5 Completing your 3DS Product Setup Form
The Cardinal Commerce RDX service is provided through Thredd, so you do not need to have a direct relationship with Cardinal. Thredd will provide Cardinal with instructions and set up your service.
Before we can start a project with Cardinal, you must complete the Thredd 3DS Product Setup Form (PSF) A spreadsheet that provides details of your Thredd account setup. The details are used to configure your Thredd account., which specifies your 3D Secure requirements. This form consists of three tabs:
Each of these tabs is described in further detail below.
5.1 Client Information
Complete the following details on this tab:
Field |
Description |
---|---|
Client Information |
|
Client name |
Your company’s name. |
Legal Name |
Your company’s legal name. |
Country of residence |
Your company’s country of residence. |
Card Scheme |
The payment network for your BIN. Thredd supports cards enabled for use on Visa, Mastercard and Discover payment networks. |
Visa BID |
Your issuer’s (BIN sponsor) Visa Business Identifier (BID) |
Mastercard Primary ICA Number |
Your issuer’s (BIN sponsor) primary ICA |
Mastercard Company Name (Issuer) |
Your issuer’s (BIN sponsor) Company Name, as registered with Mastercard. |
Mastercard Company ID (CID) |
Your issuer’s (BIN sponsor) Company ID, as registered with Mastercard. |
Thredd Program Manager ID |
Your Thredd Program ID or code |
Default language |
The default language for the 3D Secure screens. |
Other languages |
List any additional languages you support. See Language Support. |
SMS Sender ID |
The text that appears as the name of the sender of the SMS OTP for validation. This can be up to 11 alphanumeric characters with no spaces. |
Are you self-issuing? |
Whether your organisation is set up as an issuer (BIN sponsor). Select YES or NO. |
Issuer (BIN sponsor) name |
The name of your issuer (BIN sponsor). |
Is Compliance Manager required? |
The Compliance Manager is a Cardinal application which provides tools to identify transactions that require Strong Customer Authentication (SCA) In the Cardinal Access tab of the 3DS PSF, please specify the users who you want to be set up with access to Compliance Manager. For training on how to use Compliance Manager, please contact your 3D Secure project manager. |
Customer Support number |
The Customer Support phone number, including the country code, for cardholders to contact. |
Issuer regulator country |
The regulatory country of your Issuer (BIN sponsor) |
Are you PCI Compliant? |
Select YES or NO. If your organisation is not PCI compliant |
Do you have an existing ACS Provider? |
Whether you currently have a different provider of 3D Secure services/ a different Access Control Server (ACS) |
Have you been assigned full BIN range? Or sub BIN |
If you are using a full BIN Range for your programme, select YES, else select NO. |
Planned Go Live date |
When do you plan to launch your card programme? Please check with your Implementation Manager to confirm that this date is feasible. For steps and indicative time scales to launch a 3D Secure service, see Steps in a 3D Secure Biometric/In-app Project. |
Thredd Environment under which Program Manager is built |
Indicate your current production environment. For example:
|
Do you require Thredd to validate the AAV/CAVV? |
The AAV/CAVV If YES: Thredd will validate the AAV/CAVV
If NO:
|
Setup Options (provide details for Test and Production separately) |
|
Default authentication |
Select the default authentication type to support all sub-BIN ranges. Options are:
This is used for the following purposes: a) to enable a card to be enroled in this type; b) to use as the default type of authentication during a real-time authentication session with Cardinal; c) to support auto-enrolment. Note: Please discuss with your Implementation Manager before implementing OOB authentication. |
Fallback authentication |
Select the fallback authentication type to support all sub-BIN ranges. Options are:
This is used for two purposes: a) to enable a card to be enroled in this type; b) to use as the fallback type of authentication during a real-time authentication session with Cardinal, if the default type cannot be used for any reason. |
Biometric validation timeout |
The period (in seconds) you have to respond to a request for Biometric validation before the system times out3. The maximum is 900 seconds. This is the time from when we notify you to start authentication, up to your validation response. |
Out of Band validation timeout |
The period (in seconds) you have to respond to a request for Out of Band validation before the system times out. The maximum is 900 seconds. This is the time from when we notify you to start authentication, up to your validation response. |
The endpoint Thredd should use to send you the Biometric validation request. (Implemented using the (
Note: Your endpoint (in both production and UAT) must resolve to a single or set of static IP addresses. |
|
oAuth and NotifyValidate IP Addresses |
Provide details of the IP addresses you want Thredd to allow to use the Thredd oAuth server and NotifyValidate endpoint. |
Do you need Introspection credentials? (Optional) |
Select Yes or No. If you select Yes, Thredd will generate the credentials that will be used to validate the Token. |
Enable SMS OTP auto enrolment |
