3-D Secure: lists the merchant's provider bindings.
GET
/api/merchants/{id}/three-d-secure-bindings
deprecated
No permission required.
Example: `GET /api/merchants/3fa85f64-5717-4562-b3fc-2c963f66afa6/three-d-secure-bindings`.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a . See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
id
required |
path | string (uuid) | The merchant id. |
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
Request body
application/json
, required
| Field | Type | Description |
|---|
This request body has no documented fields.
Responses
200 OK
Body: array of MerchantThreeDSBinding
Each item has these fields.
| Field | Type | Description |
|---|---|---|
providerType
required |
all of ThreeDSProviderType | Which 3-D Secure provider this entry binds the merchant to. A null provider type is treated as no binding at all rather than as `Fake`, so an incompletely boarded row cannot silently become a live selection. nullable |
isEnabled
required |
boolean | Master enable flag for this provider on this merchant. When `false` or null, the binding is not used even though the row exists. nullable |
policyMode
required |
all of ThreeDSPolicyMode | How hard the merchant wants authentication applied. Null means the platform default, which callers read as `Off`. nullable |
apiKey
required |
string | The vendor API key. Not a secret in the sense the JWT secret is (it is sent as a request header and appears as a JWT audience), so it round-trips on reads; it is still never logged. Required: When IsEnabled is true. nullablemax length 256 |
jwtSecret
required |
string | The shared secret the request JWT is signed with. <b>Stored encrypted.</b> It is stripped, not decrypted, on every read that leaves the server: the admin UI and the API both see null here and re-send the secret only when the operator changes it. Only the server-side call to the provider ever uses the plaintext. nullablemax length 512 |
jwtSecretConfigured
required |
boolean | Whether a JWT secret is stored for this binding, for the editor that is never allowed to see the secret itself. nullable |
endpointEnvironment
required |
all of ThreeDSEndpointEnvironment | Which of the vendor's environments this binding points at. Null reads as `Sandbox`. nullable |
requestorUrl
required |
string | The merchant-facing origin the vendor validates authentication requests against: the HPP or checkout origin the cardholder's browser is on. HTTPS only. Conditional: When RequestorUrl is not empty. Required: When IsEnabled is true. nullablemax length 512 |
challengeEnabled
required |
boolean | Whether the merchant permits the vendor to raise an interactive challenge. Null reads as not enabled. nullable |
protocolVersion
required |
string | The 3-D Secure protocol version to request, from `SupportedProtocolVersions`. Null means the provider's own default. Conditional: When ProtocolVersion is not empty. nullablemax length 16 |
providerRegistrationId
required |
string (uuid) | Optional pointer at a vendor-side registration record for this merchant, for vendors that board a merchant out of band and hand back an identifier. Nullable because most bindings carry credentials and nothing else, and because a deleted registration should leave an inspectable dangling reference rather than a hard failure. nullable |
This response has no documented body fields.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
400 Bad Request
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.