---
title: "3D Secure Standalone"
method: POST
path: "/3dsecure/standalone"
tags: ["3D Secure"]
---

# 3D Secure Standalone

`POST /3dsecure/standalone`

This function is used to process a request via the 3D Secure process without authorizing the payment. This will return the result of the 3D Secure process as well as the 3D Secure data that can then be used to process a payment via the [Authorization](/apis/payments-platform-rest/openapi/transactions/transactionsauthorization) or [Sale/Purchase](/apis/payments-platform-rest/openapi/transactions/transactionssale) endpoint.

**Integration Methods:**
- Host Direct

See the [Integration Methods](/guides/quickstart#integration-methods) and [URLs Section](/guides/quickstart#urls) sections of the Development Quick Start guide for details regarding each processing option.

## Headers

- `InterfaceVersion` string, required
- `InterfaceName` string, required
- `CompanyName` string, required
- `AccessToken` string, uuid, required

## Request body

- union
  - 3dsecureStandaloneCardnumber
    - `dateTime` string, ISO 8601, required — The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm). Must be sent as the local date/time of the merchant. For example, a request processed at a merchant in the Pacific time zone at 9:18am on April 15th 2021 would be sent as 2021-04-15T09:18:23.283-07:00
    - `amount` AmountTotalOnly, required — Object containing information regarding the amount being requested. The `total` field within the object is required and specifies the amount being requested. Note: For merchants that are configured to allow multiple currencies, the amount fields can specify up to three decimal places. However, the number of decimal places can not exceed the number allowed for the specified currency. See the [Currency Codes](/guides/appendices/currency-codes) section for details.
      - `total` number, required — The amount being charged for a particular transaction. If other amount fields are sent, they must be included in the total amount. Amount cannot be zero.
    - `currencyCode` string, ISO 4217 3 Character Alphabetic Code, required — Transaction currency code. See the [Currency Codes](/guides/appendices/currency-codes) section for details. **Note: This is currently supported when processing for a merchant outside of the US and Canada. If processing for a US or Canadian merchant then this field will be ignored and the transaction will process in the merchant's configured currency.**
    - `customer` object, required
      - `firstName` string, required — Specifies a consumer’s first name. This field is used in AVS. If the interface sends this field, the value specified by the interface will be returned in the response, unless the API Option [USECARDNAME](/guides/appendices/api-options#usecardname) is included in the request and a Commerce Engine or UTG-controlled PIN pad is in use. If the interface does not send the `customer` object, the consumer's name will be returned in the `customer` object if the name is present in the card's EMV or track data.
      - `lastName` string, required — Specifies a consumer’s last name. This field is used in AVS. If the interface sends this field, the value specified by the interface will be returned in the response, unless the API Option [USECARDNAME](/guides/appendices/api-options#usecardname) is included in the request and a Commerce Engine or UTG-controlled PIN pad is in use. If the interface does not send the `customer` object, the consumer's name will be returned in the `customer` object if the name is present in the card's EMV or track data.
      - `phoneNumber` string — Customer phone number
      - `phoneCountry` string — Country calling code of the phone number. Required when sending `customer.phoneNumber`.
      - `emailAddress` string, required — Customer email address.
      - `addressLine1` string — Cardholder’s street address exactly as it appears on their billing statement. This field is used in AVS. **Recommended for increasing the possibility of frictionless flow**
      - `addressLine2` string — Customer address line 2.
      - `city` string — Customer address city. **Recommended for increasing the possibility of frictionless flow**
      - `region` string — A level 2 country subdivision code according to ISO-3166-2. **Recommended for increasing the possibility of frictionless flow**
      - `postalCode` string — Cardholder’s ZIP/postal code from their billing statement. This field is used in AVS. Do not include special characters. **Note: This field only allows alphanumeric characters (a-z, A-Z, 0-9). Special characters including - are not allowed. If you are sending in zip+4 you must not include the dash so 89134-1234 would be sent as 891341234** **Recommended for increasing the possibility of frictionless flow**
      - `country` string — 2 character ISO Country Code. See the [ISO](https://www.iso.org/obp/ui/#search/code/) website for details. **Recommended for increasing the possibility of frictionless flow**
      - `ipAddress` string, required — Public source IP Address where the request originates, not the IP Address of the web server.
      - `shipping` CustomerShipping3DSecure — **Conditional: must be sent if `threeDSecure.addressMatch` is 'false'**
        - `addressLine1` string — Shipping street address - Line 1 **Recommended for increasing the possibility of frictionless flow**
        - `addressLine2` string — Shipping street address - Line 2
        - `city` string — Shipping address - City **Recommended for increasing the possibility of frictionless flow**
        - `country` string — Shipping address - 2 character ISO Country Code. **Recommended for increasing the possibility of frictionless flow**
        - `postalCode` string — Shipping address - Postal Code **Recommended for increasing the possibility of frictionless flow**
        - `region` string — Shipping address - A level 2 country subdivision code according to ISO-3166-2. **Recommended for increasing the possibility of frictionless flow**
    - `card` object, required
      - `number` string, required — The payment card number entered in an initial authorization/sale request. This field will always be masked when returned in a response.
      - `expirationDate` integer, required — **Conditional: Send only when card data is manually entered or when using a token. This field should not be specified when using an encrypted device.** Card expiration date in MMYY format. This value should only be populated in the initial sale/authorization request.
      - `present` 'Y' | 'N' — **Conditional: Send in the initial authorization/sale request** Indicates whether a card was present (‘Y’) or not (‘N’) at the time a transaction took place. This should be set appropriately in the initial authorization/sale request. In subsequent requests, this field should be left blank or should not be sent. **Note:** Subsequent request here does not apply to the secondary request for card on file type transactions or reuse of the same card. An example of a subsequent request would be a capture after an authorization. You would not include `card.present` in the capture, which is the subsequent request. Another example is when performing an incremental authorization where you perform an authorization, followed by an incremental authorization then a capture. The second authorization (incremental) and the capture are the subsequent requests where you would not include `card.present`.
      - `securityCode` object — **Conditional: Send when processing a 3D Secure transaction in the US. This object should be sent for initial card on file request but is not required for subsequent merchant initiated charges.**
        - `indicator` '0' | '1' | '2' | '9', required — This field indicates the presence of a CSC. Value|Description -----|----------- 0 | CSC not provided by user. 1 | CSC provided. 2 | CSC illegible. 9 | CSC not on card, or card did not have a CSC.
        - `value` string, required — The three- or four-digit Card Security Code found on a payment card. This value should only be sent in an initial sale/authorization request. It should not be stored by the interface. When sending `card.securityCode.value`, `card.securityCode.indicator` must also be sent.
    - `transaction` object, required
      - `invoice` string, required — 10-digit invoice number assigned by the interface to identify a transaction. An invoice number serves as a unique key that identifies a transaction within a batch in Shift4's Gateway. **Note: For US and Canadian processing: Although the invoice number is sent as a JSON string it is a numeric value. No alpha characters are allowed.** **For processing outside of the US and Canada alpha characters are allowed.**
      - `notes` string — A free-form notes field that supports the use of HTML tags. This can be used for reference in [Lighthouse Transaction Manager](https://ltm.shift4test.com/) and is not sent to the authorization host. Escaped quotation marks should not be sent in the Notes field.
      - `vendorReference` string — Optional field for information that can be searched in the merchant portal.
