Cards & Wallets · Your payment page

Payment

Submit a customer payment directly from your server or application. A Payment request authorises and captures the funds for settlement in a single step.

The request is sent to POST /acceptor/rest/transactions/{instId}/payment. It can be used for e-commerce, MOTO and other cardholder-not-present channels, and can be configured to use 3D Secure for customer authentication.

You can pay with raw card details, a CardLock token or a saved payment method token. The response contains the transactionId, the status and the result of any AVS and CV2 checks performed by the authoriser.

Guest payment

The example below shows a payment for a customer whose details you do not intend to store.

Payment without customer (guest payment)
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payment
Request body
{
    "transaction": {
        "currency": "GBP",
        "amount": 25.00,
        "merchantRef": "TXN-0001",
        "description": "Sample Payment",
        "commerceType": "ECOM"
    },
    "paymentMethod": {
        "card": {
            "pan": "9900000000000010",
            "expiryDate": "1229",
            "cv2": "123",
            "cardHolderName": "John Smith"
        },
        "billingAddress": {
            "line1": "1 Some Street",
            "city": "Metropolis",
            "postcode": "AA1 2BB",
            "countryCode": "GBR"
        }
    }
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
    "transaction": {
        "currency": "GBP",
        "amount": 25.00,
        "merchantRef": "TXN-0001",
        "description": "Sample Payment",
        "commerceType": "ECOM"
    },
    "paymentMethod": {
        "card": {
            "pan": "9900000000000010",
            "expiryDate": "1229",
            "cv2": "123",
            "cardHolderName": "John Smith"
        },
        "billingAddress": {
            "line1": "1 Some Street",
            "city": "Metropolis",
            "postcode": "AA1 2BB",
            "countryCode": "GBR"
        }
    }
}'
Response
HTTP/1.1 201 Created

{
    "processing": {
        "model": "MANAGE",
        "authResponse": {
            "statusCode": "00",
            "acquirerName": "Barclays Merchant Services",
            "message": "AUTH CODE:116283",
            "authCode": "116283",
            "gatewayReference": "ff67e3fed51e197db4bb1f30e8a20782",
            "gatewayMessage": "AUTH CODE:116283",
            "avsAddressCheck": "FULL_MATCH",
            "avsPostcodeCheck": "FULL_MATCH",
            "cv2Check": "MATCHED",
            "status": "AUTHORISED"
        },
        "route": "CPE"
    },
    "paymentMethod": {
        "registered": false,
        "card": {
            "cardFingerprint": "0hbdt0r/7ofTCqA5qKilqtHeeJg=",
            "new": true,
            "cardType": "MC_DEBIT",
            "cardUsageType": "DEBIT",
            "cardScheme": "MASTERCARD",
            "cardCategory": "DEBIT",
            "maskedPan": "990000******0010",
            "expiryDate": "1229",
            "issuer": "PAY360 TESTING",
            "issuerCountry": "GBR",
            "cardHolderName": "John Smith"
        },
        "billingAddress": {
            "line1": "1 Some Street",
            "city": "Metropolis",
            "postcode": "AA1 2BB",
            "country": "United Kingdom",
            "countryCode": "GBR"
        },
        "paymentClass": "CARD",
        "reuse": {
            "storage": "NONE"
        }
    },
    "customFields": {
        "fieldState": []
    },
    "transaction": {
        "transactionId": "10213520962",
        "merchantRef": "TXN-0001",
        "merchantDescription": "Sample Payment",
        "status": "SUCCESS",
        "stage": "COMPLETE",
        "type": "PAYMENT",
        "amount": 25,
        "consumerSpend": 25,
        "currency": "GBP",
        "transactionTime": "2024-09-02T19:09:43.439+01:00",
        "receivedTime": "2024-09-02T19:09:43.439+01:00",
        "customerInitiated": true
    },
    "outcome": {
        "status": "SUCCESS",
        "reasonCode": "S100",
        "reasonMessage": "Authorised"
    },
    "trace": "T8ily40k8gGYLujOCljwC7g",
    "link": [
        {
            "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5302522/10213520962",
            "rel": "transaction"
        }
    ]
}

Saving a card for a new customer

When you include a customer object and the payment succeeds, we register the card against that customer. You can then reuse it for repeat payments or saved payment methods.

Payment saving card for a new customer
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payment
Request body
{
    "transaction": {
        "currency": "GBP",
        "amount": 25.00,
        "merchantRef": "TXN-0002",
        "description": "Sample Payment",
        "commerceType": "ECOM"
    },
    "customer": {
        "merchantRef": "CUST-0001",
        "displayName": "John Smith",
        "email": "[email protected]",
        "telephone": "+441234567890",
        "ip": "185.161.165.20"
    },
    "paymentMethod": {
        "card": {
            "pan": "9902000000000018",
            "expiryDate": "1229",
            "cv2": "123",
            "cardHolderName": "John Smith"
        },
        "billingAddress": {
            "line1": "1 Some Street",
            "city": "Metropolis",
            "postcode": "AA1 2BB",
            "countryCode": "GBR"
        }
    }
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
    "transaction": {
        "currency": "GBP",
        "amount": 25.00,
        "merchantRef": "TXN-0002",
        "description": "Sample Payment",
        "commerceType": "ECOM"
    },
    "customer": {
        "merchantRef": "CUST-0001",
        "displayName": "John Smith",
        "email": "[email protected]",
        "telephone": "+441234567890",
        "ip": "185.161.165.20"
    },
    "paymentMethod": {
        "card": {
            "pan": "9902000000000018",
            "expiryDate": "1229",
            "cv2": "123",
            "cardHolderName": "John Smith"
        },
        "billingAddress": {
            "line1": "1 Some Street",
            "city": "Metropolis",
            "postcode": "AA1 2BB",
            "countryCode": "GBR"
        }
    }
}'
Response
HTTP/1.1 201 Created

