# Access Control Server

Verestro Access Control Server (ACS) enables issuers to authenticate cardholders in real-time, aiming to reduce online fraud while maintaining an enhanced customer experience. Verestro ACS assesses transaction risk to determine whether to grant a frictionless approval or challenge the user for verification.

This documentation covers the fully certified Verestro ACS SaaS solution, including:

- Authentication Flows: How to implement Frictionless, Challenge (OTP/Biometrics), 3RI, and SPC flows.
- Risk Management: Using the configurable Rule Engine and Admin Panel to define custom rules and review authentication events.
- Integration &amp; Compliance: API integration guides and details on adhering to EMV® 3-D Secure (2.2.0 &amp; 2.3.1) and PSD2 SCA standards.  
      
    https://developer.verestro.com/books/knowledge-center/page/what-is-an-acs-in-the-3ds-ecosystem

# Introduction

# Verestro Access Control Server (ACS) Overview

The **Verestro Access Control Server (ACS)** is an EMVCo-certified software component located within the **Issuer Domain** of the 3-D Secure ecosystem. It functions as the authoritative system for authenticating cardholders during Card-Not-Present (CNP) transactions.

As a fully managed SaaS solution, the Verestro ACS processes authentication requests (AReq) from the Directory Server (DS) and 3DS Server, applies risk logic, and returns the appropriate authentication response (ARes) to the acquirer.

## Technical Scope &amp; Functionality

The ACS is responsible for the complete lifecycle of a 3-D Secure transaction on the issuer side. Its primary technical functions include:

<div class="ProseMirror" contenteditable="true" id="bkmrk-protocol-version-neg" spellcheck="false" translate="no">- **Protocol Version Negotiation:** Automatically determines the highest common version of the EMV 3-D Secure protocol (2.1.0, 2.2.0, 2.3.1) supported by both the issuer and the merchant's 3DS Server.
- **Card Eligibility Validation:** Queries the card range and BIN configurations to confirm if a specific PAN is enrolled in the 3-D Secure program.
- **Device Info Analysis:** Ingests device telemetry and browser data to determine if the consumer's endpoint (User Interface) supports the required security method.
- **Risk-Based Authentication (RBA):** Evaluates transaction data against a configured rule set to determine the authentication method (Frictionless vs. Challenge).
- **Challenge Orchestration:** Manages the step-up authentication interface and logic, including OTP generation/validation, Biometric prompts, and Out-of-Band (OOB) verification.

</div>## Supported Authentication Flows

The Verestro ACS supports the full range of EMV 3-D Secure transaction flows:

<div class="ProseMirror" contenteditable="true" id="bkmrk-frictionless-flow%3A-t" spellcheck="false" translate="no">- **Frictionless Flow:** The ACS assesses the transaction risk as low based on historical data and rules. Access is granted without user interaction.
- **Challenge Flow:** The ACS mandates user interaction via a UI Challenge. Supported methods include SMS OTP, Mobile App OOB, and Biometrics.
- **3RI (Three Requestor Initiated):** Asynchronous authentication initiated by the merchant for recurring billing or installments, without active user participation.
- **SPC (Secure Payment Confirmation):** Leveraging FIDO/WebAuthn standards for cryptographically secure authentication via browser-based biometrics.

</div>## System Architecture &amp; Integration

The solution is architected as a cloud-native SaaS platform, ensuring high availability and compliance without local infrastructure management.

### Rule Engine &amp; Administration

The ACS includes a granular **Rule Engine** allowing administrators to define logic for risk assessment. Authentication decisions are available in the **Admin Panel**, providing detailed audit trails for every transaction (AReq/ARes pairs, Challenge results, and error codes).

### Integration Interface

Integration is achieved via the flexible REST APIs or Verestro LC API.

### Compliance &amp; Security Standards

The platform is certified and compliant with the following specifications:

<div class="ProseMirror" contenteditable="true" id="bkmrk-emv%C2%AE-3-d-secure%3A-ver" spellcheck="false" translate="no">- **EMV® 3-D Secure:** Versions 2.2.0 and 2.3.1
- **Security:** PCI-DSS and PCI 3DS Core Security Standard
- **Regulatory:** PSD2 SCA (Strong Customer Authentication) compliant

</div>

# Overview

ACS by Verestro is a solution designed to address online payment threats. It allows for secure processing of card-not-present transactions, compliant with the latest 3D Secure standards from EMV, ensuring the highest level of security for users and their funds. By using the latest 3DS protocols in version 2.3.x, you can effectively combat financial fraud while maintaining customer convenience in everyday card purchases.

## Terminology

<table border="1" id="bkmrk-name-description-cus" style="border-collapse: collapse; width: 100%; height: 1136.52px;"><tbody><tr style="height: 49.1875px;"><td bgcolor="#1C1E3F" style="width: 21.0858%; height: 49.1875px;" width="353"><span style="color: #ecf0f1;">**Name**</span>  
</td><td bgcolor="#1C1E3F" style="width: 78.8632%; height: 49.1875px;" width="353"><span style="color: #ecf0f1;">**Description**</span>

</td></tr><tr><td style="width: 21.0858%;"><span style="color: #1c1e3f;">3DS Server</span></td><td style="width: 78.8632%;"><span style="color: #1c1e3f;">A 3DS server (3D Secure server) is a software system used in online card payments to manage and secure communication between a merchant and a card's issuing bank. 3DS server is built on the acquirer side.</span></td></tr><tr><td style="width: 21.0858%;"><span style="color: #1c1e3f;">Decoupled authentication</span></td><td style="width: 78.8632%;"><span style="color: #1c1e3f;">Decoupled authentication (often referred to in the context of 3D Secure as decoupled authorization) is a feature in EMV 3DS 2.2+ that separates the customer's identity check from the active checkout session.</span></td></tr><tr><td style="width: 21.0858%;"><span style="color: #1c1e3f;">In app OOB authentication</span></td><td style="width: 78.8632%;"><span style="color: #1c1e3f;">In-app OOB (Out-of-Band) authorization in 3D Secure (3DS) is a secure mobile payment verification method where your banking app approves a purchase on the user device through a separate communication channel.</span></td></tr><tr><td style="width: 21.0858%;"><span style="color: #1c1e3f;">SPC authentication</span></td><td style="width: 78.8632%;"><span style="color: #1c1e3f;">Secure Payment Confirmation (SPC) authorization in 3D Secure (3DS) is a streamlined authentication method that lets customers confirm online card payments using fast device biometrics like a fingerprint or face scan directly from trusted device or WEB browser.</span>