      - `s4RiskId` string — Unique transaction identification number generated by Shift4 to identify a specific risk transaction and a field that can be searched in LTM. **Conditional: must be sent if [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) was completed prior to processing the transaction.**
    - `threeDSecure` object, required
      - `initiate` '01' | '03', required — Indicates whether to initiate the 3D Secure authentication process Value| Description -----|------------ 01 | Force 3D Secure authentication 03 | Initiate 3D Secure according to the 3D Secure Adviser result
      - `browser` ThreeDSecureBrowser, required
        - `acceptHeader` string, required — Exact content of the HTTP accept headers.
        - `javaEnabled` boolean, required — Indicates whether the cardholder's browser has the ability to execute Java. Value | Description ------|------------ true | Cardholder's browser does have the ability to execute Java. false | Cardholder's browser does not have the ability to execute Java.
        - `javascriptEnabled` boolean, required — Indicates whether the cardholder's browser has the ability to execute Javascript. Value | Description ------|------------ true | Cardholder's browser does have the ability to execute Javascript. false | Cardholder's browser does not have the ability to execute Javascript.
        - `language` string, required — Value representing the browser language as defined in IETF BCP47.
        - `colorDepth` '1' | '4' | '8' | '15' | '16' | '24' | '32' | '48', required — Value representing the bit depth of the colour palette for displaying images, in bits per pixel. Accepted values are: Value| Description -----|------------ 1 | 1 bit 4 | 4 bits 8 | 8 bits 15 | 15 bits 16 | 16 bits 24 | 24 bits 32 | 32 bits 48 | 48 bits
        - `screenWidth` integer, required — Total height of the Cardholder's screen in pixels.
        - `screenHeight` integer, required — Total height of the Cardholder's screen in pixels.
        - `tz` integer, required — Time difference between UTC time and the Cardholder browser local time, in minutes.
      - `headerContent` string, required — Exact content of the HTTP user-agent header.
      - `challengeWindowSize` '01' | '02' | '03' | '04' | '05', required — Dimensions of the challenge window that will be displayed to the cardholder. The issuer replies with content that is formatted to appropriately render in this window to provide the best possible user experience. Preconfigured window sizes are given in “width x height” in pixels. Value| Description -----|------------ 01 | 250 x 400 02 | 390 x 400 03 | 500 x 600 04 | 600 x 400 05 | Full screen
      - `transType` '01' | '03' | '10' | '11' | '28', required — Identifies the type of transaction being authenticated. The values are derived from ISO 8583. Value| Description -----|------------ 01 | Goods / Service purchase 03 | Check Acceptance 10 | Account Funding 11 | Quasi-Cash Transaction 28 | Prepaid activation and Loan
      - `channel` '01' | '02' | '03', required — Indicates the type of channel interface being used to initiate the transaction. Value| Description -----|------------ 01 | App-based (APP) 02 | Browser (BRW) 03 | 3DS Requestor Initiated (3RI)
      - `addressMatch` boolean — Indicates whether the Cardholder Shipping Address and Cardholder Billing Address are identical. Value | Description ------|------------ true | Shipping Address matches Billing Address false | Shipping Address does not match Billing Address
      - `reqChallengeInd` '01' | '02' | '03' | '04' | '05' | '06' | '07' | '08' | '09' — Indicates whether a challenge is requested for this transaction. For example: For payment authentication, a merchant may have concerns about the transaction, and request a challenge. Value| Description -----|------------ 01 | No preference 02 | No challenge requested 03 | Challenge requested by merchant 04 | Challenge requested: Mandate 05 | No Challenge Requested, transactional risk analysis is already performed 06 | No Challenge Requested, Data share only 07 | No Challenge Requested, SCA is already performed 08 | No challenge requested (utilise whitelist exemption if no challenge required) 09 | Challenge requested (whitelist prompt requested if challenge required)"
    - `completionUrl` string, required — Contains the merchant URL to which the browser should be redirected after the challenge session.
    - `risk` RiskTransactionRequest — **Conditional: must be sent if [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) was completed prior to processing the transaction.**
      - `tranId` string — The risk tranId value received in the [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) response. **Conditional: must be sent if [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) was completed prior to processing the transaction.**
      - `assessment` 'A' | 'D' | 'R' | 'E' — The risk assessment value received in the [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) response. **Conditional: must be sent if [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) was completed prior to processing the transaction.**
    - `apiOptions` string[] — API Options modify the request being made. See the [API Options](/guides/appendices/api-options.md) section for more information.
  - 3dsecureStandaloneTokenGtv
    - `dateTime` string, ISO 8601, required — The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm). Must be sent as the local date/time of the merchant. For example, a request processed at a merchant in the Pacific time zone at 9:18am on April 15th 2021 would be sent as 2021-04-15T09:18:23.283-07:00
    - `amount` AmountTotalOnly, required — Object containing information regarding the amount being requested. The `total` field within the object is required and specifies the amount being requested. Note: For merchants that are configured to allow multiple currencies, the amount fields can specify up to three decimal places. However, the number of decimal places can not exceed the number allowed for the specified currency. See the [Currency Codes](/guides/appendices/currency-codes) section for details.
      - `total` number, required — The amount being charged for a particular transaction. If other amount fields are sent, they must be included in the total amount. Amount cannot be zero.
    - `currencyCode` string, ISO 4217 3 Character Alphabetic Code, required — Transaction currency code. See the [Currency Codes](/guides/appendices/currency-codes) section for details. **Note: This is currently supported when processing for a merchant outside of the US and Canada. If processing for a US or Canadian merchant then this field will be ignored and the transaction will process in the merchant's configured currency.**
    - `customer` object, required
      - `firstName` string, required — Specifies a consumer’s first name. This field is used in AVS. If the interface sends this field, the value specified by the interface will be returned in the response, unless the API Option [USECARDNAME](/guides/appendices/api-options#usecardname) is included in the request and a Commerce Engine or UTG-controlled PIN pad is in use. If the interface does not send the `customer` object, the consumer's name will be returned in the `customer` object if the name is present in the card's EMV or track data.
      - `lastName` string, required — Specifies a consumer’s last name. This field is used in AVS. If the interface sends this field, the value specified by the interface will be returned in the response, unless the API Option [USECARDNAME](/guides/appendices/api-options#usecardname) is included in the request and a Commerce Engine or UTG-controlled PIN pad is in use. If the interface does not send the `customer` object, the consumer's name will be returned in the `customer` object if the name is present in the card's EMV or track data.
      - `phoneNumber` string — Customer phone number
      - `phoneCountry` string — Country calling code of the phone number. Required when sending `customer.phoneNumber`.
      - `emailAddress` string, required — Customer email address.
      - `addressLine1` string — Cardholder’s street address exactly as it appears on their billing statement. This field is used in AVS. **Recommended for increasing the possibility of frictionless flow**
      - `addressLine2` string — Customer address line 2.
      - `city` string — Customer address city. **Recommended for increasing the possibility of frictionless flow**
      - `region` string — A level 2 country subdivision code according to ISO-3166-2. **Recommended for increasing the possibility of frictionless flow**
      - `postalCode` string — Cardholder’s ZIP/postal code from their billing statement. This field is used in AVS. Do not include special characters. **Note: This field only allows alphanumeric characters (a-z, A-Z, 0-9). Special characters including - are not allowed. If you are sending in zip+4 you must not include the dash so 89134-1234 would be sent as 891341234** **Recommended for increasing the possibility of frictionless flow**