{
    "processing": {
        "model": "MANAGE",
        "authResponse": {
            "statusCode": "00",
            "acquirerName": "Barclays Merchant Services",
            "message": "AUTH CODE:634920",
            "authCode": "634920",
            "gatewayReference": "5f9ad54a83b5ee7a1b35b5302803c2b7",
            "gatewayMessage": "AUTH CODE:634920",
            "avsAddressCheck": "FULL_MATCH",
            "avsPostcodeCheck": "FULL_MATCH",
            "cv2Check": "MATCHED",
            "status": "AUTHORISED"
        },
        "route": "CPE"
    },
    "paymentMethod": {
        "registered": true,
        "card": {
            "cardToken": "MT_QXG4ltszTiyiz1nWbQydnA",
            "cardFingerprint": "l313hfHapXJiLXyROD3X6P75k9E=",
            "new": true,
            "cardType": "VISA_DEBIT",
            "cardUsageType": "DEBIT",
            "cardScheme": "VISA",
            "cardCategory": "DEBIT",
            "maskedPan": "990200******0018",
            "expiryDate": "1229",
            "issuer": "PAY360 TESTING",
            "issuerCountry": "GBR",
            "cardHolderName": "John Smith"
        },
        "billingAddress": {
            "line1": "1 Some Street",
            "city": "Metropolis",
            "postcode": "AA1 2BB",
            "country": "United Kingdom",
            "countryCode": "GBR"
        },
        "paymentClass": "CARD",
        "reuse": {
            "storage": "NEW",
            "agreement": "ADHOC",
            "receivedSchemeReference": "XWM3I9SBV3ORCO"
        }
    },
    "customFields": {
        "fieldState": []
    },
    "customer": {
        "id": "2453687",
        "merchantRef": "CUST-0001"
    },
    "transaction": {
        "transactionId": "10213520965",
        "merchantRef": "TXN-0002",
        "merchantDescription": "Sample Payment",
        "status": "SUCCESS",
        "stage": "COMPLETE",
        "type": "PAYMENT",
        "amount": 25,
        "consumerSpend": 25,
        "currency": "GBP",
        "transactionTime": "2024-09-02T19:22:36.422+01:00",
        "receivedTime": "2024-09-02T19:22:36.422+01:00",
        "customerInitiated": true
    },
    "outcome": {
        "status": "SUCCESS",
        "reasonCode": "S100",
        "reasonMessage": "Authorised"
    },
    "trace": "TBxYU9RS-RyfnP52P9Yh6bw",
    "link": [
        {
            "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5302522/10213520965",
            "rel": "transaction"
        }
    ]
}

Using the default card for an existing customer

When an existing customer has a default saved card, use paymentMethod.fromCustomer to charge it. Include the card's CV2 in the request.

Payment using default card for an existing customer
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payment
Request body
{
    "transaction": {
        "currency": "GBP",
        "amount": 25.00,
        "merchantRef": "TXN-0003",
        "description": "Sample Payment",
        "commerceType": "ECOM"
    },
    "customer": {
        "merchantRef": "CUST-0001",
        "ip": "185.161.165.20"
    },
    "paymentMethod": {
        "fromCustomer": {
            "cv2": "123"
        }
    }
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
    "transaction": {
        "currency": "GBP",
        "amount": 25.00,
        "merchantRef": "TXN-0003",
        "description": "Sample Payment",
        "commerceType": "ECOM"
    },
    "customer": {
        "merchantRef": "CUST-0001",
        "ip": "185.161.165.20"
    },
    "paymentMethod": {
        "fromCustomer": {
            "cv2": "123"
        }
    }
}'
Response
HTTP/1.1 201 Created

{
    "processing": {
        "model": "MANAGE",
        "authResponse": {
            "statusCode": "00",
            "acquirerName": "Barclays Merchant Services",
            "message": "AUTH CODE:572009",
            "authCode": "572009",
            "gatewayReference": "a689a7919a629904ddd164209ba78894",
            "gatewayMessage": "AUTH CODE:572009",
            "avsAddressCheck": "FULL_MATCH",
            "avsPostcodeCheck": "FULL_MATCH",
            "cv2Check": "MATCHED",
            "status": "AUTHORISED"
        },
        "route": "CPE"
    },
    "paymentMethod": {
        "registered": true,
        "card": {
            "cardToken": "MT_QXG4ltszTiyiz1nWbQydnA",
            "cardFingerprint": "l313hfHapXJiLXyROD3X6P75k9E=",
            "new": false,
            "cardType": "VISA_DEBIT",
            "cardUsageType": "DEBIT",
            "cardScheme": "VISA",
            "cardCategory": "DEBIT",
            "maskedPan": "990200******0018",
            "expiryDate": "1229",
            "issuer": "PAY360 TESTING",
            "issuerCountry": "GBR",
            "cardHolderName": "John Smith"
        },
        "billingAddress": {
            "line1": "1 Some Street",
            "city": "Metropolis",
            "postcode": "AA1 2BB",
            "country": "United Kingdom",
            "countryCode": "GBR"
        },
        "paymentClass": "CARD",
        "reuse": {
            "storage": "EXISTING",
            "agreement": "ADHOC",
            "originalSchemeReference": "XWM3I9SBV3ORCO",
            "receivedSchemeReference": "699VJDIILOHYP4"
        }
    },
    "customFields": {
        "fieldState": []
    },
    "customer": {
        "id": "2453687",
        "merchantRef": "CUST-0001"
    },
    "transaction": {
        "transactionId": "10213520966",
        "merchantRef": "TXN-0003",
        "merchantDescription": "Sample Payment",
        "status": "SUCCESS",
        "stage": "COMPLETE",
        "type": "PAYMENT",
        "amount": 25,
        "consumerSpend": 25,
        "currency": "GBP",
        "transactionTime": "2024-09-02T19:26:25.953+01:00",
        "receivedTime": "2024-09-02T19:26:25.953+01:00",
        "customerInitiated": true
    },
    "outcome": {
        "status": "SUCCESS",
        "reasonCode": "S100",
        "reasonMessage": "Authorised"
    },
    "trace": "TPUoVKGedfrLUvFZCiTKB1Q",
    "link": [
        {
            "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5302522/10213520966",
            "rel": "transaction"
        }
    ]
}

3D Secure payments

When the card is enrolled in 3D Secure 2 the payment does not authorise straight away. We suspend it and answer U100 with a clientRedirect section: the cardholder has to be authenticated with their issuer before we ask for authorisation.

