsChallengeFinished
object
17 properties 12 required
frictionlessFlow
ThreeDsPriorAuthenticationInfo
object
References the initial 3DS transaction to set up this sequence.
4 properties 4 required
DynamicDescriptor
object
Allows customizing the DBA name on a per-transaction basis, to help the cardholder recognize the business name on their card or bank statement.
1 property
threeDSServerTransID
string
Universally unique transaction identifier assigned by the 3DS server to identify a single transaction. This identifier is assigned by Silverflow.
notificationUrl
string
URL that receives the challenge response (CRes) or error message from the issuer's Access Control Server (ACS).
ThreeDsCardRangesProcessorTokenRequest
object
1 property 1 required
schemas-CountryCodeNumeric
object
1 property 1 required
version
integer
The version of this object
browserScreenHeight
string
Total height of the cardholder's screen in pixels. Value is returned from the screen.height property from the HTML DOM API.
schemas-offsetToken
string
ResponseAmount
An amount encoded as an object with a value in minor units and a currency code. The amount is unknown for entities older than 2023-03-30.
schemas-Page
object
1 property
PublicCreate3dsRequestWithMerchantInfo
object
15 properties 5 required
ThreeDsNoFlowNoAuthWithoutAuthValue
object
14 properties 10 required
PublicCreate3dsRequestWithMerchantAcceptor
object
15 properties 5 required
schemas-currencyCode
string
AResWithoutAuthValue
object
The issuer's response to the 3DS request.
components-schemas-line2
string
Address line 2
ThreeDsCardRangesResponse
object
10 properties 7 required
dataOnlyResult
components-schemas-line1
string
Address line 1
ThreeRiIndicator
string
Indicates the type of 3RI request. This property provides additional information to the ACS to determine the best approach for handling a 3RI request.
ReferencedEntityNotFoundErrorDetails
object
5 properties 5 required
ThreeDsChallenge
object
14 properties 10 required
ThreeDsFrictionlessAuthenticated
object
15 properties 10 required
BrowserDataJavascriptEnabledFalse
InstallmentTerms
integer
Maximum number of authorizations for an installment payment. Required for and only allowed when threeRiIndicator = "installment". Must be greater than 1 and at…
AddressInput
MessageExtension
object
4 properties 4 required
result
string
Authentication result.
ThreeDsCardRangesRequest
browserUserAgent
string
Exact content of the HTTP user-agent header.
browserTimeZoneOffset
string
Time-zone offset in minutes between UTC and the cardholder browser local time. Value is returned from the getTimezoneOffset() method. Note that the offset is p…
pan
string
Full digits of the card.
acsRenderingType
object
The ACS rendering type contains information about the rendering type that the ACS is sending for the cardholder authentication.
2 properties 2 required
whiteListStatus
string
Enables the communication of trusted beneficiary/whitelist status between the ACS, the DS and the 3DS requestor.
noAuthResult
Result
string
Authentication result.
challengeCancel
string
Indicator informing the ACS and the DS that the authentication has been canceled.
ThreeDsFrictionlessAuthenticatedWithoutAuthValue
object
14 properties 10 required
authenticationMethod
string
Authentication approach that the ACS used to authenticate the cardholder for this specific transaction.
schemas-CountryCodeAlpha3
object
1 property 1 required
RReq
object
This property is only present after the cardholder finished the challenge flow. The RReq message communicates the results of the authentication or verification…
errorTitle
string
A short, human-readable summary of the problem type. It does not change from occurrence to occurrence of the error.
ThreeDsChallengeFinishedWithoutAuthValue
object
17 properties 12 required
components-schemas-postalCode
string
The postal code of the address, allowing spaces and dashes
flow
string
Indicates the flow that was used for the 3DS authentication.
ThreeDsDataOnly
object
15 properties 10 required
cvc
string
The CVC of the card
browserColorDepth
string
Value representing the bit depth of the colour palette for displaying images, in bits per pixel. Obtained from cardholder browser using the screen.colorDepth p…
browserIP
string
IP address of the browser as returned by the HTTP headers. Shall be included where regionally acceptable. Example IPv6 address: 2011:0db8:85a3:0101:0101:8a2e:0…
PhoneNumber
object
2 properties 2 required
MerchantInfoResponse
object
Merchant details as stored and returned in the response. The merchantCountryCode is returned as a complete ISO 3166-1 country code object containing all repres…
7 properties 6 required
CardholderInformation
object
Extra information about the cardholder.
