# Create a 3DS Data Share Only Payment

3DS Data Share Only is a mode within EMV 3-D Secure (3DS) where transaction data is shared between the merchant, issuer, and card network for risk assessment purposes, but **no cardholder authentication challenge is performed**.

In this model:
* The merchant sends transaction and customer data through the 3DS protocol.
* The issuer receives the data and can use it for fraud detection, risk scoring, and authorization decisions.
* The transaction proceeds without requiring the cardholder to complete an authentication step (such as entering a one-time password or using biometric verification).
* The purpose is to improve fraud prevention while maintaining a frictionless customer experience.

## Requirements

Before starting the integration, complete the following:

* **API Credentials**: Contact the Integration Support Team to obtain your `client_id` and `client_secret`.
* **Access Token**: Generate a Bearer token using your credentials via the Access Token endpoint.
* **Card Brand Support**: Verify the card brand is Mastercard or Visa. These are currently supported for 3DS in Argentina, Chile, Mexico, Brazil, and Uruguay.

> **Payment facilitators**: When Getnet enables your credential as a payment facilitator, you must also send the `data.sub_merchant` object when you create the payment. See [Payment Facilitators](/en/global-api/reference-global/payment-facilitators).

## Understanding the Data Share Only Process 

Data Share Only sends transaction and cardholder data to the issuer so it can decide whether to approve the payment without presenting a challenge to the customer. Request this behavior by setting the EMV 3DS `threeDSRequestorChallengeInd` value through the `requestor_challenge_indicator` field to `"06"`, inside `extra_fields.data_only`. Because the customer never leaves your checkout page, Data Share Only removes the redirect friction of a challenge.

After you initiate enrollment, the API returns the same `status` field used in the standard 3DS flow:

1. **Direct decision**: The issuer approves or declines the transaction immediately, based on the shared data (status: `Authenticated`/`3-D Secure Data Only` or `Denied`).
2. **Pending Enrollment Continue**: The issuer requires additional processing before reaching a final state (status: `Pending Enrolment Continue`). This step may ultimately result in the success of the workflow.

## Implementation Steps

### Step 1: Obtain Access Token and Tokenize Card

Request an access token using your API credentials.

### Step 2: Initiate Enrollment with Data Share Only

Call the [3DS - Init Authentication](https://docs.globalgetnet.com/en/products/online-payments/regional-api/swagger#tag/payments/post/dpm/security-gwproxy/v2/enrolments-initial) endpoint. Include the same `extra_fields.billing_address` and `extra_fields.shipping_address` object you'd send for a standard 3DS enrollment, plus a `data_only` object with `requestor_challenge_indicator` set to `"06"`.

```bash
curl --request POST \
  --url https://api-sbx.globalgetnet.com/dpm/security-gwproxy/v2/enrolments-initial \
  --header 'authorization: Bearer <your-token>' \
  --header 'content-type: application/json' \
  --data '{
  "currency": "CLP",
  "md": "NmQyZTQzODAtZDhhMy00Y2NiLTkxMzgtYzI4OTE4MjgxOGE0",
  "term_url": "123",
  "amount": 1,
  "payment_method": {
    "expiration_month": "05",
    "expiration_year": "25",
    "security_code": "282",
    "number": "5155901222280001"
  },
  "description": "TEST",
  "operation": "CREDIT",
  "extra_fields": {
    "billing_address": {
      "street": "Av. Brasil",
      "number": "1000",
      "complement": "Sala 1",
      "district": "São Geraldo",
      "city": "Porto Alegre",
      "state": "RS",
      "country": "BR",
      "postal_code": "90230060",
      "reference": "Near the hospital"
    },
    "shipping_address": {
      "street": "Av. Brasil",
      "number": "1000",
      "complement": "Sala 1",
      "district": "São Geraldo",
      "city": "Porto Alegre",
      "state": "RS",
      "country": "BR",
      "postal_code": "90230060",
      "reference": "Near the hospital"
    },
    "data_only": {
      "requestor_challenge_indicator": "06"
    }
  }
}'
```