Payment suspended for 3D Secure
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payment
Request body
{
  "transaction": {
    "currency": "GBP",
    "amount": 12.99,
    "commerceType": "ECOM"
  },
  "paymentMethod": {
    "card": {
      "pan": "9900000000005159",
      "cv2": "456",
      "expiryDate": "1229",
      "cardHolderName": "John Smith"
    }
  }
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
  "transaction": {
    "currency": "GBP",
    "amount": 12.99,
    "commerceType": "ECOM"
  },
  "paymentMethod": {
    "card": {
      "pan": "9900000000005159",
      "cv2": "456",
      "expiryDate": "1229",
      "cardHolderName": "John Smith"
    }
  }
}'
Response
HTTP/1.1 201 Created

{
  "clientRedirect": {
    "type": "THREEDSECURE_V2_REDIRECT",
    "url": "https://dev.mite.pay360.com/threedsv2/handover",
    "threeDSServerTransId": "86622536-3de4-42f0-92aa-d504cb9ccff8"
  },
  "paymentMethod": {
    "registered": false,
    "card": {
      "cardFingerprint": "IkNwdkR7LUV6VNjJVFeTg+mfPQc=",
      "new": true,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******5159",
      "expiryDate": "1229",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {},
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NONE"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "threeDSecure": {
    "scheme": "MASTERCARD_IDENTITY_CHECK",
    "status": "INCOMPLETE",
    "version": 2,
    "protocolVersion": "2.2.0",
    "threeDSServerTransId": "86622536-3de4-42f0-92aa-d504cb9ccff8",
    "challengeRequest": "NO_PREFERENCE",
    "versionsAttempted": [
      {
        "version": 2,
        "availability": "AVAILABLE"
      }
    ]
  },
  "transaction": {
    "transactionId": "10254739388",
    "status": "PENDING",
    "stage": "THREE_D_SECURE",
    "type": "PAYMENT",
    "amount": 12.99,
    "consumerSpend": 0,
    "currency": "GBP",
    "transactionTime": "2026-09-07T16:27:41.360+01:00",
    "receivedTime": "2026-09-07T16:27:41.360+01:00",
    "customerInitiated": true
  },
  "outcome": {
    "status": "SUCCESS",
    "reasonCode": "U100",
    "reasonMessage": "Suspended pending Three D Secure process"
  },
  "strongCustomerAuthentication": {
    "transactionType": "GOODS_OR_SERVICES"
  },
  "trace": "TjqySFnpbmZ1Q1OGOPn5USQ",
  "link": [
    {
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10254739388",
      "rel": "transaction"
    }
  ]
}
HTTP/1.1 207 Multi-Status

{
  "processing": {
    "model": "MANAGE",
    "authResponse": {
      "statusCode": "1A",
      "acquirerName": "Barclays Merchant Services",
      "message": "DECLINED",
      "gatewayReference": "c7065f91ac5662d9227284d49c358efd",
      "gatewayMessage": "DECLINED",
      "avsAddressCheck": "NOT_CHECKED",
      "avsPostcodeCheck": "NOT_CHECKED",
      "cv2Check": "MATCHED",
      "status": "DECLINED"
    },
    "route": "CPE"
  },
  "paymentMethod": {
    "registered": false,
    "card": {
      "cardFingerprint": "2PBLpVOESPyZgvHQjT0wNnmV9ws=",
      "new": true,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******2161",
      "expiryDate": "1229",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {},
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NONE"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "threeDSecure": {
    "versionsAttempted": [
      {
        "version": 2,
        "availability": "ISSUER_NO_3DS"
      }
    ]
  },
  "transaction": {
    "transactionId": "10254739445",
    "status": "FAILED",
    "stage": "AUTHORISATION",
    "type": "PAYMENT",
    "amount": 12.99,
    "consumerSpend": 0,
    "currency": "GBP",
    "transactionTime": "2026-09-07T16:52:50.931+01:00",
    "receivedTime": "2026-09-07T16:52:50.931+01:00",
    "customerInitiated": true
  },
  "outcome": {
    "status": "FAILED",
    "reasonCode": "D101",
    "reasonMessage": "Transaction declined; Strong Customer Authentication required"
  },
  "strongCustomerAuthentication": {
    "transactionType": "GOODS_OR_SERVICES"
  },
  "trace": "TfB2NNOUbXaX-dyoAnKcRfA",
  "link": [
    {
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10254739445",
      "rel": "transaction"
    }
  ]
}
Notes:
  • A card enrolled in 3D Secure 2 suspends here rather than authorising: the outcome is U100 and the response carries a clientRedirect, which the cardholder's browser must be POSTed to before a resume request can complete the payment. See 3D Secure.
  • There is no clientRedirect when 3D Secure is not available for the card, as in the second response: the payment is authorised without it, or the issuer soft declines it for want of Strong Customer Authentication — D101, alongside availability ISSUER_NO_3DS.