</td></tr><tr style="height: 46.5938px;"><td style="width: 21.0858%; height: 46.5938px;"><span style="color: #1c1e3f;">ACS</span></td><td style="width: 78.8632%; height: 46.5938px;"><span style="color: #1c1e3f;">ACS stands for Access Control Server, which is the central software system operated by a card-issuing bank to authenticate online shoppers.</span></td></tr><tr style="height: 54px;"><td style="width: 21.0858%; height: 54px;"><span style="color: #1c1e3f;">Customer</span></td><td style="width: 78.8632%; height: 54px;"><span style="color: #1c1e3f;">Institution which is using Verestro products. This institution decides which SDK should be used and how transaction should be processed. Basicly Customer can be called Verestro client.</span></td></tr><tr style="height: 46.5938px;"><td style="width: 21.0858%; height: 46.5938px;"><span style="color: #1c1e3f;">Directory Server</span></td><td style="width: 78.8632%; height: 46.5938px;"><span style="color: #1c1e3f;">A Directory Server (DS) in 3-D Secure (3DS) is a central hub managed by card networks (like Mastercard or Visa) that routes authentication messages between online merchants and card-issuing banks.</span></td></tr><tr style="height: 147.188px;"><td style="width: 21.0858%; height: 147.188px;"><span style="color: #1c1e3f;">User</span></td><td style="width: 78.8632%; height: 147.188px;"><span style="color: #1c1e3f;">User which is using Payment Hub Application. It is root of entity tree. User is identified in Wallet Server by some unique identifier which is provided after registration. User can have access to his data and operations based on session. User’s session is created after device pairing is performed. When session expires then user authentication have to be performed. Session is valid 10 minutes, however it is configurable parameter.</span></td></tr><tr style="height: 80px;"><td style="width: 21.0858%; height: 80px;"><span style="color: #1c1e3f;">Card</span></td><td style="width: 78.8632%; height: 80px;"><span style="color: #1c1e3f;">Card belongs to the user. User can have many cards. Card is identified via internal id given after storing card on Wallet Server. Whole PAN is stored on Wallet Server which has PCI DSS certificate.</span></td></tr><tr style="height: 113.594px;"><td style="width: 21.0858%; height: 113.594px;"><span style="color: #1c1e3f;">Device</span></td><td style="width: 78.8632%; height: 113.594px;"><span style="color: #1c1e3f;">Device belongs to user. When user starts using application after installation then device pairing is performed. After pairing device with some unique id, unique device installation id is generated and this installation is assigned to user. It is possible to have one active installation on specific device for specific user.</span></td></tr><tr style="height: 113.594px;"><td style="width: 21.0858%; height: 113.594px;"><span style="color: #1c1e3f;">Session Token</span></td><td style="width: 78.8632%; height: 113.594px;"><span style="color: #1c1e3f;">Token which defines User. It is an authorization way of the User. This entity is created after paring device and this is needed to perform any actions in the application. When session is expired then user authentication needs to be performed. Session is valid 10 minute s, however it is configurable parameter.</span></td></tr><tr style="height: 96.7969px;"><td style="width: 21.0858%; height: 96.7969px;"><span style="color: #1c1e3f;">Acquirer</span></td><td style="width: 78.8632%; height: 96.7969px;"><span style="color: #1c1e3f;">External institution responsible for processing transaction and 3ds requests ordered by the Verestro Payment Hub App. Acquirer connects with banks / card issuers and returns information whether the ordered action on a given card is possible.</span></td></tr><tr style="height: 63.1875px;"><td style="width: 21.0858%; height: 63.1875px;"><span style="color: #1c1e3f;">PAN</span></td><td style="width: 78.8632%; height: 63.1875px;"><span style="color: #1c1e3f;">(Primary Account Number) It is 14-19 (usually 16) digits number which is a unique identifier of the payment card issued to the customer's account.</span></td></tr><tr style="height: 80px;"><td style="width: 21.0858%; height: 80px;"><span style="color: #1c1e3f;">Wallet Server</span></td><td style="width: 78.8632%; height: 80px;"><span style="color: #1c1e3f;">Provides the backend services to support Mobile Payment Application via Verestro Wallet SDK and is responsible for managing users, devices, cards , device tokens, storing transactions history and communication with Acquirers.</span>  
</td></tr><tr style="height: 96.7969px;"><td style="width: 21.0858%; height: 96.7969px;"><span style="color: #1c1e3f;">PCI DSS</span></td><td style="width: 78.8632%; height: 96.7969px;"><span style="color: #1c1e3f;">PCI DSS (Payment Card Industry Data Security Standard) is a security standard used in environments where the data of payment cardholders is processed. The standard covers meticulous data processing control and protection of users against violations.</span></td></tr><tr style="height: 113.594px;"><td style="width: 21.0858%; height: 113.594px;"><span style="color: #1c1e3f;">PCI 3DS</span></td><td style="width: 78.8632%; height: 113.594px;"><span style="color: #1c1e3f;">PCI 3DS (Payment Card Industry 3-D Secure) is a security standard and protocol designed to add an extra layer of authentication for online and card-not-present (CNP) payment transactions</span>