2 properties
acsDecConInd
string
Indicates whether the ACS confirms utilisation of decoupled authentication and agrees to utilize decoupled authentication to authenticate the cardholder.
addressInputBase
object
A physical postal address
5 properties 3 required
schemas-AcceptorRef
object
Reference key and status of the acceptor
2 properties 2 required
protocolVersion
string
The 3DS protocol version which has been used to perform 3DS. Protocol version 2.1.0 is no longer supported by the card networks. The value 2.1.0 can be retriev…
UnenrolledAccountNumberErrorDetails
object
5 properties 5 required
processorTokenKey
string
The key to a card stored using [Processor Tokenization](tag/Processor-Tokenization).
ThreeDsPageEntity
recurringFrequency
integer
Number of days between recurring authorizations. Required when type.order is recurring or installment.
MessageExtensionList
array
Carries additional data that is not defined within the 3DS protocol. This field is usually used for card network specific data.
browserAcceptHeader
string
Exact content of the HTTP accept headers as sent to the 3DS Requestor from the cardholder's browser.
Amount
object
An amount encoded as an object with a value in minor units and a currency code.
2 properties 2 required
schemas-acceptorKey
string
Uniquely identifies a merchant acceptor.
acsReferenceNumber
string
Unique identifier assigned by the EMVCo secretariat upon testing and approval.
Message
object
A 3DS protocol message as it is received by the card network.
4 properties 2 required
UnsupportedProtocolVersionErrorDetails
object
5 properties 5 required
CardByProcessorTokenKey
object
2 properties 1 required
BrowserData
object
4 properties 3 required
acsSignedContent
string
Contains the JWS object (represented as a string) created by the ACS for the ARes message.
ThreeRiRecurringFrequency
integer
Number of days between recurring authorizations. This property is required for threeRiIndicator = "recurring", "installment", or "standing-order". For other ca…
cardHolderInfo
string
Text provided by the ACS/issuer to cardholder during a frictionless or decoupled transaction.
EntityNotFoundErrorDetails
object
5 properties 5 required
acsTransID
string
Universally unique transaction identifier assigned by the ACS to identify a single transaction. Each DS can provide a unique ID to each ACS on an individual ba…
PublicCreate3dsRequest
expiryMonth
integer
The month the card expires. January is 1
MerchantInfoRequest
object
Merchant details provided directly in the request, as an alternative to providing a merchantAcceptorKey.
7 properties 6 required
components-schemas-city
string
The city of the address.
network
string
The card network to query for PAN information. Diners support is EXPERIMENTAL .
expiryYear
integer
The year the card expires including the century
ThreeRiAResWithoutAuthenticationValue
object
The issuer's response to the 3DS request.
ThreeDsNoFlowNoAuth
object
15 properties 10 required
UnsupportedCardNetworkRegionErrorDetails
object
5 properties 5 required
challengeIndicator
string
When set, indicates the preferred 3DS challenge flow as follows: - no-preference: No preference related to the challenge flow. - no-challenge: No challenge flo…
ThreeRiRequestWithMerchantInfo
object
Initiate a 3RI authentication by providing merchant information directly. This allows performing 3RI without requiring merchant acceptor onboarding.
11 properties 5 required
intent
string
The intention of the cardholder.
noAuthFlow
messageCategory
string
Indicates the category of the EMV 3-D Secure message.
ThreeRiARes
object
The issuer's response to the 3DS request.
frictionlessResult
ThreeRiRecurringExpiry
string
The date at which the recurring authorization expires. This property is required for threeRiIndicator = "recurring", "installment", or "standing-order". For ot…
AuthenticationContext
object
Contains data that the issuer needs to perform the fingerprinting, but also optional configuration settings.
2 properties 2 required
ThreeRiRequestWithMerchantAcceptor
object
Initiate a 3RI authentication using an existing merchant acceptor. This requires prior onboarding of the merchant acceptor in the Silverflow system.
11 properties 5 required
ThreeRiResponseWithoutAuthenticationValue
object
13 properties 10 required
acsChallengeMandated
string
Indication of whether a challenge is required for the transaction to be authorized due to local/regional mandates or other variable.
ARes
object
The issuer's response to the 3DS request.
