Approve with step-up authentication
Step-up authentication is typically used for Tokenization with xPay Wallets. It does not apply to Tokenization initiated by an e-commerce merchant.
A step-up authentication decision (YELLOW) means D1 has conditionally approved Tokenization. Before the payment network TSP can provision and activate the digital card, the End User must complete an additional authentication step (an ID&V method).
What happens next
D1 returns a YELLOW decision to the payment network TSP, along with the supported ID&V methods.
The token requestor prompts the End User to complete one of the supported methods.
If authentication succeeds, the payment network TSP completes provisioning and activates the digital card (payment network behavior).
D1 can notify your issuer backend of the Tokenization outcome and optionally send End User notifications (depending on what you enabled during D1 onboarding). For details, see Processing the response.
Common triggers
Step-up authentication is commonly triggered when D1 detects higher risk, for example:
Phone number mismatch between End User data provided by the Issuer and the phone number provided by the payment network TSP. See Decision engine > End User (consumer).
Missing CSC for a capture method where the CSC is expected. See Decision engine > Card capture.
Supported ID&V methods
When D1 returns YELLOW, it provides the payment network TSP with the list of supported ID&V methods.
OTP by SMS/email – The payment network generates the OTP. The Issuer (or D1 on behalf of the Issuer) delivers it to the End User.
In-app authentication backend – The End User authenticates in the issuer application, and the Issuer activates the digital card.
Customer service – The End User authenticates through the Issuer’s customer service process.
The methods that can be used depend on the Issuer’s ability to provide the required data. For example, if the Issuer does not have contact details such as an email address or phone number, those methods will not be available.
If you do not want D1 to send OTPs, you must support the Deliver OTP API.
Last updated
Was this helpful?