</td></tr><tr><td style="width: 21.0858%;"><span style="color: #1c1e3f;">Partner</span></td><td style="width: 78.8632%;"><span style="color: #1c1e3f;">Wherever this document refers to the Partner, it refers to your company and your IT infrastructure, depending on the context.</span>

</td></tr></tbody></table>

## <span style="color: #1c1e3f;">Integration Methods</span>

<span style="color: #1c1e3f;">Regardless of whether you already have card issuance implemented or are starting from scratch, Verestro's ACS is able to flexibly adapt the deployment model for you. </span>

#### <span style="color: #1c1e3f;">1. Integration with a bank/processor</span>

<span style="color: #1c1e3f;">We will redirect verification and authorization requests, as well as generated IAVs, to you.  
</span>

[![image.png](https://developer.verestro.com/uploads/images/gallery/2026-08/scaled-1680-/dy3image.png)](https://developer.verestro.com/uploads/images/gallery/2026-08/dy3image.png)

#### <span style="color: #1c1e3f;">2. Verestro API</span>

<span style="color: #1c1e3f;">With full PCI DSS / PCI 3DS certification, Verestro enables secure storage and management of cards on our servers; in this model, you feed the Verestro system with your cards and receive an IAV, while authorization takes place directly between Verestro and the user.  
</span>

[![image.png](https://developer.verestro.com/uploads/images/gallery/2026-08/scaled-1680-/L2dimage.png)](https://developer.verestro.com/uploads/images/gallery/2026-08/L2dimage.png)

#### <span style="color: #1c1e3f;">3. Full core banking and processing solution from Verestro</span>

<span style="color: #1c1e3f;">Verestro is able to provide a complete platform through which you can acquire a user, register them, create an account for them, and issue them a card, including processing transactions using the most advanced methods available on the market.   
</span>

[![image.png](https://developer.verestro.com/uploads/images/gallery/2026-08/scaled-1680-/DXhimage.png)](https://developer.verestro.com/uploads/images/gallery/2026-08/DXhimage.png)

## <span style="color: #1c1e3f;">High-level structure of Verestro's ACS</span>

<span style="color: #1c1e3f;">Verestro's system architecture is based on microservices, which makes it possible to tailor the integration precisely to clients' needs.</span>

<span style="color: #1c1e3f;">  
</span>[![image.png](https://developer.verestro.com/uploads/images/gallery/2026-08/scaled-1680-/qDXimage.png)](https://developer.verestro.com/uploads/images/gallery/2026-08/qDXimage.png)

##### <span style="color: #1c1e3f;">Administrative Panel</span>

<span style="color: #1c1e3f;">the basic interface through which you gain access to the full ACS configuration and real-time monitoring of its operation, making it an excellent support tool  
</span>

##### <span style="color: #1c1e3f;">Notification Service</span>

<span style="color: #1c1e3f;">The service through which the ACS sends messages to users. The Notification Service allows the configuration of multiple communication channels depending on your needs - SMS, email, server-to-server connection, and others.  
</span>

##### <span style="color: #1c1e3f;">ACS</span>

<span style="color: #1c1e3f;">(Access Control Service) the main service processing 3D Secure authorizations, holding PCI 3DS and EMV certification. This is where all data is verified, the appropriate authorization path is selected, and the IAV is generated, which is attached to the transaction authorization object.  
</span>

##### <span style="color: #1c1e3f;">Risk Engine</span>

<span style="color: #1c1e3f;">a tool used by the ACS when selecting the appropriate authorization path; this is where the full configuration of rules, exceptions, and whitelists and blacklists resides.  
</span>

##### <span style="color: #1c1e3f;">Mobile SDK</span>

<span style="color: #1c1e3f;">an optional element, a library prepared by Verestro ready for integration into an application on the user's mobile device. The SDK enables secure communication and provides the ability to perform IN APP OOB authorization  
</span>

##### <span style="color: #1c1e3f;">VIPP</span>

<span style="color: #1c1e3f;">(Verestro Issuing Processing Platform) an optional element through which Verestro is able to deliver a complete solution, from card generation through 3DS verification to transaction authorization.  
</span>

##### <span style="color: #1c1e3f;">Data Core</span>

<span style="color: #1c1e3f;">an optional central service, holding full PCI DSS certification, used to store user data and their cards used in the 3DS authorization process</span>

## Configuration

The basic parameter that is part of every ACS configuration is the BIN and its range. Depending on the Partner's preferences, the available authorization methods, their channels, the appearance and content of 3DS templates are defined for a given range, and the parameters according to which the Risk Engine will make decisions regarding the authorization path are configured. The basic tool available to the partner is the Administrative Panel, through which they gain access to the entire ACS solution and all its components.

##### <span style="color: #1c1e3f;">Card Program</span>

<span style="color: #1c1e3f;">The basic configuration element within which we define the BIN range to which challenge profiles and risk profiles will be assigned. </span>

[![image.png](https://developer.verestro.com/uploads/images/gallery/2026-08/scaled-1680-/DFAimage.png)](https://developer.verestro.com/uploads/images/gallery/2026-08/DFAimage.png)

##### <span style="color: #1c1e3f;">Challenge profile</span>

<span style="color: #1c1e3f;">here we define the parameters according to which authorizations will be carried out, including their configuration (OTP, IN APP, DECOUPLED, SPC), as well as the design of the authorization screen template itself</span>

[![image.png](https://developer.verestro.com/uploads/images/gallery/2026-08/scaled-1680-/Co5image.png)](https://developer.verestro.com/uploads/images/gallery/2026-08/Co5image.png)

[![image.png](https://developer.verestro.com/uploads/images/gallery/2026-08/scaled-1680-/xY7image.png)](https://developer.verestro.com/uploads/images/gallery/2026-08/xY7image.png)

##### <span style="color: #1c1e3f;">Risk profile</span>

<span style="color: #1c1e3f;">Configuration of the parameters according to which authorization paths are selected, including MCC code whitelists/blacklists, geolocation, as well as low-value transaction thresholds.</span>