ThreeRiTransStatus
string
Indicates whether a transaction is authenticated or not. - Y indicates authenticated - N indicates not authenticated - R indicates rejected
recurringExpiry
string
The date at which the recurring authorization expires. Format: YYYY-MM-DD. Required when type.order is recurring or installment.
transStatusReason
string
Provides information on why the transStatus field has the specified value.
authenticationValue
string
The result value from the 3DS transaction received from the ACS. This value is no longer present on responses after 45 days have passed after the authenticatio…
acceptorKeyRef
string
Uniquely identifies a merchant acceptor.
activeProtocolVersion
whiteListStatusSource
string
This data element will be populated by the system setting Whitelist Status. Required if Whitelist Status is present.
acsOperatorID
string
DS assigned ACS identifier.
ThreeDs
transactionReference
string
Unique ID assigned by the merchant or payment service provider for the transaction. Used to identify the transaction.
browserJavaEnabled
boolean
The ability of the cardholder browser to execute Java. Value is returned from the navigator.javaEnabled property from the HTML DOM API.
UnknownAmount
object
2 properties 2 required
Card
This field represents the card. The card credentials can either be passed directly in the request or be referenced using a key.
challengeResult
BrowserDataJavascriptEnabledTrue
merchantAcceptorResolver
object
The resolver is used to select the appropriate merchant acceptor for doing the authentication.
1 property 1 required
transStatus
string
Indicates whether a transaction qualifies as an authenticated transaction or account verification.
InternalServerErrorDetails
object
5 properties 5 required
cardEntry
string
The method used to capture the card details.
schemas-InvalidInputErrorDetails
object
6 properties 6 required
dsTransID
string
Universally unique transaction identifier assigned by the DS to identify a single transaction.
fraudLiability
string
Which party is liable in case of fraud.
ThreeRiRequest
RReqWithoutAuthValue
object
This property is only present after the cardholder finished the challenge flow. The RReq message communicates the results of the authentication or verification…
dsReferenceNumber
string
EMVCo-assigned unique identifier to track approved DS.
errorInstance
string
A reference that identifies the specific occurrence of the error. The instance is unique for every error.
localTransactionDateTime
string
Date and time of the transaction in the local timezone.
errorStatus
integer
The HTTP status code generated by the origin server for this occurrence of the problem.
InvalidRequestErrorDetails
object
5 properties 5 required
threedsKey
string
Uniquely identifies a 3DS authentication.
InvalidOffsetTokenErrorDetails
object
5 properties 5 required
authenticationType
string
Indicates the type of authentication method the issuer will use to challenge the cardholder, whether in the ARes message or what was used by the ACS when in th…
TooManyRequestsErrorDetails
object
5 properties 5 required
UnenrolledAcquireOrMerchantErrorDetails
object
5 properties 5 required
AuthenticationRequiredErrorDetails
object
5 properties 5 required
errorDetail
string
A human readable explanation specific to this occurrence of the problem.
ThreeDsType
object
Describes the kind of transaction the merchant wants to submit.
3 properties 3 required
authenticationNetwork
string
The card network that was used for the authentication. It is unknown for entities older than 2024-04-11.
deviceChannel
string
Indicates the type of the interface used to initiate the transaction.
eci
string
Payment system-specific value provided by the ACS or DS to indicate the results of the attempt to authenticate the Cardholder.
schemas-lastModified
string
The date and time this object was last modified.
errorType
string
A relative URI reference, this property can be used to perform automated error handling.
threeDsPage
ThreeRiResponse
object
14 properties 11 required
InputCard
object
Card data
5 properties 3 required
challengeFlow
amountValue
integer
The amount in minor units. For example $12.34 should be encoded as 1234. Note that not all currencies have 2 minor units. Some have three or zero.
UnsupportedCardNetworkErrorDetails
object
5 properties 5 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

silverflow-3ds-authentication-api-openapi.yml Raw ↑

Other APIs Silverflow publishes across the network.

Silverflow Agents API
Silverflow AMMF Submission Events API
Silverflow API Keys API
Silverflow BEP Authentication API
Silverflow Bins API
Silverflow Card Info API
Silverflow Card Management API
Silverflow Card Network Reports API
Silverflow Charge Actions API
Silverflow Charges Events API
Silverflow Charges Reports API
Silverflow Clearing Events API
Where this information came from

This is an independent, third-party profile of Silverflow 3DS Authentication API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.