      - `country` string — 2 character ISO Country Code. See the [ISO](https://www.iso.org/obp/ui/#search/code/) website for details. **Recommended for increasing the possibility of frictionless flow**
      - `ipAddress` string, required — Public source IP Address where the request originates, not the IP Address of the web server.
      - `shipping` CustomerShipping3DSecure — **Conditional: must be sent if `threeDSecure.addressMatch` is 'false'**
        - `addressLine1` string — Shipping street address - Line 1 **Recommended for increasing the possibility of frictionless flow**
        - `addressLine2` string — Shipping street address - Line 2
        - `city` string — Shipping address - City **Recommended for increasing the possibility of frictionless flow**
        - `country` string — Shipping address - 2 character ISO Country Code. **Recommended for increasing the possibility of frictionless flow**
        - `postalCode` string — Shipping address - Postal Code **Recommended for increasing the possibility of frictionless flow**
        - `region` string — Shipping address - A level 2 country subdivision code according to ISO-3166-2. **Recommended for increasing the possibility of frictionless flow**
    - `card` object, required
      - `token` CardTokenRequired, required
        - `value` string, required — This field is used to specify a card token. Whenever CHD is sent in a request, a card token will be returned in this field. Your interface should be designed to store this card token for future use. The latest card token received should be used in any subsequent request that references the same card data.
      - `expirationDate` integer — **Conditional: Send only when card data is manually entered or when using a token. This field should not be specified when using an encrypted device.** Card expiration date in MMYY format. This value should only be populated in the initial sale/authorization request.
      - `present` 'Y' | 'N' — **Conditional: Send in the initial authorization/sale request** Indicates whether a card was present (‘Y’) or not (‘N’) at the time a transaction took place. This should be set appropriately in the initial authorization/sale request. In subsequent requests, this field should be left blank or should not be sent. **Note:** Subsequent request here does not apply to the secondary request for card on file type transactions or reuse of the same card. An example of a subsequent request would be a capture after an authorization. You would not include `card.present` in the capture, which is the subsequent request. Another example is when performing an incremental authorization where you perform an authorization, followed by an incremental authorization then a capture. The second authorization (incremental) and the capture are the subsequent requests where you would not include `card.present`.
    - `transaction` object, required
      - `invoice` string, required — 10-digit invoice number assigned by the interface to identify a transaction. An invoice number serves as a unique key that identifies a transaction within a batch in Shift4's Gateway. **Note: For US and Canadian processing: Although the invoice number is sent as a JSON string it is a numeric value. No alpha characters are allowed.** **For processing outside of the US and Canada alpha characters are allowed.**
      - `notes` string — A free-form notes field that supports the use of HTML tags. This can be used for reference in [Lighthouse Transaction Manager](https://ltm.shift4test.com/) and is not sent to the authorization host. Escaped quotation marks should not be sent in the Notes field.
      - `vendorReference` string — Optional field for information that can be searched in the merchant portal.
      - `s4RiskId` string — Unique transaction identification number generated by Shift4 to identify a specific risk transaction and a field that can be searched in LTM. **Conditional: must be sent if [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) was completed prior to processing the transaction.**
    - `threeDSecure` object, required
      - `initiate` '01' | '03', required — Indicates whether to initiate the 3D Secure authentication process Value| Description -----|------------ 01 | Force 3D Secure authentication 03 | Initiate 3D Secure according to the 3D Secure Adviser result
      - `browser` ThreeDSecureBrowser, required
        - `acceptHeader` string, required — Exact content of the HTTP accept headers.
        - `javaEnabled` boolean, required — Indicates whether the cardholder's browser has the ability to execute Java. Value | Description ------|------------ true | Cardholder's browser does have the ability to execute Java. false | Cardholder's browser does not have the ability to execute Java.
        - `javascriptEnabled` boolean, required — Indicates whether the cardholder's browser has the ability to execute Javascript. Value | Description ------|------------ true | Cardholder's browser does have the ability to execute Javascript. false | Cardholder's browser does not have the ability to execute Javascript.
        - `language` string, required — Value representing the browser language as defined in IETF BCP47.
        - `colorDepth` '1' | '4' | '8' | '15' | '16' | '24' | '32' | '48', required — Value representing the bit depth of the colour palette for displaying images, in bits per pixel. Accepted values are: Value| Description -----|------------ 1 | 1 bit 4 | 4 bits 8 | 8 bits 15 | 15 bits 16 | 16 bits 24 | 24 bits 32 | 32 bits 48 | 48 bits
        - `screenWidth` integer, required — Total height of the Cardholder's screen in pixels.
        - `screenHeight` integer, required — Total height of the Cardholder's screen in pixels.
        - `tz` integer, required — Time difference between UTC time and the Cardholder browser local time, in minutes.
      - `headerContent` string, required — Exact content of the HTTP user-agent header.
      - `challengeWindowSize` '01' | '02' | '03' | '04' | '05', required — Dimensions of the challenge window that will be displayed to the cardholder. The issuer replies with content that is formatted to appropriately render in this window to provide the best possible user experience. Preconfigured window sizes are given in “width x height” in pixels. Value| Description -----|------------ 01 | 250 x 400 02 | 390 x 400 03 | 500 x 600 04 | 600 x 400 05 | Full screen
      - `transType` '01' | '03' | '10' | '11' | '28', required — Identifies the type of transaction being authenticated. The values are derived from ISO 8583. Value| Description -----|------------ 01 | Goods / Service purchase 03 | Check Acceptance 10 | Account Funding 11 | Quasi-Cash Transaction 28 | Prepaid activation and Loan
      - `channel` '01' | '02' | '03', required — Indicates the type of channel interface being used to initiate the transaction. Value| Description -----|------------ 01 | App-based (APP) 02 | Browser (BRW) 03 | 3DS Requestor Initiated (3RI)
      - `addressMatch` boolean — Indicates whether the Cardholder Shipping Address and Cardholder Billing Address are identical. Value | Description ------|------------ true | Shipping Address matches Billing Address false | Shipping Address does not match Billing Address
      - `reqChallengeInd` '01' | '02' | '03' | '04' | '05' | '06' | '07' | '08' | '09' — Indicates whether a challenge is requested for this transaction. For example: For payment authentication, a merchant may have concerns about the transaction, and request a challenge. Value| Description -----|------------ 01 | No preference 02 | No challenge requested 03 | Challenge requested by merchant 04 | Challenge requested: Mandate 05 | No Challenge Requested, transactional risk analysis is already performed 06 | No Challenge Requested, Data share only 07 | No Challenge Requested, SCA is already performed 08 | No challenge requested (utilise whitelist exemption if no challenge required) 09 | Challenge requested (whitelist prompt requested if challenge required)"
    - `completionUrl` string, required — Contains the merchant URL to which the browser should be redirected after the challenge session.
    - `risk` RiskTransactionRequest — **Conditional: must be sent if [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) was completed prior to processing the transaction.**
      - `tranId` string — The risk tranId value received in the [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) response. **Conditional: must be sent if [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) was completed prior to processing the transaction.**
      - `assessment` 'A' | 'D' | 'R' | 'E' — The risk assessment value received in the [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) response. **Conditional: must be sent if [Risk Assessment](/apis/payments-platform-rest/openapi/risk/riskassess) was completed prior to processing the transaction.**
    - `apiOptions` string[] — API Options modify the request being made. See the [API Options](/guides/appendices/api-options.md) section for more information.