Completing it takes three more steps, all described in When using your payment page:

  1. POST the cardholder's browser to clientRedirect.url with transactionId, your own notificationUrl and MD — usually a hidden form your page submits with JavaScript. Carry the Advanced Payments transaction id in MD, since that is what comes back to you.
  2. Receive the cardholder back on your notificationUrl, and check the overallStatus they arrive with — it reports the handover, not the payment.
  3. Send a resume request to complete the transaction, whatever the authentication outcome. Its response is the finished payment, with the authentication result in threeDSecure.
Resume after 3D Secure authentication
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/{transactionId}/resume
Request body
{}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/{transactionId}/resume" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{}'
Response
HTTP/1.1 201 Created

{
  "processing": {
    "model": "MANAGE",
    "authResponse": {
      "statusCode": "00",
      "acquirerName": "Barclays Merchant Services",
      "message": "AUTH CODE:158810",
      "authCode": "158810",
      "gatewayReference": "5da9a9664240a0f927eed76373ded055",
      "gatewayMessage": "AUTH CODE:158810",
      "avsAddressCheck": "NOT_CHECKED",
      "avsPostcodeCheck": "NOT_CHECKED",
      "cv2Check": "MATCHED",
      "status": "AUTHORISED"
    },
    "route": "CPE"
  },
  "paymentMethod": {
    "registered": false,
    "card": {
      "cardFingerprint": "IkNwdkR7LUV6VNjJVFeTg+mfPQc=",
      "new": true,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******5159",
      "expiryDate": "1229",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {},
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NONE"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "threeDSecure": {
    "scheme": "MASTERCARD_IDENTITY_CHECK",
    "status": "AUTHENTICATED",
    "eci": "02",
    "version": 2,
    "protocolVersion": "2.2.0",
    "threeDSServerTransId": "86622536-3de4-42f0-92aa-d504cb9ccff8",
    "dsTransactionId": "b3be62ea-9ebb-4821-89db-ae03ce257115",
    "acsTransactionId": "1138b70b-6a3d-44c0-ba1a-ef6977a7010f",
    "challengeRequest": "NO_PREFERENCE",
    "frictionless": false,
    "versionsAttempted": [
      {
        "version": 2,
        "availability": "AVAILABLE"
      }
    ]
  },
  "transaction": {
    "transactionId": "10254739388",
    "status": "SUCCESS",
    "stage": "COMPLETE",
    "type": "PAYMENT",
    "amount": 12.99,
    "consumerSpend": 12.99,
    "currency": "GBP",
    "transactionTime": "2026-09-07T16:27:41.360+01:00",
    "receivedTime": "2026-09-07T16:27:41.360+01:00",
    "customerInitiated": true
  },
  "outcome": {
    "status": "SUCCESS",
    "reasonCode": "S100",
    "reasonMessage": "Authorised"
  },
  "strongCustomerAuthentication": {
    "transactionType": "GOODS_OR_SERVICES"
  },
  "trace": "Ti4qElDVKU52wLOFzh2YcMA",
  "link": [
    {
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10254739388",
      "rel": "transaction"
    }
  ]
}
HTTP/1.1 207 Multi-Status

{
  "processing": {
    "model": "MANAGE",
    "authResponse": {
      "statusCode": "05",
      "acquirerName": "Barclays Merchant Services",
      "message": "DECLINED",
      "gatewayReference": "13d8a56b7f739943414b22074b65668b",
      "gatewayMessage": "DECLINED",
      "avsAddressCheck": "NOT_CHECKED",
      "avsPostcodeCheck": "NOT_CHECKED",
      "cv2Check": "MATCHED",
      "status": "DECLINED"
    },
    "route": "CPE"
  },
  "paymentMethod": {
    "registered": false,
    "card": {
      "cardFingerprint": "mexdHzRFd0o5qJYx4XemakUUZj4=",
      "new": true,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******8427",
      "expiryDate": "1229",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {},
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NONE"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "threeDSecure": {
    "scheme": "MASTERCARD_IDENTITY_CHECK",
    "status": "AUTHENTICATED",
    "eci": "02",
    "version": 2,
    "protocolVersion": "2.2.0",
    "threeDSServerTransId": "2206025c-769c-4230-b98f-5c3b6136e3b9",
    "dsTransactionId": "18839c83-907e-49e4-add9-0e7a59da5c0a",
    "acsTransactionId": "229fe61d-d9c0-4bc1-9ce5-e89adc520eb0",
    "challengeRequest": "NO_PREFERENCE",
    "frictionless": true,
    "versionsAttempted": [
      {
        "version": 2,
        "availability": "AVAILABLE"
      }
    ],
    "cardHolderMessage": "Please call {issuer} at XXX-XXX-XXXX to set up authentication."
  },
  "transaction": {
    "transactionId": "10254739452",
    "status": "FAILED",
    "stage": "AUTHORISATION",
    "type": "PAYMENT",
    "amount": 12.99,
    "consumerSpend": 0,
    "currency": "GBP",
    "transactionTime": "2026-09-07T16:53:33.876+01:00",
    "receivedTime": "2026-09-07T16:53:33.876+01:00",
    "customerInitiated": true
  },
  "outcome": {
    "status": "FAILED",
    "reasonCode": "D100",
    "reasonMessage": "Declined by upstream processor"
  },
  "strongCustomerAuthentication": {
    "transactionType": "GOODS_OR_SERVICES"
  },
  "trace": "ThomdpeF9e4SBLTDZV-jDmQ",
  "link": [
    {
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10254739452",
      "rel": "transaction"
    }
  ]
}
Notes:
  • Sent once the cardholder is back on your notificationUrl, whatever overallStatus they came back with: the resume is what completes the transaction.
  • The body is empty — the transaction id in the path is enough — and the response is the transaction as it now stands, with the authentication result in threeDSecure.
  • Authentication and authorisation are separate outcomes: the declined response below was authenticated (status AUTHENTICATED) and still refused by the issuer. Where Strong Customer Authentication has not been performed, the issuer may instead soft decline the authorisation, which we report as D101 rather than D100.

In MITE, the 3DS test cards force a particular authentication outcome, so the only thing you change between scenarios is the pan in the payment request.