[![image.png](https://developer.verestro.com/uploads/images/gallery/2026-08/scaled-1680-/YnCimage.png)](https://developer.verestro.com/uploads/images/gallery/2026-08/YnCimage.png)

## <span style="color: #1c1e3f;">Security</span>

Deployments in which we integrate Server-to-Server require the use of the following security measures:

#### Connectivity Architecture

##### Issuer → ACS

- **Protocol:** HTTPS (TLS 1.2+)
- **Authentication:** Mutual TLS (X.509)
- **Issuer Role:** Client
- **ACS Role:** Server
- **Certificate Usage:**
    
    
    - The Issuer presents a client certificate signed by a Verestro CA.
    - ACS validates the Issuer's certificate against its trust store.
    - ACS authenticates the Issuer

##### ACS → Issuer

- **Protocol:** HTTPS (TLS 1.2+)
- **Authentication:** Mutual TLS (X.509)
- **ACS Role:** Client
- **Issuer Role:** Server
- **Certificate Usage:**
    
    
    - ACS presents its client certificate.
    - The Issuer validates ACS’s certificate against its trust store.
    - The Issuer authenticates ACS

#### Certificate Generation and Use

<div class="_tableWrapper_16hzy_14 group flex w-fit flex-col-reverse" id="bkmrk--8" tabindex="-1"></div><div class="_tableContainer_16hzy_1" id="bkmrk-certificate-type-gen"><div class="_tableWrapper_16hzy_14 group flex w-fit flex-col-reverse" tabindex="-1"><table class="w-fit min-w-(--thread-content-width)" data-end="1500" data-start="366" style="width: 100%;"><thead data-end="552" data-start="366"><tr data-end="552" data-start="366"><th data-col-size="sm" data-end="405" data-start="366" style="width: 22.646%;">Certificate Type</th><th data-col-size="sm" data-end="427" data-start="405" style="width: 12.3957%;">Generated By</th><th data-col-size="sm" data-end="447" data-start="427" style="width: 9.53516%;">Signed By</th><th data-col-size="sm" data-end="474" data-start="447" style="width: 9.17646%;">Used By</th><th data-col-size="md" data-end="552" data-start="474" style="width: 46.2467%;">Purpose(s)</th></tr></thead><tbody data-end="1500" data-start="743"><tr data-end="931" data-start="743"><td data-col-size="sm" data-end="782" data-start="743" style="width: 22.646%;">**Client Certificate (Issuer)**</td><td data-col-size="sm" data-end="805" data-start="782" style="width: 12.3957%;">Issuer</td><td data-col-size="sm" data-end="826" data-start="805" style="width: 9.53516%;">Verestro</td><td data-col-size="sm" data-end="854" data-start="826" style="width: 9.17646%;">Issuer</td><td data-col-size="md" data-end="931" data-start="854" style="width: 46.2467%;">X.509 mTLS authentication (Issuer → Verestro)</td></tr><tr data-end="1120" data-start="932"><td data-col-size="sm" data-end="971" data-start="932" style="width: 22.646%;"> </td><td data-col-size="sm" data-end="994" data-start="971" style="width: 12.3957%;"> </td><td data-col-size="sm" data-end="1015" data-start="994" style="width: 9.53516%;"> </td><td data-col-size="sm" data-end="1043" data-start="1015" style="width: 9.17646%;">Verestro/Issuer</td><td data-col-size="md" data-end="1120" data-start="1043" style="width: 46.2467%;">JWE. Verestro uses the public key from this certificate to encrypt sensitive fields (e.g., card number) in requests. The Issuer uses the private key from this certificate to decrypt sensitive fields</td></tr><tr data-end="1311" data-start="1121"><td data-col-size="sm" data-end="1162" data-start="1121" style="width: 22.646%;">**Client Certificate (Verestro)**</td><td data-col-size="sm" data-end="1185" data-start="1162" style="width: 12.3957%;">Verestro</td><td data-col-size="sm" data-end="1206" data-start="1185" style="width: 9.53516%;">Issuer</td><td data-col-size="sm" data-end="1234" data-start="1206" style="width: 9.17646%;">Verestro</td><td data-col-size="md" data-end="1311" data-start="1234" style="width: 46.2467%;">X.509 mTLS authentication (Verestro → Issuer)</td></tr><tr data-end="1500" data-start="1312"><td data-col-size="sm" data-end="1351" data-start="1312" style="width: 22.646%;"> </td><td data-col-size="sm" data-end="1374" data-start="1351" style="width: 12.3957%;"> </td><td data-col-size="sm" data-end="1395" data-start="1374" style="width: 9.53516%;"> </td><td data-col-size="sm" data-end="1423" data-start="1395" style="width: 9.17646%;">Issuer/ Verestro</td><td data-col-size="md" data-end="1500" data-start="1423" style="width: 46.2467%;">JWE. The Issuer uses the public key from this certificate to encrypt sensitive fields (e.g., card number) in requests. Verestro uses the private key from this certificate to decrypt sensitive fields</td></tr></tbody></table>

</div><div class="_tableWrapper_16hzy_14 group flex w-fit flex-col-reverse" tabindex="-1">  
</div><div class="_tableWrapper_16hzy_14 group flex w-fit flex-col-reverse" tabindex="-1">**Note:** While the same certificate pair may be used for both mTLS and JWE, it's **recommended** to use **separate certificates** for TLS and field-level encryption for improved security and certificate lifecycle management.</div></div>#### Certificate Requirements

- **Format:** X.509
- **Key Length:** RSA 2048-bit or higher
- **Validity:** Minimum 1 year validity recommended

Check the following document on how to create a client certificate:

[https://developer.verestro.com/books/connecting-to-our-services-and-sandbox/page/connecting-to-server-to-server-apis-fe-sandbox](https://developer.verestro.com/books/connecting-to-our-services-and-sandbox/page/connecting-to-server-to-server-apis-fe-sandbox)

#### Field-Level Encryption

Certain sensitive fields (e.g., `cardNumber`) are encrypted using JWE (JSON Web Encryption) to provide end-to-end protection beyond TLS.