**Response (`Authenticated`):**

```json
{
  "transaction_id": "3729756321501820",
  "md": "",
  "tx_id": 48347501,
  "xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
  "protocol": "3DS2.3.1",
  "status": "Authenticated",
  "operation": "DEBIT",
  "redirect_html_template": "",
  "extra_fields": {
    "billing_address": {
      "street": "Av. Brasil",
      "number": "1000",
      "complement": "Sala 1",
      "district": "São Geraldo",
      "city": "Porto Alegre",
      "state": "RS",
      "country": "BR",
      "postal_code": "90230060",
      "reference": "Near the hospital"
    },
    "shipping_address": {
      "street": "Av. Brasil",
      "number": "1000",
      "complement": "Sala 1",
      "district": "São Geraldo",
      "city": "Porto Alegre",
      "state": "RS",
      "country": "BR",
      "postal_code": "90230060",
      "reference": "Near the hospital"
    },
    "data_only": {
      "requestor_challenge_indicator": "06"
    }
  },
  "ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
  "eci": 6,
  "cavv": "aglgsCXwXPJDRA1aTlXIMVQnQakX"
}
```

**Response (`Pending Enrolment Continue`):**

```json
{
  "transaction_id": "3729756321501820",
  "md": "",
  "tx_id": 48347501,
  "xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
  "status": "Pending Enrolment Continue",
  "protocol": "3DS2.3.1",
  "operation": "DEBIT",
  "redirect_html_template": "",
  "ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
  "eci": 7,
  "cavv": "aglgsCXwXPJDRA1aTlXIMVQnQakX"
}
```

> The exact `eci` value depends on the card brand and issuer. A value indicating no liability shift is common for Data Share Only, since the issuer approved the transaction without a full authentication challenge.

### Step 3: Check Status

Check the `status` field in the response and follow the appropriate scenario:

#### Status: `Authenticated`

The issuer approved the transaction based on the shared data alone. Extract `xid`, `eci`, `cavv`, and `ds_trans_id`, skip Step 4 proceeding to [Step 5: Create the Payment](#step-5-create-the-payment).

#### Status: `Denied`

The issuer declined the transaction based on the shared data. Don't attempt to create the payment.

#### Status: `Pending Enrolment Continue`

If the initial enrollment returns `Pending Enrolment Continue`, proceed to [Step 4: Continue Enrolment](#step-4-continue-enrolment).

### Step 4: Continue Enrolment

Call the [3DS - Continue Enrollment](https://docs.globalgetnet.com/en/products/online-payments/regional-api/swagger#tag/payments/post/dpm/security-gwproxy/v2/enrolments-continue) endpoint with the `transaction_id` from Step 2.

```json
curl https://api.pre.globalgetnet.com/dpm/security-gwproxy/v2/enrolments-continue \
  --request POST \
  --header 'Content-Type: application/json' \
  --data '{
  "transaction_id": "3729756321501820",
  "xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA="
}'
```

**Response (`3-D Secure Data Only`):**

```json
{
  "transaction_id": "84c05897-fbf1-4a91-90e8-d292a0fda1c8",
  "md": "",
  "tx_id": 48347501,
  "xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
  "status": "3-D Secure Data Only",
  "protocol": "3DS2.3.1",
  "operation": "DEBIT",
  "redirect_html_template": "",
  "ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
  "eci": 7,
  "cavv": "aglgsCXwXPJDRA1aTlXIMVQnQakX"
}
```

### Step 5: Create the Payment

Once authentication completes (status `Authenticated` or `3-D Secure Data Only`), call the [Create - Authorize](https://docs.globalgetnet.com/en/products/online-payments/regional-api/swagger#tag/payments/post/dpm/payments-gwproxy/v2/payments) endpoint. Include the authentication data (`xid`, `eci`, `cavv`, `ds_trans_id`) in the `payment` object.

```bash
curl --request POST \
  --url https://api-sbx.globalgetnet.com/dpm/payments-gwproxy/v2/payments \
  --header 'authorization: Bearer '\
  --header 'content-type: application/json' \
  --header 'x-seller-id: 54f88e68-7764-4e87-8830-756b1e2c02f8' \
  --data '{
    "order_id": "123order",
    "data": {
      "amount": 118708,
      "currency": "CLP",
      "payment": {
        "payment_method": "CREDIT_AUTHORIZATION",
        "xid": "VDdnR0kyU1g4ZXlxMkhWTlp0VnA=",
        "eci": "24",
        "ds_trans_id": "f7e5f76e-6388-43e6-b8cd-49b251a1f89c",
        "card": { ... }
      }
    }
  }'
```

## Next Steps

* [Create a 3DS Authenticated Payment](/en/global-api/sep-api/payment-guides-api/card-payments/3ds-guide)
* [Create a 3DS Authenticated Payment with Third-Party Provider](/en/global-api/sep-api/payment-guides-api/card-payments/3ds-third-party-guide)