What you send in the payment affects the journey: a cardholder name is required, and addresses, email and telephone all make a frictionless outcome more likely — see Additional request data. If 3D Secure is not available for the card, the payment may proceed without it, or be soft declined by the issuer.

You can go further and describe the transaction, the customer and their history with you in strongCustomerAuthentication, which the issuer may use in their risk analysis — see Strong Customer Authentication tuning. Every field is optional, so send what you have; these four payments show the shapes it takes.

Requesting a challenge
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payment
Request body
{
  "transaction": {
    "currency": "GBP",
    "amount": 150.00,
    "commerceType": "ECOM"
  },
  "customer": {
    "registered": false,
    "displayName": "John Smith",
    "email": "[email protected]",
    "telephone": "+441234567890"
  },
  "paymentMethod": {
    "card": {
      "pan": "9900000000005159",
      "cv2": "456",
      "expiryDate": "1229",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "countryCode": "GBR"
    }
  },
  "strongCustomerAuthentication": {
    "challengeRequested": "CHALLENGE_REQUESTED"
  }
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
  "transaction": {
    "currency": "GBP",
    "amount": 150.00,
    "commerceType": "ECOM"
  },
  "customer": {
    "registered": false,
    "displayName": "John Smith",
    "email": "[email protected]",
    "telephone": "+441234567890"
  },
  "paymentMethod": {
    "card": {
      "pan": "9900000000005159",
      "cv2": "456",
      "expiryDate": "1229",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "countryCode": "GBR"
    }
  },
  "strongCustomerAuthentication": {
    "challengeRequested": "CHALLENGE_REQUESTED"
  }
}'
Response
HTTP/1.1 201 Created

{
  "clientRedirect": {
    "type": "THREEDSECURE_V2_REDIRECT",
    "url": "https://dev.mite.pay360.com/threedsv2/handover",
    "threeDSServerTransId": "a0ab5969-323b-4974-bc18-c0c4b5e4a260"
  },
  "paymentMethod": {
    "registered": false,
    "card": {
      "cardFingerprint": "IkNwdkR7LUV6VNjJVFeTg+mfPQc=",
      "new": true,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******5159",
      "expiryDate": "1229",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "country": "United Kingdom",
      "countryCode": "GBR"
    },
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NONE"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "threeDSecure": {
    "scheme": "MASTERCARD_IDENTITY_CHECK",
    "status": "INCOMPLETE",
    "version": 2,
    "protocolVersion": "2.2.0",
    "threeDSServerTransId": "a0ab5969-323b-4974-bc18-c0c4b5e4a260",
    "challengeRequest": "CHALLENGE_REQUESTED",
    "versionsAttempted": [
      {
        "version": 2,
        "availability": "AVAILABLE"
      }
    ]
  },
  "customer": {},
  "transaction": {
    "transactionId": "10254739606",
    "status": "PENDING",
    "stage": "THREE_D_SECURE",
    "type": "PAYMENT",
    "amount": 150.0,
    "consumerSpend": 0,
    "currency": "GBP",
    "transactionTime": "2026-09-07T18:58:31.231+01:00",
    "receivedTime": "2026-09-07T18:58:31.231+01:00",
    "customerInitiated": true
  },
  "outcome": {
    "status": "SUCCESS",
    "reasonCode": "U100",
    "reasonMessage": "Suspended pending Three D Secure process"
  },
  "strongCustomerAuthentication": {
    "transactionType": "GOODS_OR_SERVICES",
    "challengeRequested": "CHALLENGE_REQUESTED"
  },
  "trace": "TpU_kIJ5iF0d47HKVVp906Q",
  "link": [
    {
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10254739606",
      "rel": "transaction"
    }
  ]
}
Notes:
  • challengeRequested on its own asks the issuer for a particular authentication flow — here a challenge, for a transaction you are not comfortable letting through frictionless.
  • The preference we ultimately sent is in threeDSecure.challengeRequest: we override it where scheme rules require a challenge, and the issuer decides in any case. See Strong Customer Authentication tuning.
Digital pre-order payment
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payment
Request body
{
  "transaction": {
    "currency": "GBP",
    "amount": 50.00,
    "commerceType": "ECOM"
  },
  "customer": {
    "registered": false,
    "displayName": "John Smith",
    "email": "[email protected]",
    "telephone": "+441234567890"
  },
  "paymentMethod": {
    "card": {
      "pan": "9900000000005159",
      "cv2": "456",
      "expiryDate": "1229",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "countryCode": "GBR"
    }
  },
  "strongCustomerAuthentication": {
    "merchantRisk": {
      "deliveryTimeframe": "ELECTRONIC",
      "deliveryEmail": "[email protected]",
      "preorder": true,
      "preorderDate": "2026-11-01",
      "shippingTo": "DIGITAL"
    },
    "accountInfo": {
      "accountOpened": {
        "period": "MORE_THAN_60_DAYS"
      },
      "accountLastChanged": {
        "period": "BETWEEN_30_AND_60_DAYS"
      },
      "passwordLastChanged": {
        "period": "MORE_THAN_60_DAYS"
      },
      "paymentAccountRegistered": {
        "period": "MORE_THAN_60_DAYS"
      },
      "suspiciousActivity": false
    }
  }
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
  "transaction": {
    "currency": "GBP",
    "amount": 50.00,
    "commerceType": "ECOM"
  },
  "customer": {
    "registered": false,
    "displayName": "John Smith",
    "email": "[email protected]",
    "telephone": "+441234567890"
  },
  "paymentMethod": {
    "card": {
      "pan": "9900000000005159",
      "cv2": "456",
      "expiryDate": "1229",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "countryCode": "GBR"
    }
  },
  "strongCustomerAuthentication": {
    "merchantRisk": {
      "deliveryTimeframe": "ELECTRONIC",
      "deliveryEmail": "[email protected]",
      "preorder": true,
      "preorderDate": "2026-11-01",
      "shippingTo": "DIGITAL"
    },
    "accountInfo": {
      "accountOpened": {
        "period": "MORE_THAN_60_DAYS"
      },
      "accountLastChanged": {
        "period": "BETWEEN_30_AND_60_DAYS"
      },
      "passwordLastChanged": {
        "period": "MORE_THAN_60_DAYS"
      },
      "paymentAccountRegistered": {
        "period": "MORE_THAN_60_DAYS"
      },
      "suspiciousActivity": false
    }
  }
}'
Response
HTTP/1.1 201 Created