## Response `200`

Request was processed

- union
  - object
    - `result` object[]
      - `dateTime` string, ISO 8601, required — The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm). Must be sent as the local date/time of the merchant. For example, a request processed at a merchant in the Pacific time zone at 9:18am on April 15th 2021 would be sent as 2021-04-15T09:18:23.283-07:00
      - `amount` Amount, required — Object containing information regarding the amount being requested. The `total` field within the object is required and specifies the amount being requested. All other fields are for informational purposes and must also be included in the `total` field. For example, a purchase of $100 with a $20 tip and $8 tax would be `128.00` in the `total` field, `20.00` in the `tip` field and `8.00` in the `tax` field. Note: For merchants that are configured to allow multiple currencies, the amount fields can specify up to three decimal places. However, the number of decimal places can not exceed the number allowed for the specified currency. See the [Currency Codes](/guides/appendices/currency-codes) section for details.
        - `total` number, required — The amount being charged for a particular transaction. If other amount fields are sent, they must be included in the total amount. Amount cannot be zero.
        - `tax` number, required — The amount of sales tax charged for a transaction. The tax amount is used by businesses to track tax expenses for accounting purposes. Identifying the tax amount also helps consumers understand the total amount that they were billed. This field is part of Level 2 card data.
        - `taxIndicator` 'Y' | 'N' — Value|Description -----|----------- Y | Tax is included N | Tax is not included
        - `cashback` number — Specifies the cashback amount in a transaction. When using a UTG-controlled PIN pad with the ALLOWCASHBACK API Option, this field will return the cashback amount requested by the consumer. The interface can also send the desired cashback amount in a request by adding it to the `amount.total` and including it in the `amount.cashback` field. This will bypass prompting the consumer for a cashback amount.
        - `iiasAmounts` IIASAmounts[] — **Conditional: Send in the request if processing for a health care merchant.** For Vision related charges you must send only `iiasAmounts.type = 4V` and the corresponding `iiasAmounts.amount` value. For all other charges, the first entry in the array should have an amount representing the total of all healthcare costs, and `iiasAmounts.type = 4S`. Any subsequent entries should contain the subtotal for each of the other expense types involved in this transaction.
          - `amount` number — The subtotal for this type of healthcare expenses.
          - `type` '4O' | '4S' | '4T' | '4U' | '4V' | '4W' | '4X' — This code classifies eligible healthcare expenses. Value|Description -----|----------- 4O | Cash Disbursement (Discover Only) – Amount of Cash Back Being Requested 4S | Healthcare (Visa/MC Only) – Qualified Medical Expenses or Over-the-Counter 4T | Transit (Visa Only) – Transit Fare Media (e.g., Commuter and Parking Passes, Mass Transit Vouchers, and Tickets) 4U | RX (Visa/MC Only) 4V | Vision (Visa Only) 4W | Clinical (Visa Only) 4X | Dental (Visa Only)
        - `surcharge` number — **Conditional: Send in the request if a surcharge was applied to the transaction.** In a sale or authorization transaction, the `surcharge` field specifies a fee amount that a consumer is charged in addition to the transaction amount. The fee amount is also added into `amount.total`. For example, if the transaction request had `amount.total = 100` and the `surcharge.percentage` was 1.5% the transaction would include `amount.total = 101.50` and `amount.surcharge = 1.50`
        - `tip` number — **Conditional: Send in the request if a tip is included.** The tip amount of the transaction.
        - `checkTotal` number — Optional field specifying the total amount of the entire bill/invoice that this transaction is part of. It can be larger than `amount.total` in scenarios where the check is being split or if a portion of the check was already paid in cash or another form of payment.
      - `currencyCode` string, ISO 4217 3 Character Alphabetic Code, required — Transaction currency code. See the [Currency Codes](/guides/appendices/currency-codes) section for details. **Note: This is currently supported when processing for a merchant outside of the US and Canada. If processing for a US or Canadian merchant then this field will be ignored and the transaction will process in the merchant's configured currency.**
      - `card` CardResponse
        - `entryMode` '1' | '2' | 'C' | 'E' | 'M' | 'Q' | 'R' — **Conditional: The Card Entry Mode should be sent in an initial request; in subsequent requests, it should be left blank or not sent. When using a Universal Transaction Gateway® (UTG®)-controlled PIN pad, this field should be left blank or not sent in a request; the UTG will capture the card entry mode and return it in the response. When P2PE data is being sent from a non-UTG controlled device, this field is not needed** The method used to capture a payment card in an authorization/sale request. Value|Description -----|----------- 1 | Track 1 Only or Dual Track (Track 1 & 2) 2 | Track 2 Only C | EMV Contactless via card or mobile wallet E | EMV Chip M | Manual Entry Q | QR Code R | Contactless MSD
        - `expirationDate` integer — **Conditional: Requires API Option "RETURNEXPDATE".** Card expiration date in MMYY format. This value will only be populated if "RETURNEXPDATE" is included in the `apiOptions` array.
        - `levelResult` string — Classifies the type of card used in an authorization/sale request. This field is returned in a response if the data is provided by the processor. See [Card Level Results]/guides/appendices/card-level-results) for a complete list of values.
        - `number` string — The card number field will always be masked when returned in a response.
        - `present` 'Y' | 'N' — **Conditional: Send in the initial authorization/sale request** Indicates whether a card was present (‘Y’) or not (‘N’) at the time a transaction took place. This should be set appropriately in the initial authorization/sale request. In subsequent requests, this field should be left blank or should not be sent. **Note:** Subsequent request here does not apply to the secondary request for card on file type transactions or reuse of the same card. An example of a subsequent request would be a capture after an authorization. You would not include `card.present` in the capture, which is the subsequent request. Another example is when performing an incremental authorization where you perform an authorization, followed by an incremental authorization then a capture. The second authorization (incremental) and the capture are the subsequent requests where you would not include `card.present`.
        - `type` 'AX' | 'AP' | 'BC' | 'CI' | 'DB' | 'GC' | 'JC' | 'MC' | 'NS' | 'PL' | 'SC' | 'VS' | 'WP' | 'YC' — An abbreviation used to specify the type of card that was used when processing a transaction. Value| Description -----|------------ AX | American Express AP | Alipay BC | Backed Card CI | Citgo DB | Debit card GC | Gift Card JC | JCB MC | Mastercard NS | Discover/JCB/Novus PL | Private Label SC | Sears Canada VS | Visa WP | WeChat Pay YC | IT’S YOUR CARD
        - `balance` CardBalance
          - `amount` number — The balance remaining on the card. Depending on which processor is being used, the balance may be returned for a gift card, debit card, EBT card, or other stored value card.
        - `securityCode` CardSecurityCodeResponse — **Conditional: Returned if card.securityCode was sent in the request.**
          - `result` 'M' | 'N' | 'P' | 'S' | 'U' | 'Y' | '1' | '2' | '3' — **Conditional: Returned if `card.securityCode.indicator` and `card.securityCode.value` are sent in the request.** The result of a CSC check. This field will be used by Shift4 to determine the value sent in the `card.securityCode.valid` field (based on the merchant’s list of accepted verification results as configured with Shift4). Value|Description -----|------------ M | CSC matched. N | CSC did not match. P | CSC not processed. S | CSC should have been present. U | Issuer unable to process. Y | CVC1 incorrect. 1 | CSC Unavailable - processor / card type does not support this parameter. 2 | An unrecognised result code was returned by the processor. 3 | No result code was returned by the processor.
          - `valid` string — **Conditional: Returned if `card.securityCode.indicator` and `card.securityCode.value` are sent in the request.** A simplified CSC check result based on the value in the `card.securityCode.result` field and the merchant’s accepted verification results as configured with Shift4. The value returned will be ‘Y’ if CSC verification passed or ‘N’ if CSC verification did not pass.
        - `token` CardTokenResponse
          - `value` string — This field is used to specify a card token. Whenever CHD is sent in a request, a card token will be returned in this field. Your interface should be designed to store this card token for future use. The latest card token received should be used in any subsequent request that references the same card data.
        - `debitType` 'girocard' | 'eftpos' | 'Interac' | 'Visa Interlink' | 'Visa US Common Debit' | 'Maestro Int'l' | 'Maestro US Common Debit' | 'Amex US Common Debit' | 'Discover US Common Debit' | 'DNA Debit' | 'UnionPay' — Specifies the type of debit card that was used when processing a transaction. Only returned if `card.type` = `DB`
      - `customer` object