#### JWE Encryption Details

Data is encrypted using JWE per RFC 7516 ([https://tools.ietf.org/html/rfc7516)](https://tools.ietf.org/html/rfc7516))

<div class="table-wrap" id="bkmrk-jwe-header-name-desc"><table class="confluenceTable tablesorter tablesorter-default stickyTableHeaders" role="grid"><colgroup><col></col><col></col><col></col></colgroup><thead class="tableFloatingHeaderOriginal"><tr class="tablesorter-headerRow" role="row"><th aria-disabled="false" aria-label="JWE header: No sort applied, activate to apply an ascending sort" aria-sort="none" class="confluenceTh tablesorter-header sortableHeader tablesorter-headerUnSorted" data-column="0" role="columnheader" scope="col" tabindex="0">JWE header

</th><th aria-disabled="false" aria-label="Name: No sort applied, activate to apply an ascending sort" aria-sort="none" class="confluenceTh tablesorter-header sortableHeader tablesorter-headerUnSorted" data-column="1" role="columnheader" scope="col" tabindex="0">Name

</th><th aria-disabled="false" aria-label="Description: No sort applied, activate to apply an ascending sort" aria-sort="none" class="confluenceTh tablesorter-header sortableHeader tablesorter-headerUnSorted" data-column="2" role="columnheader" scope="col" tabindex="0">Description

</th></tr></thead><tbody aria-live="polite" aria-relevant="all"><tr role="row"><td class="confluenceTd">alg

</td><td class="confluenceTd">RSA-OAEP-256

</td><td class="confluenceTd">Cryptographic algorithm used to encrypt CEK

</td></tr><tr role="row"><td class="confluenceTd">enc

</td><td class="confluenceTd">A256GCM

</td><td class="confluenceTd">Identifies the content encryption algorithm used to perform authenticated encryption

</td></tr></tbody></table>

</div>- **Algorithm:** RSA-OAEP-256
- **Content Encryption:** A256GCM
- **Key Material:** Derived from or aligned with the public key in the X.509 certificate
- **Envelope Format:** Compact JWE serialization

#### Encrypted Fields

<div class="_tableContainer_16hzy_1" id="bkmrk-field-location-requi"><div class="_tableWrapper_16hzy_14 group flex w-fit flex-col-reverse" tabindex="-1"><table class="w-fit min-w-(--thread-content-width)" data-end="2563" data-start="2352"><thead data-end="2403" data-start="2352"><tr data-end="2403" data-start="2352"><th data-col-size="sm" data-end="2367" data-start="2352">Field</th><th data-col-size="sm" data-end="2382" data-start="2367">Location</th><th data-col-size="sm" data-end="2403" data-start="2382">Requirement</th></tr></thead><tbody data-end="2563" data-start="2456"><tr data-end="2507" data-start="2456"><td data-col-size="sm" data-end="2471" data-start="2456">`encryptedCardNumber`

</td><td data-col-size="sm" data-end="2486" data-start="2471">JSON Payload</td><td data-col-size="sm" data-end="2507" data-start="2486">Must be encrypted</td></tr><tr data-end="2563" data-start="2508"><td data-col-size="sm" data-end="2523" data-start="2508">`encryptedCVC`</td><td data-col-size="sm" data-end="2538" data-start="2523">JSON Payload</td><td data-col-size="sm" data-end="2563" data-start="2538">Must be encrypted if present</td></tr></tbody></table>

</div></div>## Authentication Flows

Below are the paths and their variants according to which 3D Secure authorization requests are processed:

#### Frictionless

Used for lists of trusted merchants, devices, low-value transactions, and others for which the Risk Engine allows authorization without additional user involvement in the process.

@startuml  
skinparam ParticipantPadding 30  
skinparam BoxPadding 30  
skinparam noteFontColor #FFFFFF  
skinparam noteBackgroundColor #1C1E3F  
skinparam noteBorderColor #1C1E3F  
skinparam noteBorderThickness 1  
skinparam sequence {  
ArrowColor #1C1E3F  
ArrowFontColor #1C1E3F  
ActorBorderColor #1C1E3F  
ActorBackgroundColor #FFFFFF  
ActorFontStyle bold  
ParticipantBorderColor #1C1E3F  
ParticipantBackgroundColor #1C1E3F  
ParticipantFontColor #FFFFFF  
ParticipantFontStyle bold  
LifeLineBackgroundColor #1C1E3F  
LifeLineBorderColor #1C1E3F  
}  
title Authentication via Frictionless (no challenge required)  
actor "Cardholder\\nbrowser &amp; phone" as Cardholder  
participant "Merchant\\n3DS Server" as Merchant  
participant "Directory Server\\ncard scheme" as DS  
participant "Verestro ACS\\nAccess Control Server" as ACS  
participant "Issuer" as Issuer  
note over Issuer  
Card systems  
end note  
Cardholder -&gt; Merchant: Pay with card  
activate Merchant  
Merchant -&gt; DS: Authenticate \\n(AReq)  
activate DS  
DS -&gt; ACS: Route to ACS \\n(AReq)  
activate ACS  
ACS -&gt; Issuer: Card verification \\n(API)  
activate Issuer  
ACS &lt;-- Issuer: Card active - not blocked (ACTIVE)  
deactivate Issuer  
ACS -&gt; ACS: RISK ENGINE \\nDECISION: FRICTIONLESS \\n(trusted merchant / device / low-value)  
note over Cardholder, Issuer #1C1E3F  
No challenge is presented to the cardholder -  
authentication result is returned immediately  
end note  
ACS -&gt; Issuer: IAV authenticationValue  
ACS &lt;-- Issuer: Acknowledged  
DS &lt;-- ACS: Authentication result \\n(ARes) \[transStatus=Y\] \\nIAV authenticationValue  
Merchant &lt;-- DS: Authentication result \\n(ARes) \[transStatus=Y\] \\nIAV authenticationValue  
deactivate DS  
deactivate ACS  
Cardholder &lt;-- Merchant: Transaction authorized  
deactivate Merchant  
@enduml

#### Challenge

The most commonly used path, requiring the user to authorize the transaction via the methods available to them (OTP, in APP, bio).