{
  "clientRedirect": {
    "type": "THREEDSECURE_V2_REDIRECT",
    "url": "https://dev.mite.pay360.com/threedsv2/handover",
    "threeDSServerTransId": "0718c490-bd68-4247-87c9-e65f553bd1b8"
  },
  "paymentMethod": {
    "registered": false,
    "card": {
      "cardFingerprint": "IkNwdkR7LUV6VNjJVFeTg+mfPQc=",
      "new": true,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******5159",
      "expiryDate": "1229",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "country": "United Kingdom",
      "countryCode": "GBR"
    },
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NONE"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "threeDSecure": {
    "scheme": "MASTERCARD_IDENTITY_CHECK",
    "status": "INCOMPLETE",
    "version": 2,
    "protocolVersion": "2.2.0",
    "threeDSServerTransId": "0718c490-bd68-4247-87c9-e65f553bd1b8",
    "challengeRequest": "NO_PREFERENCE",
    "versionsAttempted": [
      {
        "version": 2,
        "availability": "AVAILABLE"
      }
    ]
  },
  "customer": {},
  "transaction": {
    "transactionId": "10254739607",
    "status": "PENDING",
    "stage": "THREE_D_SECURE",
    "type": "PAYMENT",
    "amount": 50.0,
    "consumerSpend": 0,
    "currency": "GBP",
    "transactionTime": "2026-09-07T18:58:32.148+01:00",
    "receivedTime": "2026-09-07T18:58:32.148+01:00",
    "customerInitiated": true
  },
  "outcome": {
    "status": "SUCCESS",
    "reasonCode": "U100",
    "reasonMessage": "Suspended pending Three D Secure process"
  },
  "strongCustomerAuthentication": {
    "transactionType": "GOODS_OR_SERVICES",
    "merchantRisk": {
      "deliveryEmail": "[email protected]",
      "deliveryTimeframe": "ELECTRONIC",
      "preorder": true,
      "preorderDate": "2026-11-01",
      "shippingTo": "DIGITAL"
    },
    "accountInfo": {
      "accountOpened": {
        "period": "MORE_THAN_60_DAYS"
      },
      "accountLastChanged": {
        "period": "BETWEEN_30_AND_60_DAYS"
      },
      "passwordLastChanged": {
        "period": "MORE_THAN_60_DAYS"
      },
      "paymentAccountRegistered": {
        "period": "MORE_THAN_60_DAYS"
      },
      "suspiciousActivity": false
    }
  },
  "trace": "TgWpvtA5BVtO-TEQVriMpHw",
  "link": [
    {
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10254739607",
      "rel": "transaction"
    }
  ]
}
Notes:
  • Merchandise that is delivered electronically and is not yet available: merchantRisk describes the delivery, and accountInfo the customer's account with you — an established account with nothing suspicious on it makes a frictionless outcome more likely.
  • No challengeRequested was sent, so the preference passed to the issuer is NO_PREFERENCE.
Gift card payment with a challenge requested
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payment
Request body
{
  "transaction": {
    "currency": "GBP",
    "amount": 1000.00,
    "commerceType": "ECOM"
  },
  "customer": {
    "registered": false,
    "displayName": "John Smith",
    "email": "[email protected]",
    "telephone": "+441234567890"
  },
  "paymentMethod": {
    "card": {
      "pan": "9900000000005159",
      "cv2": "456",
      "expiryDate": "1229",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "countryCode": "GBR"
    }
  },
  "order": {
    "shippingAddress": {
      "line1": "123 Fake Street",
      "city": "Fakeville",
      "postcode": "FV99 6TY",
      "countryCode": "GBR"
    }
  },
  "strongCustomerAuthentication": {
    "challengeRequested": "CHALLENGE_REQUESTED",
    "merchantRisk": {
      "deliveryTimeframe": "SAME_DAY",
      "giftCardPurchase": {
        "totalAmount": 1000,
        "currency": "GBP",
        "count": 20
      },
      "shippingTo": "OTHER_ADDRESS"
    },
    "accountInfo": {
      "accountOpened": {
        "period": "MORE_THAN_60_DAYS"
      },
      "accountLastChanged": {
        "period": "THIS_TRANSACTION"
      },
      "passwordLastChanged": {
        "period": "THIS_TRANSACTION"
      },
      "paymentAccountRegistered": {
        "period": "MORE_THAN_60_DAYS"
      },
      "activity": {
        "purchasesInLastSixMonths": 5,
        "transactionAttemptsInLast24Hours": 27,
        "transactionAttemptsInLastYear": 32
      },
      "shippingNameSameAsAccountName": false
    }
  }
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
  "transaction": {
    "currency": "GBP",
    "amount": 1000.00,
    "commerceType": "ECOM"
  },
  "customer": {
    "registered": false,
    "displayName": "John Smith",
    "email": "[email protected]",
    "telephone": "+441234567890"
  },
  "paymentMethod": {
    "card": {
      "pan": "9900000000005159",
      "cv2": "456",
      "expiryDate": "1229",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "countryCode": "GBR"
    }
  },
  "order": {
    "shippingAddress": {
      "line1": "123 Fake Street",
      "city": "Fakeville",
      "postcode": "FV99 6TY",
      "countryCode": "GBR"
    }
  },
  "strongCustomerAuthentication": {
    "challengeRequested": "CHALLENGE_REQUESTED",
    "merchantRisk": {
      "deliveryTimeframe": "SAME_DAY",
      "giftCardPurchase": {
        "totalAmount": 1000,
        "currency": "GBP",
        "count": 20
      },
      "shippingTo": "OTHER_ADDRESS"
    },
    "accountInfo": {
      "accountOpened": {
        "period": "MORE_THAN_60_DAYS"
      },
      "accountLastChanged": {
        "period": "THIS_TRANSACTION"
      },
      "passwordLastChanged": {
        "period": "THIS_TRANSACTION"
      },
      "paymentAccountRegistered": {
        "period": "MORE_THAN_60_DAYS"
      },
      "activity": {
        "purchasesInLastSixMonths": 5,
        "transactionAttemptsInLast24Hours": 27,
        "transactionAttemptsInLastYear": 32
      },
      "shippingNameSameAsAccountName": false
    }
  }
}'
Response
HTTP/1.1 201 Created