        - `firstName` string — Specifies a consumer’s first name. This field is used in AVS. If the interface sends this field, the value specified by the interface will be returned in the response, unless the API Option [USECARDNAME](/guides/appendices/api-options#usecardname) is included in the request and a Commerce Engine or UTG-controlled PIN pad is in use. If the interface does not send the `customer` object, the consumer's name will be returned in the `customer` object if the name is present in the card's EMV or track data.
        - `lastName` string — Specifies a consumer’s last name. This field is used in AVS. If the interface sends this field, the value specified by the interface will be returned in the response, unless the API Option [USECARDNAME](/guides/appendices/api-options#usecardname) is included in the request and a Commerce Engine or UTG-controlled PIN pad is in use. If the interface does not send the `customer` object, the consumer's name will be returned in the `customer` object if the name is present in the card's EMV or track data.
        - `phoneNumber` string — Customer phone number
        - `emailAddress` string — Customer email address.
        - `addressLine1` string — Cardholder’s street address exactly as it appears on their billing statement. This field is used in AVS.
        - `city` string — Customer address city.
        - `region` string — A level 2 country subdivision code according to ISO-3166-2.
        - `postalCode` string — Cardholder’s ZIP/postal code from their billing statement. This field is used in AVS. Do not include special characters. **Note: This field only allows alphanumeric characters (a-z, A-Z, 0-9). Special characters including - are not allowed. If you are sending in zip+4 you must not include the dash so 89134-1234 would be sent as 891341234**
        - `country` string — 2 character ISO Country Code. See the [ISO](https://www.iso.org/obp/ui/#search/code/) website for details.
        - `ipAddress` string — Public source IP Address where the request originates, not the IP Address of the web server.
        - `shipping` CustomerShipping3DSecure — **Conditional: must be sent if `threeDSecure.addressMatch` is 'false'**
          - `addressLine1` string — Shipping street address - Line 1 **Recommended for increasing the possibility of frictionless flow**
          - `addressLine2` string — Shipping street address - Line 2
          - `city` string — Shipping address - City **Recommended for increasing the possibility of frictionless flow**
          - `country` string — Shipping address - 2 character ISO Country Code. **Recommended for increasing the possibility of frictionless flow**
          - `postalCode` string — Shipping address - Postal Code **Recommended for increasing the possibility of frictionless flow**
          - `region` string — Shipping address - A level 2 country subdivision code according to ISO-3166-2. **Recommended for increasing the possibility of frictionless flow**
      - `merchant` MerchantResponse
        - `mid` number — The merchant ID associated with the merchant account.
        - `name` string — The merchant’s business name as configured with Shift4.
      - `transaction` object
        - `authSource` 'E' | 'O' | 'A' | 'F' — In a response, a code returned by the processor to indicate which host issued the response. Value | Description -------|---------------------------- E | Engine (Online) O | Offline A | APM (Online) F | Payment Platform (Online)
        - `hostResponse` HostResponse — Returns the response code detailing why the transaction was declined. **Notes:** - **For Visa, the response codes are categorized, detailing how declined transactions may be re-attempted for approval. To avoid fees, merchants are responsible for preventing additional attempts based on the information returned.** - **Support for this field is dependent on the processor. Our demo environment does not return this field in the response.**
          - `reasonCode` string — Returns a response code from the host. Value |Category|Description ------|--------|----------- 04 | 1 | Pick Up Card 07 | 1 | Pick Up Card, Special Condition 12 | 1 | Invalid Transaction 15 | 1 | No Such Issuer 41 | 1 | Lost Card 43 | 1 | Stolen Card 46 | 1 | Closed Account 57 | 1 | Trans. not Permitted to Cardholder R0 | 1 | Stop Payment Order R1 | 1 | Revocation of Auth Order R3 | 1 | Revocation of all Authorization 03 | 2 | Invalid Merchant 19 | 2 | Re-enter Transaction 51 | 2 | Not sufficient funds 59 | 2 | Suspected Fraud 61 | 2 | Exceeds approval amount limit 62 | 2 | Restricted Card (card invalid in region or country) 65 | 2 | Exceeds withdrawal frequency limit 75 | 2 | Allowable number of PIN-entry tried exceeded 78 | 2 | Blocked, first used 86 | 2 | Cannot Verify PIN 91 | 2 | Issuer or switch inoperative 93 | 2 | Transaction cannot be completed - violation of law 96 | 2 | System malfunction N3 | 2 | Cash service not available N4 | 2 | Cash request exceeds issuer of approved limit 14 | 3 | Invalid Account 54 | 3 | Expired card or expiration date missing 55 | 3 | PIN incorrect or missing 70 | 3 | PIN data required 82 | 3 | Negative Online CAM, dCVV, iCVV, or CVV results 1A | 3 | Additional customer authentication required N7 | 3 | Decline for CVV2 Failure 05 | 4 | Do not honor 06 | 4 | General error 08 | 4 | Honor MasterCard with ID 13 | 4 | Invalid amount 21 | 4 | Invalid amount 30 | 4 | Format error 39 | 4 | No credit account 52 | 4 | No checking account 53 | 4 | No savings account 58 | 4 | Transaction not permitted-Terminal 63 | 4 | Security violation 66 | 4 | Card Acceptor call Acquirer’s security dept 67 | 4 | Hard capture (requires ATM pick-up) 68 | 4 | Response received too late 71 | 4 | PIN Not Changed 76 | 4 | Unsolicited reversal 77 | 4 | Invalid Data including AVS failures. 79 | 4 | Already reversed at switch 80 | 4 | No Financial impact 81 | 4 | Cryptographic error 92 | 4 | Unable to route transaction 94 | 4 | Duplicate Transaction B1 | 4 | Surcharge amount not permitted on debit cards or EBTfoodstamps B2 | 4 | Surcharge amount not supported by debit network issuer CV | 4 | Card Type VerificationError EA | 4 | Acct Length Err EB | 4 | Check Digit Err EC | 4 | CID Format Error HV | 4 | Hierarchy Verification Error N0 | 4 | Force STIP P5 | 4 | PIN Change/Unblock failed P6 | 4 | New PIN not accepted Z3 | 4 | Unable to go online; offline-declined \-38 | 4 | The transaction has been denied by the Gateway because 3D secure Authentication failed. Reason: {}<br><br>Note: The “Reason” part is optional and may appear according to detected reason. | D2 | 4 | Decline Retry Later All other, generic declines may be classified as a Category 4 response code.
          - `reasonDescription` string — Returns a description from the host.
          - `reattemptPermission` string — Returns one of the following values: Value |Description ----------------------------------------|----------- Reattempt not permitted | Returned when the reasonCode returned is classified as a Category 1 response code. Reattempt permitted 15 times in 30 days | Returned when the reasonCode returned is classified as a Category 2 or Category 3 response code. Reattempts permitted | Returned when the reasonCode returned is classified as a Category 4 response code.
        - `invoice` string — 10-digit invoice number assigned by the interface to identify a transaction. An invoice number serves as a unique key that identifies a transaction within a batch in Shift4's Gateway. **Note: For US and Canadian processing: Although the invoice number is sent as a JSON string it is a numeric value. No alpha characters are allowed.** **For processing outside of the US and Canada alpha characters are allowed.**
        - `responseCode` 'A' | 'C' | 'D' | 'e' | 'f' | 'P' | 'R' | 'S' — Code indicating the Shift4 host response. Value | Description | Details -------|---------------|-------- A | Approved | The 3D Secure process was approved. D | Declined | The 3D Secure process was declined.
        - `retrievalReference` string — Reference retrieval number assigned by the authorizing agency. This value is printed on some receipts.
        - `avs` AVS
          - `postalCodeVerified` 'Y' | 'N' — Identifies whether the ZIP/postal code was verified (‘Y’) or not (‘N’) in an AVS check with a processor.
          - `result` 'A' | 'E' | 'G' | 'N' | 'R' | 'S' | 'U' | 'W' | 'X' | 'Y' | 'Z' | '1' | '2' | '3' | '4' | '5' | '6' | '7' | '8' — Identifies the response code returned from an Address Verification System (AVS) check with a processor. Value|Description -----|----------- A | Street address matched, but ZIP/postal code did not match. E | Error (AVS data is invalid or not allowed). G | Card issuer does not participate in AVS. N | No street address and no ZIP/postal code match. R | Card issuer system is unavailable. S | AVS service not supported. U | Street address information unavailable. W | Street address did not match, but ZIP/postal code matched. X | Street address and 9-digit ZIP/postal code matched. Y | Street address and 5-digit ZIP code matched. Z | Only the ZIP/postal code matched. 1 | Cardholder name and ZIP match 2 | Cardholder name, address, and ZIP match 3 | Cardholder name, address match 4 | Cardholder name matches 5 | Cardholder name incorrect, ZIP matches 6 | Cardholder name incorrect; address and ZIP match 7 | Cardholder name incorrect; address matches 8 | Cardholder name, address, and ZIP do not match
          - `streetVerified` 'Y' | 'N' — Identifies whether the street number was verified (‘Y’) or not (‘N’) in an AVS check with a processor.
          - `valid` 'Y' | 'N' — Simplified AVS result based on the merchant’s list of accepted responses as configured with Shift4: (‘Y’) if accepted or (‘N’) if not accepted.
      - `threeDSecure` object
        - `trxId` string — The assigned 3D Secure transaction ID
        - `cardholderInfo` string — Provides additional information to the customer in particular cases when 3D secure Authentication failed.
        - `cryptogram` string — Ecommerce Cryptogram information