##### SMS OTP

@startuml  
skinparam ParticipantPadding 30  
skinparam BoxPadding 30  
skinparam noteFontColor #FFFFFF  
skinparam noteBackgroundColor #1C1E3F  
skinparam noteBorderColor #1C1E3F  
skinparam noteBorderThickness 1  
skinparam sequence {  
ArrowColor #1C1E3F  
ArrowFontColor #1C1E3F  
ActorBorderColor #1C1E3F  
ActorBackgroundColor #FFFFFF  
ActorFontStyle bold  
ParticipantBorderColor #1C1E3F  
ParticipantBackgroundColor #1C1E3F  
ParticipantFontColor #FFFFFF  
ParticipantFontStyle bold  
LifeLineBackgroundColor #1C1E3F  
LifeLineBorderColor #1C1E3F  
}  
title Authentication via SMS OTP with the ability to select the method by the user  
actor "Cardholder\\nbrowser &amp; phone" as Cardholder  
participant "Merchant\\n3DS Server" as Merchant  
participant "Directory Server\\ncard scheme" as DS  
participant "Verestro ACS\\nAccess Control Server" as ACS  
participant "Issuer" as Issuer  
note over Issuer  
Card systems  
Mobile app  
end note  
Cardholder -&gt; Merchant: Pay with card  
activate Merchant  
Merchant -&gt; DS: Authenticate \\n(AReq)  
activate DS  
DS -&gt; ACS: Route to ACS \\n(AReq)  
activate ACS  
ACS -&gt; Issuer: Card verification \\n(API)  
activate Issuer  
ACS &lt;-- Issuer: Card active - not blocked (ACTIVE)  
ACS -&gt; ACS: RISK ENGINE \\nDECISION: CHALLENGE  
DS &lt;-- ACS: Challenge required \\n(ARes) \[transStatus=C\]  
Merchant &lt;-- DS: Challenge required \\n(ARes)  
Cardholder -&gt; ACS: Open challenge \\n(CReq)  
Cardholder &lt;-- ACS: Authentication methods \\n(CRes)  
Cardholder -&gt; ACS: Method: SMS OTP \\n(CReq)  
ACS -&gt; Issuer: Send one-time code \\n(SMS)  
deactivate Issuer  
Cardholder -&gt; ACS: Code submitted \\n(CReq)  
Cardholder &lt;-- ACS: Challenge complete \\n(CRes)  
ACS -&gt; Issuer: Final result \\n(RReq) \[transStatus=Y\] \\nIAV authenticationValue  
ACS &lt;-- Issuer: Acknowledged \\n(RRes)  
ACS -&gt; DS: Final result \\n(RReq) \[transStatus=Y\] \\nIAV authenticationValue  
DS -&gt; Merchant: Final result \\n(RReq) \[transStatus=Y\] \\nIAV authenticationValue  
DS &lt;-- Merchant: Acknowledged \\n(RRes)  
deactivate Merchant  
ACS &lt;-- DS: Acknowledged \\n(RRes)  
deactivate DS  
deactivate ACS  
deactivate Merchant  
@enduml

##### IN APP OOB

@startuml  
skinparam ParticipantPadding 30  
skinparam BoxPadding 30  
skinparam noteFontColor #FFFFFF  
skinparam noteBackgroundColor #1C1E3F  
skinparam noteBorderColor #1C1E3F  
skinparam noteBorderThickness 1  
skinparam sequence {  
ArrowColor #1C1E3F  
ArrowFontColor #1C1E3F  
ActorBorderColor #1C1E3F  
ActorBackgroundColor #FFFFFF  
ActorFontStyle bold  
ParticipantBorderColor #1C1E3F  
ParticipantBackgroundColor #1C1E3F  
ParticipantFontColor #FFFFFF  
ParticipantFontStyle bold  
LifeLineBackgroundColor #1C1E3F  
LifeLineBorderColor #1C1E3F  
}  
title Authentication via IN APP OOB with the ability to select the method by the user  
actor "Cardholder\\nbrowser &amp; phone" as Cardholder  
participant "Merchant\\n3DS Server" as Merchant  
participant "Directory Server\\ncard scheme" as DS  
participant "Verestro ACS\\nAccess Control Server" as ACS  
participant "Issuer" as Issuer  
note over Issuer  
Card systems  
Mobile app  
end note  
Cardholder -&gt; Merchant: Pay with card  
activate Merchant  
Merchant -&gt; DS: Authenticate \\n(AReq)  
activate DS  
DS -&gt; ACS: Route to ACS \\n(AReq)  
activate ACS  
ACS -&gt; Issuer: Card verification \\n(API)  
activate Issuer  
ACS &lt;-- Issuer: Card active - not blocked (ACTIVE)  
ACS -&gt; ACS: RISK ENGINE \\nDECISION: CHALLENGE  
DS &lt;-- ACS: Challenge required \\n(ARes) \[transStatus=C\]  
Merchant &lt;-- DS: Challenge required \\n(ARes)  
deactivate DS  
Cardholder -&gt; ACS: Open challenge \\n(CReq)  
Cardholder &lt;-- ACS: Authentication methods \\n(CRes)  
Cardholder -&gt; ACS: Method: mobile app \\n(CReq)  
ACS -&gt; Issuer: Push notification \\n(OOB)  
ACS &lt;-- Issuer: Confirmed by cardholder \\n(OOB)  
deactivate Issuer  
Cardholder &lt;-- ACS: Challenge complete \\n(CRes)  
ACS -&gt; Issuer: Final result \\n(RReq) \[transStatus=Y\] \\nIAV authenticationValue  
activate Issuer  
ACS &lt;-- Issuer: Acknowledged \\n(RRes)  
deactivate Issuer  
ACS -&gt; DS: Final result \\n(RReq) \[transStatus=Y\] \\nIAV authenticationValue  
activate DS  
DS -&gt; Merchant: Final result \\n(RReq) \[transStatus=Y\] \\nIAV authenticationValue  
DS &lt;-- Merchant: Acknowledged \\n(RRes)  
deactivate Merchant  
ACS &lt;-- DS: Acknowledged \\n(RRes)  
deactivate DS  
deactivate Merchant  
@enduml