{
  "clientRedirect": {
    "type": "THREEDSECURE_V2_REDIRECT",
    "url": "https://dev.mite.pay360.com/threedsv2/handover",
    "threeDSServerTransId": "6ccc4b39-d5ff-4f2d-b16d-a45fcda2ad49"
  },
  "paymentMethod": {
    "registered": false,
    "card": {
      "cardFingerprint": "IkNwdkR7LUV6VNjJVFeTg+mfPQc=",
      "new": true,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******5159",
      "expiryDate": "1229",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "country": "United Kingdom",
      "countryCode": "GBR"
    },
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NONE"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "threeDSecure": {
    "scheme": "MASTERCARD_IDENTITY_CHECK",
    "status": "INCOMPLETE",
    "version": 2,
    "protocolVersion": "2.2.0",
    "threeDSServerTransId": "6ccc4b39-d5ff-4f2d-b16d-a45fcda2ad49",
    "challengeRequest": "CHALLENGE_REQUESTED",
    "versionsAttempted": [
      {
        "version": 2,
        "availability": "AVAILABLE"
      }
    ]
  },
  "customer": {},
  "transaction": {
    "transactionId": "10254739608",
    "status": "PENDING",
    "stage": "THREE_D_SECURE",
    "type": "PAYMENT",
    "amount": 1000.0,
    "consumerSpend": 0,
    "currency": "GBP",
    "transactionTime": "2026-09-07T18:58:33.182+01:00",
    "receivedTime": "2026-09-07T18:58:33.182+01:00",
    "customerInitiated": true
  },
  "order": {
    "shippingAddress": {
      "line1": "123 Fake Street",
      "city": "Fakeville",
      "postcode": "FV99 6TY",
      "country": "United Kingdom",
      "countryCode": "GBR"
    }
  },
  "outcome": {
    "status": "SUCCESS",
    "reasonCode": "U100",
    "reasonMessage": "Suspended pending Three D Secure process"
  },
  "strongCustomerAuthentication": {
    "transactionType": "GOODS_OR_SERVICES",
    "challengeRequested": "CHALLENGE_REQUESTED",
    "merchantRisk": {
      "deliveryTimeframe": "SAME_DAY",
      "giftCardPurchase": {
        "totalAmount": 1000,
        "currency": "GBP",
        "count": 20
      },
      "shippingTo": "OTHER_ADDRESS"
    },
    "accountInfo": {
      "accountOpened": {
        "period": "MORE_THAN_60_DAYS"
      },
      "accountLastChanged": {
        "period": "THIS_TRANSACTION"
      },
      "passwordLastChanged": {
        "period": "THIS_TRANSACTION"
      },
      "activity": {
        "purchasesInLastSixMonths": 5,
        "transactionAttemptsInLast24Hours": 27,
        "transactionAttemptsInLastYear": 32
      },
      "paymentAccountRegistered": {
        "period": "MORE_THAN_60_DAYS"
      },
      "shippingNameSameAsAccountName": false
    }
  },
  "trace": "TFTRLFJQMpqwASrqS6dcNaQ",
  "link": [
    {
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10254739608",
      "rel": "transaction"
    }
  ]
}
Notes:
  • A large gift card order, shipped somewhere other than the billing address, to an account whose password changed during this transaction: the data says as much, and challengeRequested asks for the cardholder to be challenged.
  • giftCardPurchase.totalAmount is in major units, and the shipping address is part of order details rather than of strongCustomerAuthentication.
Reorder payment with a prior authentication
EndpointDefinition
POST /acceptor/rest/transactions/{instId}/payment
Request body
{
  "transaction": {
    "currency": "GBP",
    "amount": 75.00,
    "commerceType": "ECOM"
  },
  "customer": {
    "registered": false,
    "displayName": "John Smith",
    "email": "[email protected]",
    "telephone": "+441234567890"
  },
  "paymentMethod": {
    "card": {
      "pan": "9900000000005159",
      "cv2": "456",
      "expiryDate": "1229",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "countryCode": "GBR"
    }
  },
  "strongCustomerAuthentication": {
    "challengeRequested": "NO_CHALLENGE_REQUESTED",
    "merchantRisk": {
      "deliveryTimeframe": "TWO_OR_MORE_DAYS",
      "reorder": true,
      "shippingTo": "BILLING_ADDRESS"
    },
    "accountInfo": {
      "accountOpened": {
        "date": "2023-07-23"
      },
      "accountLastChanged": {
        "date": "2025-09-21"
      },
      "passwordLastChanged": {
        "date": "2026-03-07"
      },
      "paymentAccountRegistered": {
        "date": "2023-07-23"
      },
      "activity": {
        "purchasesInLastSixMonths": 6,
        "transactionAttemptsInLast24Hours": 1,
        "transactionAttemptsInLastYear": 12
      },
      "shippingNameSameAsAccountName": true
    },
    "priorAuthenticationInfo": {
      "reference": "64a09f9b-0d89-4cfe-8de9-9b96fdfa4eb8",
      "method": "FRICTIONLESS_AUTH",
      "time": "2026-08-11T13:04:54"
    }
  }
}
cURL
curl -X POST "{targetEnvironmentPath}/acceptor/rest/transactions/{instId}/payment" \
  -u "{apiUser}:{apiPassword}" \
  -H "Content-Type: application/json" \
  -d '{
  "transaction": {
    "currency": "GBP",
    "amount": 75.00,
    "commerceType": "ECOM"
  },
  "customer": {
    "registered": false,
    "displayName": "John Smith",
    "email": "[email protected]",
    "telephone": "+441234567890"
  },
  "paymentMethod": {
    "card": {
      "pan": "9900000000005159",
      "cv2": "456",
      "expiryDate": "1229",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "countryCode": "GBR"
    }
  },
  "strongCustomerAuthentication": {
    "challengeRequested": "NO_CHALLENGE_REQUESTED",
    "merchantRisk": {
      "deliveryTimeframe": "TWO_OR_MORE_DAYS",
      "reorder": true,
      "shippingTo": "BILLING_ADDRESS"
    },
    "accountInfo": {
      "accountOpened": {
        "date": "2023-07-23"
      },
      "accountLastChanged": {
        "date": "2025-09-21"
      },
      "passwordLastChanged": {
        "date": "2026-03-07"
      },
      "paymentAccountRegistered": {
        "date": "2023-07-23"
      },
      "activity": {
        "purchasesInLastSixMonths": 6,
        "transactionAttemptsInLast24Hours": 1,
        "transactionAttemptsInLastYear": 12
      },
      "shippingNameSameAsAccountName": true
    },
    "priorAuthenticationInfo": {
      "reference": "64a09f9b-0d89-4cfe-8de9-9b96fdfa4eb8",
      "method": "FRICTIONLESS_AUTH",
      "time": "2026-08-11T13:04:54"
    }
  }
}'
Response
HTTP/1.1 201 Created

