3DS ReferenceProtocol & field guide

EMV 3-D Secure · Core specification 2.3.1.1

CReq — Challenge Request

The CReq message initiates Cardholder interaction in a Challenge Flow and can be used to carry authentication data from the Cardholder.

Direction 3DS SDK/Browser → ACS

Full message description

The CReq message initiates Cardholder interaction in a Challenge Flow and can be used to carry authentication data from the Cardholder. • App-based—The CReq message is sent by the 3DS SDK. There are two or more CReq messages per challenge as multiple back-and-forth attempts between the ACS and the Cardholder may be required to complete the authentication. • Browser-based—The CReq message is formed by the 3DS Server and is posted through the Cardholder Browser. There is only one CReq message per challenge.

Explore CReq with context filters

22 top-level fields

Baseline inclusion. Effective requirements depend on transaction context. Check the field’s conditions and FAQ qualifications; select channel and category in the explorer.

FieldBaseline inclusion
acsTransIDACS Transaction IDRequired
challengeAddCodeChallenge Additional CodeConditional
challengeCancelChallenge Cancelation IndicatorConditional
challengeDataEntryChallenge Data EntryConditional
challengeDataEntryTwoChallenge Data Entry 2Conditional
challengeHTMLDataEntryChallenge HTML Data EntryConditional
challengeNoEntryChallenge No EntryConditional
challengeWindowSizeChallenge Window SizeRequired
deviceBindingDataEntryDevice Binding Data EntryConditional
infoContinueIndicatorInformation Continuation IndicatorConditional
messageExtensionMessage ExtensionConditional
messageTypeMessage TypeRequired
messageVersionMessage Version NumberRequired
oobAppStatusOOB App StatusConditional
oobAppURLIndOOB App URL IndicatorRequired
oobContinueOOB Continuation IndicatorConditional
resendChallengeResend Challenge Information CodeConditional
sdkCounterStoASDK Counter SDK to ACSRequired
sdkTransIDSDK Transaction IDRequired
threeDSRequestorAppURL3DS Requestor App URLConditional
threeDSServerTransID3DS Server Transaction IDRequired
trustListDataEntryTrust List Data EntryConditional

Source

EMV_3DS_CoreSpec_v2.3.1.1_20230530.pdf · Section 2.4.3, Table B.3

Official EMVCo specifications · Coverage and review limits