        - `programProtocol` '1' | '2' | '3' | '4' | '5' | '6' | '7' | '8' | '9' — Indicates the 3D Secure protocol version. **Required when processing for merchants in the United States. For merchants outside of the United States use the `threeDSecure.version` field instead.** |Value| Description |-----|----------------------------| | 1 | EMV 3-D Secure Version 2.1 | | 2 | EMV 3-D Secure Version 2.2 | | 3 | EMV 3-D Secure Version 2.3 | | 4 | EMV 3-D Secure Version 2.4 | | 5 | EMV 3-D Secure Version 2.5 | | 6 | EMV 3-D Secure Version 2.6 | | 7 | EMV 3-D Secure Version 2.7 | | 8 | EMV 3-D Secure Version 2.8 | | 9 | EMV 3-D Secure Version 2.9 |
        - `directoryServerTranId` string — The Directory Server Transaction ID is generated by the EMV 3DS Mastercard Directory Server during the authentication transaction and passed back to the merchant with the authentication results. This field allows the merchant to pass the Directory Server Transaction ID during authorization in order to link authentication and authorization data for Mastercard Identity Check.
        - `ecommIndicator` '5' | '6' | '7' — E-commerce Indicator as provided by the application generating the cryptogram. Value| Description -----|------------ 5 | Secure electronic commerce transaction 6 | Authentication attempted, non-authenticated security transaction 7 | Non-authenticated Security Transaction
        - `securityLevelIndicator` string — This field contains the electronic commerce indicators representing the security level and cardholder authentication associated with the transaction. This field must be present in all Auth Request messages for electronic commerce transactions. First 2 positions: Value| Description -----|------------ 21 | Channel encryption; cardholder certificate not used (preferred value for Mastercard SecureCode, Identity Check, and all eCommerce) 22 | Masterpass-generated transaction 24 | Digital Secure Remote Payment (DSRP) with UCAF Data 91 | No security protocol; cardholder certificate not used Third position: Value| Description -----|------------ 0 | UCAF Data collection is not supported by the merchant; or the merchant supports SecureCode or Identity Check but has chosen not to undertake it on this transaction; or authentication failed and merchant desires to proceed with the transaction. 1 | UCAF data collection is supported by the merchant and UCAF data must be present and contain an attempt AAV 2 | UCAF data collection is supported by the merchant and UCAF data must be present and contain a fully authenticated AAV 3 | UCAF data collection is supported by the merchant and UCAF (Mastercard assigned Static Accountholder Authentication Value) data must be present. Note that the UCAF Data is required for Static AAV transactions. This value identifies participation in one of the following programs: Maestro Recurring Payments Program, Mastercard Utility Payment Program, Maestro Static AAV for Masterpass 4 | Merchant has chosen to share authentication data within authorization; UCAF data collection not supported
      - `receipt` Receipt[] — Array of receipt key/value pairs that should be printed on the receipt.
        - `key` string — The identifier the interface vendor can use to programmatically determine where to print a specific value.
        - `printName` string — The label that relates to the `printValue` field. When present in the response, this must be printed to the left of the `printValue`.
        - `printValue` string — The value that relates to the `printName` field. This must be printed to the right of the `printName`.
      - `server` Server
        - `name` string — The name of the server that processed the request.
      - `universalToken` UniversalToken
        - `value` string — An identifier for a card or payment account across all Shift4 merchants.
      - `cardBrandToken` CardBrandToken
        - `requestorId` string, required — This field uniquely identifies the pairing of token requestor with the token domain. It is assigned by the token service provider and is unique within the token vault. For Apple Pay requests, this is mapped from the `token.paymentData.data.deviceManufacturerIdentifier` field
        - `assuranceLevel` string — This is a response field defined by the token service provider. This Visa, Discover, or Mastercard value indicates the assigned confidence level of the token-to-PAN/cardholder binding.
        - `panLast4` string — This is a response field that contains 4 characters that represent the last 4 digits of the actual cardholder PAN.
        - `acctRangeStatus` string — This is a response field contains a one-character value that indicates the Visa regulatory status of the actual card number for which the token represents. Value| Description -----|------------ space| Blank/no value R | Regulated N | Non-Regulated
  - object
    - `result` object[]
      - `dateTime` string, ISO 8601, required — The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm). Must be sent as the local date/time of the merchant. For example, a request processed at a merchant in the Pacific time zone at 9:18am on April 15th 2021 would be sent as 2021-04-15T09:18:23.283-07:00
      - `amount` Amount, required — Object containing information regarding the amount being requested. The `total` field within the object is required and specifies the amount being requested. All other fields are for informational purposes and must also be included in the `total` field. For example, a purchase of $100 with a $20 tip and $8 tax would be `128.00` in the `total` field, `20.00` in the `tip` field and `8.00` in the `tax` field. Note: For merchants that are configured to allow multiple currencies, the amount fields can specify up to three decimal places. However, the number of decimal places can not exceed the number allowed for the specified currency. See the [Currency Codes](/guides/appendices/currency-codes) section for details.
        - `total` number, required — The amount being charged for a particular transaction. If other amount fields are sent, they must be included in the total amount. Amount cannot be zero.
        - `tax` number, required — The amount of sales tax charged for a transaction. The tax amount is used by businesses to track tax expenses for accounting purposes. Identifying the tax amount also helps consumers understand the total amount that they were billed. This field is part of Level 2 card data.
        - `taxIndicator` 'Y' | 'N' — Value|Description -----|----------- Y | Tax is included N | Tax is not included
        - `cashback` number — Specifies the cashback amount in a transaction. When using a UTG-controlled PIN pad with the ALLOWCASHBACK API Option, this field will return the cashback amount requested by the consumer. The interface can also send the desired cashback amount in a request by adding it to the `amount.total` and including it in the `amount.cashback` field. This will bypass prompting the consumer for a cashback amount.
        - `iiasAmounts` IIASAmounts[] — **Conditional: Send in the request if processing for a health care merchant.** For Vision related charges you must send only `iiasAmounts.type = 4V` and the corresponding `iiasAmounts.amount` value. For all other charges, the first entry in the array should have an amount representing the total of all healthcare costs, and `iiasAmounts.type = 4S`. Any subsequent entries should contain the subtotal for each of the other expense types involved in this transaction.
          - `amount` number — The subtotal for this type of healthcare expenses.
          - `type` '4O' | '4S' | '4T' | '4U' | '4V' | '4W' | '4X' — This code classifies eligible healthcare expenses. Value|Description -----|----------- 4O | Cash Disbursement (Discover Only) – Amount of Cash Back Being Requested 4S | Healthcare (Visa/MC Only) – Qualified Medical Expenses or Over-the-Counter 4T | Transit (Visa Only) – Transit Fare Media (e.g., Commuter and Parking Passes, Mass Transit Vouchers, and Tickets) 4U | RX (Visa/MC Only) 4V | Vision (Visa Only) 4W | Clinical (Visa Only) 4X | Dental (Visa Only)
        - `surcharge` number — **Conditional: Send in the request if a surcharge was applied to the transaction.** In a sale or authorization transaction, the `surcharge` field specifies a fee amount that a consumer is charged in addition to the transaction amount. The fee amount is also added into `amount.total`. For example, if the transaction request had `amount.total = 100` and the `surcharge.percentage` was 1.5% the transaction would include `amount.total = 101.50` and `amount.surcharge = 1.50`
        - `tip` number — **Conditional: Send in the request if a tip is included.** The tip amount of the transaction.
        - `checkTotal` number — Optional field specifying the total amount of the entire bill/invoice that this transaction is part of. It can be larger than `amount.total` in scenarios where the check is being split or if a portion of the check was already paid in cash or another form of payment.
      - `currencyCode` string, ISO 4217 3 Character Alphabetic Code, required — Transaction currency code. See the [Currency Codes](/guides/appendices/currency-codes) section for details. **Note: This is currently supported when processing for a merchant outside of the US and Canada. If processing for a US or Canadian merchant then this field will be ignored and the transaction will process in the merchant's configured currency.**
      - `card` CardResponse3DSChallenge
        - `entryMode` '1' | '2' | 'C' | 'E' | 'M' | 'Q' | 'R' — **Conditional: The Card Entry Mode should be sent in an initial request; in subsequent requests, it should be left blank or not sent. When using a Universal Transaction Gateway® (UTG®)-controlled PIN pad, this field should be left blank or not sent in a request; the UTG will capture the card entry mode and return it in the response. When P2PE data is being sent from a non-UTG controlled device, this field is not needed** The method used to capture a payment card in an authorization/sale request. Value|Description -----|----------- 1 | Track 1 Only or Dual Track (Track 1 & 2) 2 | Track 2 Only C | EMV Contactless via card or mobile wallet E | EMV Chip M | Manual Entry Q | QR Code R | Contactless MSD