Options are: NO— All cards must be enroled for OTP SMS and the mobile number must be registered using either Web Services or Cards API; see Using the Card Enrolment API. YES - Initial Load — Thredd enrol the existing cards to the OTP SMS credential. Thredd use the phone number linked to the card (i.e., the phone number supplied when the card was created or updated). YES - Continuous — Same as Initial load, however any future cards created will also have their phone numbers automatically registered for 3D Secure in the same way. Auto-enrolment enrols all live and active cards. It is not recommended if you wish to exclude some cardholders from enrolment. If using Continuous auto-enrolment, this may restrict your ability to unenrol cards which have been previously enroled and which currently have a live status. SeeSection 8.2 Card Unenrolment. |
Enable Biometric auto enrolment |
Options are: NO— All cards must be enroled for Biometric using either Web Services or Cards API; see Using the Card Enrolment API. YES - Initial Load — Thredd creates a Biometric credential for all existing cardholders. YES - Continuous — Same as Initial load, however any future cards created will also have Biometric credentials created the same way. Auto-enrolment enrols all live and active cards. It is not recommended if you wish to exclude some cardholders from enrolment. If using Continuous auto-enrolment, this may restrict your ability to unenrol cards which have been previously enroled and which currently have a live status. See Section 8.2 Card Unenrolment.Enrol_cards_in_3DSecure.htm |
KBA Setup Options (provide details for Test and Production separately) |
|
KBA questions |
Enter the KBA questions you want to include. For each KBA question, indicate if required. You can also provide questions in other languages. See KBA Language Support. Thredd will provide you with details of the unique KBA |
Bin Ranges Low and Bin Ranges High |
|
Provide the whole range (14, 16, or 19 digit) of the Sub-BIN or BIN. If you do not own the whole BIN, please provide the SUB-BIN range. |
|
UAT testing cards /UAT product ID |
|
Provide the staging cards and their product ID you want to use for staging testing. |
|
Pilot testing cards /Production product ID |
|
Provide the pilot cards and their product ID you want to use for production testing. |
For more details, refer to the instructions in the 3DS Product Setup Form (PSF).
5.2 Cardinal Access
Please provide Thredd with a list of IP addresses you want to allow to access the Cardinal Portal. See How to Access the Cardinal Portal.
For security reasons we can only set up permission lists for client-owned static Office IP addresses; employees working remotely will need to connect securely to their office IP address. Any attempt to access Cardinal from a non-registered IP address will result in the page not being displayed.
Please provide details of the administrator users who need to access the Cardinal Portal. Thredd can set up role-based access for your users to the following Cardinal Portal applications: Customer Service Application, Rules Application, Reporting Application and Admin Application.
Any users Thredd set up with Admin level rights with full access to all Cardinal applications on the Cardinal Portal will be able to create access for additional users.
For more details, refer to the instructions in the 3DS Product Setup Form (PSF) A spreadsheet that provides details of your Thredd account setup. The details are used to configure your Thredd account..
5.3 Supported Languages
Please select the languages you want to support. You must specify a default language. You can specify additional languages and provide the translated text you want to use for each language.
Cardinal identifies the language in which to display the Authentication screens based on the cardholder’s web browser language settings (e.g., English, French).
If the cardholder uses a language that has not been configured in Cardinal (i.e., is not provided in the PSF) then Cardinal will show the screens in the default language.
The screen text limit is 350 characters.
5.3.1 KBA Language Support
If you support more than one language, you can provide translations for the Thredd questions in different languages. This is set up per card product. Questions defined in a different language will automatically generate new KBA Question IDs. See Appendix 4: KBA Questions.
Thredd cannot use a different language to what is configured as the language with Cardinal for your BIN/sub-BINs.
5.3.2 OTP SMS Text Support
For OTP SMS messages (sent by Thredd to the cardholder’s phone number), the SMS message is dynamic, and you can specify the text and variables to use. See Appendix 2: OTP Message Templates.
Please contact your Thredd 3DS project manager to ask for these SMS options to be configured.
Language is determined by checking the current value of the card’s language
setting (if using Thredd API The Thredd API consists of web services that use SOAP and the Cards API based on REST., see the Web Services Guide >Create Card; if using our Cards API
The Thredd Cards API are REST-based API that enable you to create and manage the cards in your card programme using JSON messages., see the Cards API Website > Creating a Card). Below is an example of the OTP SMS message, in French:
Figure 6: OTP SMS Message Example
The text length limit for the Thredd SMS message is 36 characters. If you pass this limit, the message will be split into two messages.