{
  "clientRedirect": {
    "type": "THREEDSECURE_V2_REDIRECT",
    "url": "https://dev.mite.pay360.com/threedsv2/handover",
    "threeDSServerTransId": "b98ab209-764d-482a-a352-a9dd072cf785"
  },
  "paymentMethod": {
    "registered": false,
    "card": {
      "cardFingerprint": "IkNwdkR7LUV6VNjJVFeTg+mfPQc=",
      "new": true,
      "cardType": "MC_DEBIT",
      "cardUsageType": "DEBIT",
      "cardScheme": "MASTERCARD",
      "cardCategory": "DEBIT",
      "maskedPan": "990000******5159",
      "expiryDate": "1229",
      "issuer": "PAY360 TESTING",
      "issuerCountry": "GBR",
      "cardHolderName": "John Smith"
    },
    "billingAddress": {
      "line1": "16 Charlotte Street",
      "city": "Manchester",
      "postcode": "M1 4FS",
      "country": "United Kingdom",
      "countryCode": "GBR"
    },
    "paymentClass": "CARD",
    "reuse": {
      "storage": "NONE"
    }
  },
  "customFields": {
    "fieldState": []
  },
  "threeDSecure": {
    "scheme": "MASTERCARD_IDENTITY_CHECK",
    "status": "INCOMPLETE",
    "version": 2,
    "protocolVersion": "2.2.0",
    "threeDSServerTransId": "b98ab209-764d-482a-a352-a9dd072cf785",
    "challengeRequest": "NO_CHALLENGE_REQUESTED",
    "versionsAttempted": [
      {
        "version": 2,
        "availability": "AVAILABLE"
      }
    ]
  },
  "customer": {},
  "transaction": {
    "transactionId": "10254739609",
    "status": "PENDING",
    "stage": "THREE_D_SECURE",
    "type": "PAYMENT",
    "amount": 75.0,
    "consumerSpend": 0,
    "currency": "GBP",
    "transactionTime": "2026-09-07T18:58:33.928+01:00",
    "receivedTime": "2026-09-07T18:58:33.928+01:00",
    "customerInitiated": true
  },
  "outcome": {
    "status": "SUCCESS",
    "reasonCode": "U100",
    "reasonMessage": "Suspended pending Three D Secure process"
  },
  "strongCustomerAuthentication": {
    "transactionType": "GOODS_OR_SERVICES",
    "challengeRequested": "NO_CHALLENGE_REQUESTED",
    "merchantRisk": {
      "deliveryTimeframe": "TWO_OR_MORE_DAYS",
      "reorder": true,
      "shippingTo": "BILLING_ADDRESS"
    },
    "accountInfo": {
      "accountOpened": {
        "date": "2023-07-23"
      },
      "accountLastChanged": {
        "date": "2025-09-21"
      },
      "passwordLastChanged": {
        "date": "2026-03-07"
      },
      "activity": {
        "purchasesInLastSixMonths": 6,
        "transactionAttemptsInLast24Hours": 1,
        "transactionAttemptsInLastYear": 12
      },
      "paymentAccountRegistered": {
        "date": "2023-07-23"
      },
      "shippingNameSameAsAccountName": true
    },
    "priorAuthenticationInfo": {
      "reference": "64a09f9b-0d89-4cfe-8de9-9b96fdfa4eb8",
      "method": "FRICTIONLESS_AUTH",
      "time": "2026-08-11T13:04:54"
    }
  },
  "trace": "TgC9zd9eXANVCvqF5nSZQXQ",
  "link": [
    {
      "href": "https://api.mite.pay360.com/acceptor/rest/transactions/5315271/10254739609",
      "rel": "transaction"
    }
  ]
}
Notes:
  • A repeat purchase by a long-standing customer, where challengeRequested asks for no challenge. The accountInfo periods can be given as dates instead of relative periods.
  • priorAuthenticationInfo.reference is the threeDSecure.acsTransactionId of an earlier authentication of the same cardholder, which lets the issuer take it into account.