        - `number` string — The card number field will always be masked when returned in a response.
        - `expirationDate` integer — **Conditional: Requires API Option "RETURNEXPDATE".** Card expiration date in MMYY format. This value will only be populated if "RETURNEXPDATE" is included in the `apiOptions` array.
        - `present` 'Y' | 'N' — **Conditional: Send in the initial authorization/sale request** Indicates whether a card was present (‘Y’) or not (‘N’) at the time a transaction took place. This should be set appropriately in the initial authorization/sale request. In subsequent requests, this field should be left blank or should not be sent. **Note:** Subsequent request here does not apply to the secondary request for card on file type transactions or reuse of the same card. An example of a subsequent request would be a capture after an authorization. You would not include `card.present` in the capture, which is the subsequent request. Another example is when performing an incremental authorization where you perform an authorization, followed by an incremental authorization then a capture. The second authorization (incremental) and the capture are the subsequent requests where you would not include `card.present`.
        - `type` 'AX' | 'AP' | 'BC' | 'CI' | 'DB' | 'GC' | 'JC' | 'MC' | 'NS' | 'PL' | 'SC' | 'VS' | 'WP' | 'YC' — An abbreviation used to specify the type of card that was used when processing a transaction. Value| Description -----|------------ AX | American Express AP | Alipay BC | Backed Card CI | Citgo DB | Debit card GC | Gift Card JC | JCB MC | Mastercard NS | Discover/JCB/Novus PL | Private Label SC | Sears Canada VS | Visa WP | WeChat Pay YC | IT’S YOUR CARD
        - `token` CardTokenResponse
          - `value` string — This field is used to specify a card token. Whenever CHD is sent in a request, a card token will be returned in this field. Your interface should be designed to store this card token for future use. The latest card token received should be used in any subsequent request that references the same card data.
      - `customer` object
        - `firstName` string — Specifies a consumer’s first name. This field is used in AVS. If the interface sends this field, the value specified by the interface will be returned in the response, unless the API Option [USECARDNAME](/guides/appendices/api-options#usecardname) is included in the request and a Commerce Engine or UTG-controlled PIN pad is in use. If the interface does not send the `customer` object, the consumer's name will be returned in the `customer` object if the name is present in the card's EMV or track data.
        - `lastName` string — Specifies a consumer’s last name. This field is used in AVS. If the interface sends this field, the value specified by the interface will be returned in the response, unless the API Option [USECARDNAME](/guides/appendices/api-options#usecardname) is included in the request and a Commerce Engine or UTG-controlled PIN pad is in use. If the interface does not send the `customer` object, the consumer's name will be returned in the `customer` object if the name is present in the card's EMV or track data.
        - `phoneNumber` string — Customer phone number
        - `emailAddress` string — Customer email address.
        - `addressLine1` string — Cardholder’s street address exactly as it appears on their billing statement. This field is used in AVS.
        - `city` string — Customer address city.
        - `region` string — A level 2 country subdivision code according to ISO-3166-2.
        - `postalCode` string — Cardholder’s ZIP/postal code from their billing statement. This field is used in AVS. Do not include special characters. **Note: This field only allows alphanumeric characters (a-z, A-Z, 0-9). Special characters including - are not allowed. If you are sending in zip+4 you must not include the dash so 89134-1234 would be sent as 891341234**
        - `country` string — 2 character ISO Country Code. See the [ISO](https://www.iso.org/obp/ui/#search/code/) website for details.
        - `ipAddress` string — Public source IP Address where the request originates, not the IP Address of the web server.
        - `shipping` CustomerShipping3DSecure — **Conditional: must be sent if `threeDSecure.addressMatch` is 'false'**
          - `addressLine1` string — Shipping street address - Line 1 **Recommended for increasing the possibility of frictionless flow**
          - `addressLine2` string — Shipping street address - Line 2
          - `city` string — Shipping address - City **Recommended for increasing the possibility of frictionless flow**
          - `country` string — Shipping address - 2 character ISO Country Code. **Recommended for increasing the possibility of frictionless flow**
          - `postalCode` string — Shipping address - Postal Code **Recommended for increasing the possibility of frictionless flow**
          - `region` string — Shipping address - A level 2 country subdivision code according to ISO-3166-2. **Recommended for increasing the possibility of frictionless flow**
      - `merchant` MerchantResponse
        - `mid` number — The merchant ID associated with the merchant account.
        - `name` string — The merchant’s business name as configured with Shift4.
      - `transaction` object
        - `authSource` 'E' | 'O' | 'A' | 'F' — In a response, a code returned by the processor to indicate which host issued the response. Value | Description -------|---------------------------- E | Engine (Online) O | Offline A | APM (Online) F | Payment Platform (Online)
        - `invoice` string — 10-digit invoice number assigned by the interface to identify a transaction. An invoice number serves as a unique key that identifies a transaction within a batch in Shift4's Gateway. **Note: For US and Canadian processing: Although the invoice number is sent as a JSON string it is a numeric value. No alpha characters are allowed.** **For processing outside of the US and Canada alpha characters are allowed.**
        - `responseCode` 'H' — Response code indicating that the 3D Secure transaction requires device fingerprinting. Value |Description -------|----------- H | Device fingerprinting required. Issuer fingerprint URL returned in the redirectURL field. See [Handling Device Fingerprint Response](/guides/advanced-concepts/3d-secure#handling-device-fingerprint-response) for details on how to handle the Device Fingerprint process.
        - `retrievalReference` string — Reference retrieval number assigned by the authorizing agency. This value is printed on some receipts.
      - `threeDSecure` object, required
        - `trxId` string, required — The assigned 3D Secure transaction ID
      - `redirectUrl` string, required — URL to redirect the browser to the 3D Secure transaction response indicates a Device Fingerprint or 3D Secure challenge is required.
      - `server` Server
        - `name` string — The name of the server that processed the request.
  - object
    - `result` object[]
      - `dateTime` string, ISO 8601, required — The date and time in ISO 8601 format including the timezone offset (yyyy-mm-ddThh:mm:ss.nnn+hh:mm). Must be sent as the local date/time of the merchant. For example, a request processed at a merchant in the Pacific time zone at 9:18am on April 15th 2021 would be sent as 2021-04-15T09:18:23.283-07:00
      - `amount` Amount, required — Object containing information regarding the amount being requested. The `total` field within the object is required and specifies the amount being requested. All other fields are for informational purposes and must also be included in the `total` field. For example, a purchase of $100 with a $20 tip and $8 tax would be `128.00` in the `total` field, `20.00` in the `tip` field and `8.00` in the `tax` field. Note: For merchants that are configured to allow multiple currencies, the amount fields can specify up to three decimal places. However, the number of decimal places can not exceed the number allowed for the specified currency. See the [Currency Codes](/guides/appendices/currency-codes) section for details.
        - `total` number, required — The amount being charged for a particular transaction. If other amount fields are sent, they must be included in the total amount. Amount cannot be zero.
        - `tax` number, required — The amount of sales tax charged for a transaction. The tax amount is used by businesses to track tax expenses for accounting purposes. Identifying the tax amount also helps consumers understand the total amount that they were billed. This field is part of Level 2 card data.
        - `taxIndicator` 'Y' | 'N' — Value|Description -----|----------- Y | Tax is included N | Tax is not included
        - `cashback` number — Specifies the cashback amount in a transaction. When using a UTG-controlled PIN pad with the ALLOWCASHBACK API Option, this field will return the cashback amount requested by the consumer. The interface can also send the desired cashback amount in a request by adding it to the `amount.total` and including it in the `amount.cashback` field. This will bypass prompting the consumer for a cashback amount.
        - `iiasAmounts` IIASAmounts[] — **Conditional: Send in the request if processing for a health care merchant.** For Vision related charges you must send only `iiasAmounts.type = 4V` and the corresponding `iiasAmounts.amount` value. For all other charges, the first entry in the array should have an amount representing the total of all healthcare costs, and `iiasAmounts.type = 4S`. Any subsequent entries should contain the subtotal for each of the other expense types involved in this transaction.
