3DS ReferenceProtocol & field guide

EMV 3-D Secure · Core specification 2.3.1.1

Challenge Entry Box 2challengeEntryBoxTwo

Challenge Entry Box 2 in Challenge Response (CRes).

Source edition: Core 2.3.1.1 · Type: Object · Length: Variable

Baseline in CRes Conditional

Varies by context. Requirement or applicability varies by channel or message category. Select a specific context to resolve it. Usage and conditions ↓

Explore in context →

Usage in CRes

Defines the setting of an entry box in the Native UI OTP/Text Template: • Challenge Data Entry Keyboard Type • Challenge Data Entry Autofill • Challenge Data Entry Autofill Type • Challenge Data Entry Length Maximum • Challenge Data Entry Label • Challenge Data Entry Masking • Challenge Data Entry Masking Toggle

Conditional inclusion — source text

See Table A.20 for conditions.

Format and scope

Type: Object · Length: Variable

Source components: ACS. Channels: 01-APP. Categories: 01-PA, 02-NPA.

Object members

Nested presence rules apply when the parent is supplied. Consult the source for full conditions.

challengeDataEntryKeyboardType — Challenge Data Entry Keyboard Type

challengeDataEntryAutofill — Challenge Data Entry Autofill

challengeDataEntryAutofillType — Challenge Data Entry Autofill Type

challengeDataEntryLengthMax — Challenge Data Entry Length Maximum

challengeDataEntryLabel — Challenge Data Entry Label

challengeDataEntryMasking — Challenge Data Entry Masking

EMV_3DS_CoreSpec_v2.3.1.1_20230530.pdf, Table A.1, PDF pages 237

Scoped FAQ qualifications

  • FAQ 27 — Applicable object-bearing protocol versions

    Only when the parent JSON object is present

    Evaluate nested presence conditions when the parent object is present. In multiTransaction, merchantList is required when the object is supplied; merchantAmount remains optional.

    EMVCo_3DS_Specification_FAQs_8-April-2026.pdf, page 9

  • FAQ 73 — Applicable object-bearing protocol versions

    An optional or conditionally optional field is sent empty

    An empty optional field produces error 203 under Req 309. When the empty JSON object contains mandatory data, error 201 may be returned.

    EMVCo_3DS_Specification_FAQs_8-April-2026.pdf, page 23

Transaction context

This reference covers the published source edition. Use the explorer to inspect this field and any applicable transaction conditions. Scheme programme requirements are not inferred from the protocol edition.

Explore in context →

Sources and related references

EMV_3DS_CoreSpec_v2.3.1.1_20230530.pdf, Table A.1, PDF pages 237

Source review status: carried-forward. Carried-forward material has not acquired a new verification claim.

Document fingerprint (SHA-256): 6fdf0aba3fc1a765f96b74dad4069d1e189969f38f0023647021687daf589d6b