On This Page
REST API | GPX
Authorization with an SCA Exemption
A strong customer authentication (SCA) exemption enables you to remain in compliance with the EU's second Payment Services Directive. Depending on your processor, use one of the following exemption fields:
IMPORTANT
If you send more than one SCA exemption field with a single
authentication, the transaction will be denied.
- Authentication Outage: Payer authentication is not available for this transaction due to a system outage.
- B2B Corporate Card: Payment cards specifically for business-to-business transactions are exempt.
- Delegated Authentication: Payer authentication was performed outside of the authorization workflow.
- Follow-On Installment Payment: Installment payments of a fixed amount are exempt after the first transaction.
- Follow-On Recurring Payment: Recurring payments of a fixed amount are exempt after the first transaction.
- Low Risk: The average fraud levels associated with this transaction are considered low.
- Low Value: The transaction value does not warrant SCA.
- Merchant Initiated Transactions: As follow-on transactions, merchant-initiated transactions are exempt.
- Stored Credential Transaction: Credentials are authenticated before storing, so stored credential transactions are exempt.
- Trusted Merchant: Merchants registered as trusted beneficiaries.
Fields Specific to This Use Case
Use these fields to request an SCA exemption:
Exemption Type | Field | Value |
|---|---|---|
Stored Credential Transaction | processingInformation.
authorizationOptions.initiator. storedCredentialUsed | 1 |
Country-Specfic Requirements
These fields are specific to certain countries and regions.
Endpoint
POST
https://api.cybersource.com
/pts/v2/payments