##### DECOUPLED

@startuml  
skinparam ParticipantPadding 30  
skinparam BoxPadding 30  
skinparam noteFontColor #FFFFFF  
skinparam noteBackgroundColor #1C1E3F  
skinparam noteBorderColor #1C1E3F  
skinparam noteBorderThickness 1  
skinparam sequence {  
ArrowColor #1C1E3F  
ArrowFontColor #1C1E3F  
ActorBorderColor #1C1E3F  
ActorBackgroundColor #FFFFFF  
ActorFontStyle bold  
ParticipantBorderColor #1C1E3F  
ParticipantBackgroundColor #1C1E3F  
ParticipantFontColor #FFFFFF  
ParticipantFontStyle bold  
LifeLineBackgroundColor #1C1E3F  
LifeLineBorderColor #1C1E3F  
}  
title Authentication via Decoupled (asynchronous, no browser challenge window)  
actor "Cardholder\\nbrowser &amp; phone" as Cardholder  
participant "Merchant\\n3DS Server" as Merchant  
participant "Directory Server\\ncard scheme" as DS  
participant "Verestro ACS\\nAccess Control Server" as ACS  
participant "Issuer" as Issuer  
note over Issuer  
Card systems  
Mobile app  
end note  
Cardholder -&gt; Merchant: Pay with card  
activate Merchant  
Merchant -&gt; DS: Authenticate \\n(AReq) \[decoupledRequestInd=Y\]  
activate DS  
DS -&gt; ACS: Route to ACS \\n(AReq)  
activate ACS  
ACS -&gt; Issuer: Card verification \\n(API)  
activate Issuer  
ACS &lt;-- Issuer: Card active - not blocked (ACTIVE)  
ACS -&gt; ACS: RISK ENGINE \\nDECISION: DECOUPLED CHALLENGE  
DS &lt;-- ACS: Challenge required \\n(ARes) \[transStatus=D\]  
Merchant &lt;-- DS: Challenge required \\n(ARes) \[transStatus=D\]  
deactivate Merchant  
deactivate DS  
note over Cardholder, Merchant #1C1E3F  
No CReq/CRes exchange with the browser -  
authentication continues out of band in the mobile app  
end note  
ACS -&gt; Issuer: Push notification \\n(OOB)  
Cardholder &lt;-- Issuer: Authentication request \\n(mobile app)  
Cardholder -&gt; Issuer: Confirmed by cardholder \\n(mobile app)  
ACS &lt;-- Issuer: Confirmed by cardholder \\n(OOB)  
deactivate Issuer  
ACS -&gt; Issuer: Final result \\n(RReq) \[transStatus=Y\]  
activate Issuer  
ACS &lt;-- Issuer: Acknowledged \\n(RRes)  
deactivate Issuer  
deactivate ACS  
...decoupled max time / merchant polling...  
Merchant -&gt; DS: Results request \\n(RReq)  
activate Merchant  
activate DS  
DS -&gt; ACS: Route RReq  
activate ACS  
DS &lt;-- ACS: Final result \\n(RRes) \[transStatus=Y\] \\nIAV authenticationValue  
deactivate ACS  
Merchant &lt;-- DS: Final result \\n(RRes) \[transStatus=Y\] \\nIAV authenticationValue  
deactivate DS  
deactivate ACS  
deactivate Merchant  
@enduml

