Event: card.3ds_otp
Sent when the card network requests a 3D Secure (3DS) one-time passcode (OTP) for a card issued under your partner program. Your application is responsible for delivering the OTP to the cardholder via your preferred channel (SMS, email, push notification, in-app).
3DS OTPs are time-sensitive. Deliver the OTP to your cardholder within 60 seconds of receiving this event. After that window the cardholder’s transaction may fail.
Payload
Response
Your endpoint must return a 2xx status code within 30 seconds to acknowledge receipt. Any non-2xx response or timeout triggers the retry policy, but note that retries past the 60-second OTP validity window will not help the cardholder complete the transaction.
Example handler
Security considerations
- Treat
otpCode as sensitive: do not log it, do not persist it past the immediate dispatch.
- Verify the
X-Contro-Signature header before trusting the payload — see signature verification.
- Use a fast, idempotent dispatch path. Retries can deliver the same
otpCode more than once; sending it twice to the cardholder is acceptable, but failing to send it on the first attempt is not.