          - `amount` number — The subtotal for this type of healthcare expenses.
          - `type` '4O' | '4S' | '4T' | '4U' | '4V' | '4W' | '4X' — This code classifies eligible healthcare expenses. Value|Description -----|----------- 4O | Cash Disbursement (Discover Only) – Amount of Cash Back Being Requested 4S | Healthcare (Visa/MC Only) – Qualified Medical Expenses or Over-the-Counter 4T | Transit (Visa Only) – Transit Fare Media (e.g., Commuter and Parking Passes, Mass Transit Vouchers, and Tickets) 4U | RX (Visa/MC Only) 4V | Vision (Visa Only) 4W | Clinical (Visa Only) 4X | Dental (Visa Only)
        - `surcharge` number — **Conditional: Send in the request if a surcharge was applied to the transaction.** In a sale or authorization transaction, the `surcharge` field specifies a fee amount that a consumer is charged in addition to the transaction amount. The fee amount is also added into `amount.total`. For example, if the transaction request had `amount.total = 100` and the `surcharge.percentage` was 1.5% the transaction would include `amount.total = 101.50` and `amount.surcharge = 1.50`
        - `tip` number — **Conditional: Send in the request if a tip is included.** The tip amount of the transaction.
        - `checkTotal` number — Optional field specifying the total amount of the entire bill/invoice that this transaction is part of. It can be larger than `amount.total` in scenarios where the check is being split or if a portion of the check was already paid in cash or another form of payment.
      - `currencyCode` string, ISO 4217 3 Character Alphabetic Code, required — Transaction currency code. See the [Currency Codes](/guides/appendices/currency-codes) section for details. **Note: This is currently supported when processing for a merchant outside of the US and Canada. If processing for a US or Canadian merchant then this field will be ignored and the transaction will process in the merchant's configured currency.**
      - `card` CardResponse3DSChallenge
        - `entryMode` '1' | '2' | 'C' | 'E' | 'M' | 'Q' | 'R' — **Conditional: The Card Entry Mode should be sent in an initial request; in subsequent requests, it should be left blank or not sent. When using a Universal Transaction Gateway® (UTG®)-controlled PIN pad, this field should be left blank or not sent in a request; the UTG will capture the card entry mode and return it in the response. When P2PE data is being sent from a non-UTG controlled device, this field is not needed** The method used to capture a payment card in an authorization/sale request. Value|Description -----|----------- 1 | Track 1 Only or Dual Track (Track 1 & 2) 2 | Track 2 Only C | EMV Contactless via card or mobile wallet E | EMV Chip M | Manual Entry Q | QR Code R | Contactless MSD
        - `number` string — The card number field will always be masked when returned in a response.
        - `expirationDate` integer — **Conditional: Requires API Option "RETURNEXPDATE".** Card expiration date in MMYY format. This value will only be populated if "RETURNEXPDATE" is included in the `apiOptions` array.
        - `present` 'Y' | 'N' — **Conditional: Send in the initial authorization/sale request** Indicates whether a card was present (‘Y’) or not (‘N’) at the time a transaction took place. This should be set appropriately in the initial authorization/sale request. In subsequent requests, this field should be left blank or should not be sent. **Note:** Subsequent request here does not apply to the secondary request for card on file type transactions or reuse of the same card. An example of a subsequent request would be a capture after an authorization. You would not include `card.present` in the capture, which is the subsequent request. Another example is when performing an incremental authorization where you perform an authorization, followed by an incremental authorization then a capture. The second authorization (incremental) and the capture are the subsequent requests where you would not include `card.present`.
        - `type` 'AX' | 'AP' | 'BC' | 'CI' | 'DB' | 'GC' | 'JC' | 'MC' | 'NS' | 'PL' | 'SC' | 'VS' | 'WP' | 'YC' — An abbreviation used to specify the type of card that was used when processing a transaction. Value| Description -----|------------ AX | American Express AP | Alipay BC | Backed Card CI | Citgo DB | Debit card GC | Gift Card JC | JCB MC | Mastercard NS | Discover/JCB/Novus PL | Private Label SC | Sears Canada VS | Visa WP | WeChat Pay YC | IT’S YOUR CARD
        - `token` CardTokenResponse
          - `value` string — This field is used to specify a card token. Whenever CHD is sent in a request, a card token will be returned in this field. Your interface should be designed to store this card token for future use. The latest card token received should be used in any subsequent request that references the same card data.
      - `customer` object
        - `firstName` string — Specifies a consumer’s first name. This field is used in AVS. If the interface sends this field, the value specified by the interface will be returned in the response, unless the API Option [USECARDNAME](/guides/appendices/api-options#usecardname) is included in the request and a Commerce Engine or UTG-controlled PIN pad is in use. If the interface does not send the `customer` object, the consumer's name will be returned in the `customer` object if the name is present in the card's EMV or track data.
        - `lastName` string — Specifies a consumer’s last name. This field is used in AVS. If the interface sends this field, the value specified by the interface will be returned in the response, unless the API Option [USECARDNAME](/guides/appendices/api-options#usecardname) is included in the request and a Commerce Engine or UTG-controlled PIN pad is in use. If the interface does not send the `customer` object, the consumer's name will be returned in the `customer` object if the name is present in the card's EMV or track data.
        - `phoneNumber` string — Customer phone number
        - `emailAddress` string — Customer email address.
        - `addressLine1` string — Cardholder’s street address exactly as it appears on their billing statement. This field is used in AVS.
        - `city` string — Customer address city.
        - `region` string — A level 2 country subdivision code according to ISO-3166-2.
        - `postalCode` string — Cardholder’s ZIP/postal code from their billing statement. This field is used in AVS. Do not include special characters. **Note: This field only allows alphanumeric characters (a-z, A-Z, 0-9). Special characters including - are not allowed. If you are sending in zip+4 you must not include the dash so 89134-1234 would be sent as 891341234**
        - `country` string — 2 character ISO Country Code. See the [ISO](https://www.iso.org/obp/ui/#search/code/) website for details.
        - `ipAddress` string — Public source IP Address where the request originates, not the IP Address of the web server.
        - `shipping` CustomerShipping3DSecure — **Conditional: must be sent if `threeDSecure.addressMatch` is 'false'**
          - `addressLine1` string — Shipping street address - Line 1 **Recommended for increasing the possibility of frictionless flow**
          - `addressLine2` string — Shipping street address - Line 2
          - `city` string — Shipping address - City **Recommended for increasing the possibility of frictionless flow**
          - `country` string — Shipping address - 2 character ISO Country Code. **Recommended for increasing the possibility of frictionless flow**
          - `postalCode` string — Shipping address - Postal Code **Recommended for increasing the possibility of frictionless flow**
          - `region` string — Shipping address - A level 2 country subdivision code according to ISO-3166-2. **Recommended for increasing the possibility of frictionless flow**
      - `merchant` MerchantResponse
        - `mid` number — The merchant ID associated with the merchant account.
        - `name` string — The merchant’s business name as configured with Shift4.
      - `transaction` object
        - `authSource` 'E' | 'O' | 'A' | 'F' — In a response, a code returned by the processor to indicate which host issued the response. Value | Description -------|---------------------------- E | Engine (Online) O | Offline A | APM (Online) F | Payment Platform (Online)
        - `invoice` string — 10-digit invoice number assigned by the interface to identify a transaction. An invoice number serves as a unique key that identifies a transaction within a batch in Shift4's Gateway. **Note: For US and Canadian processing: Although the invoice number is sent as a JSON string it is a numeric value. No alpha characters are allowed.** **For processing outside of the US and Canada alpha characters are allowed.**
        - `responseCode` 'G' — Response code indicating that the 3D Secure transaction requires a challenge. Value |Description -------|----------- G | 3D Secure challenge required. Issuer challenge URL returned in the redirectURL field.
        - `retrievalReference` string — Reference retrieval number assigned by the authorizing agency. This value is printed on some receipts.
      - `threeDSecure` object, required
        - `trxId` string, required — The assigned 3D Secure transaction ID
      - `redirectUrl` string, required — URL to redirect the browser to the 3D Secure transaction response indicates a Device Fingerprint or 3D Secure challenge is required.
      - `server` Server
        - `name` string — The name of the server that processed the request.

## Other responses

- `400` — Error
- `504` — Timeout

---

[API](https://skmtc.dev/shift4/apis/shift4-payment-api.md) · [All operations](https://skmtc.dev/shift4/apis/shift4-payment-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/shift4/shift4-payment-api/revisions/2f85c87cc9e5/schema)