##### SPC

@startuml  
skinparam ParticipantPadding 30  
skinparam BoxPadding 30  
skinparam noteFontColor #FFFFFF  
skinparam noteBackgroundColor #1C1E3F  
skinparam noteBorderColor #1C1E3F  
skinparam noteBorderThickness 1  
skinparam sequence {  
ArrowColor #1C1E3F  
ArrowFontColor #1C1E3F  
ActorBorderColor #1C1E3F  
ActorBackgroundColor #FFFFFF  
ActorFontStyle bold  
ParticipantBorderColor #1C1E3F  
ParticipantBackgroundColor #1C1E3F  
ParticipantFontColor #FFFFFF  
ParticipantFontStyle bold  
LifeLineBackgroundColor #1C1E3F  
LifeLineBorderColor #1C1E3F  
}  
title Authentication via SPC (Secure Payment Confirmation)  
actor "Cardholder\\nbrowser &amp; phone" as Cardholder  
participant "Merchant\\n3DS Server" as Merchant  
participant "Directory Server\\ncard scheme" as DS  
participant "Verestro ACS\\nAccess Control Server" as ACS  
participant "Issuer" as Issuer  
note over Issuer  
Card systems  
Credential registry  
end note  
Cardholder -&gt; Merchant: Pay with card  
activate Merchant  
Merchant -&gt; DS: Authenticate \\n(AReq)  
activate DS  
DS -&gt; ACS: Route to ACS \\n(AReq)  
activate ACS  
ACS -&gt; Issuer: Card verification \\n(API)  
activate Issuer  
ACS &lt;-- Issuer: Card active - not blocked (ACTIVE)  
ACS -&gt; ACS: RISK ENGINE \\nDECISION: CHALLENGE (SPC supported)  
DS &lt;-- ACS: Challenge required \\n(ARes) \[transStatus=C\]  
Merchant &lt;-- DS: Challenge required \\n(ARes)  
deactivate DS  
Cardholder -&gt; ACS: Open challenge \\n(CReq)  
Cardholder &lt;-- ACS: SPC credential request \\n(CRes) \[WebAuthn options\]  
note over Cardholder #1C1E3F  
Browser invokes the platform authenticator -  
cardholder confirms with biometrics / device PIN  
(no OTP, no separate mobile app)  
end note  
Cardholder -&gt; Cardholder: Local WebAuthn \\nauthenticator ceremony  
Cardholder -&gt; ACS: SPC assertion \\n(CReq) \[signed WebAuthn response\]  
ACS -&gt; Issuer: Verify assertion \\n(API)  
ACS &lt;-- Issuer: Assertion verified (ACTIVE)  
deactivate Issuer  
Cardholder &lt;-- ACS: Challenge complete \\n(CRes)  
ACS -&gt; Issuer: Final result \\n(RReq) \[transStatus=Y\] \\nIAV authenticationValue  
activate Issuer  
ACS &lt;-- Issuer: Acknowledged \\n(RRes)  
deactivate Issuer  
ACS -&gt; DS: Final result \\n(RReq) \[transStatus=Y\] \\nIAV authenticationValue  
activate DS  
DS -&gt; Merchant: Final result \\n(RReq) \[transStatus=Y\] \\nIAV authenticationValue  
DS &lt;-- Merchant: Acknowledged \\n(RRes)  
deactivate Merchant  
ACS &lt;-- DS: Acknowledged \\n(RRes)  
deactivate DS  
deactivate ACS  
@enduml

##### Declined

An authorization that ends in failure due to its absence, a failed attempt, or the fulfillment of criteria flagged by the Risk Engine.

@startuml  
skinparam ParticipantPadding 30  
skinparam BoxPadding 30  
skinparam noteFontColor #FFFFFF  
skinparam noteBackgroundColor #1C1E3F  
skinparam noteBorderColor #1C1E3F  
skinparam noteBorderThickness 1  
skinparam sequence {  
ArrowColor #1C1E3F  
ArrowFontColor #1C1E3F  
ActorBorderColor #1C1E3F  
ActorBackgroundColor #FFFFFF  
ActorFontStyle bold  
ParticipantBorderColor #1C1E3F  
ParticipantBackgroundColor #1C1E3F  
ParticipantFontColor #FFFFFF  
ParticipantFontStyle bold  
LifeLineBackgroundColor #1C1E3F  
LifeLineBorderColor #1C1E3F  
}  
title Authentication via Declined (authorization ends in failure)  
actor "Cardholder\\nbrowser &amp; phone" as Cardholder  
participant "Merchant\\n3DS Server" as Merchant  
participant "Directory Server\\ncard scheme" as DS  
participant "Verestro ACS\\nAccess Control Server" as ACS  
participant "Issuer" as Issuer  
note over Issuer  
Card systems  
Mobile app  
end note  
Cardholder -&gt; Merchant: Pay with card  
activate Merchant  
Merchant -&gt; DS: Authenticate \\n(AReq)  
activate DS  
DS -&gt; ACS: Route to ACS \\n(AReq)  
activate ACS  
ACS -&gt; Issuer: Card verification \\n(API)  
activate Issuer  
ACS &lt;-- Issuer: Card verification result  
deactivate Issuer  
alt Blocked by Risk Engine \\nrules or unavailable \\ncard data  
ACS -&gt; ACS: RISK ENGINE \\nDECISION: DECLINED \\n(MCC / geolocation blacklist, blocked card, missing data)  
note over Cardholder, Issuer #1C1E3F  
No challenge is presented -  
transaction is rejected immediately  
end note  
DS &lt;-- ACS: Authentication result \\n(ARes) \[transStatus=N\]  
Merchant &lt;-- DS: Authentication result \\n(ARes) \[transStatus=N\]  
else Challenge required but \\n authentication fails  
ACS -&gt; ACS: RISK ENGINE \\nDECISION: CHALLENGE  
DS &lt;-- ACS: Challenge required \\n(ARes) \[transStatus=C\]  
Merchant &lt;-- DS: Challenge required \\n(ARes)  
Cardholder -&gt; ACS: Open challenge \\n(CReq)  
Cardholder &lt;-- ACS: Authentication methods \\n(CRes)  
Cardholder -&gt; ACS: Method: mobile app \\n(CReq)  
ACS -&gt; Issuer: Push notification \\n(OOB)  
activate Issuer  
ACS &lt;-- Issuer: Rejected / timed out by cardholder \\n(OOB)  
deactivate Issuer  
Cardholder &lt;-- ACS: Challenge failed \\n(CRes)  
ACS -&gt; Issuer: Final result \\n(RReq) \[transStatus=N\]  
activate Issuer  
ACS &lt;-- Issuer: Acknowledged \\n(RRes)  
deactivate Issuer  
DS &lt;-- ACS: Final result \\n(RRes) \[transStatus=N\]  
deactivate ACS  
Merchant &lt;-- DS: Final result \\n(RRes) \[transStatus=N\]  
deactivate DS  
end  
Cardholder &lt;-- Merchant: Transaction declined  
deactivate Merchant  
@enduml

<div class="_tableContainer_16hzy_1" id="bkmrk--9"></div>

# Your APIs for us - Issuer

## Issuer API

---

 @swagger="https://s3.verestro.dev/valinor-public/acs\_docs/issuer-api-v1\_0.yaml"

# Technical Documentation

## ACS API

---

 @swagger="https://s3.verestro.dev/valinor-public/acs\_docs/acs-api-v1\_0.yaml"