# 3DS Event

> Receive 3DS one-time password event notifications for issued card transactions.

```yaml
openapi: 3.1.0
info:
  title: 3DS Event
  version: 1.0.0
  description: Receive 3DS one-time password event notifications for issued card
    transactions.
webhooks:
  card.threeds.event:
    post:
      summary: 3DS Event
      description: Receive 3DS one-time password event notifications for issued card
        transactions.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                request_id:
                  type: string
                  description: Unique event identifier for deduplication.
                  x-onerway-signature-participation: included
                event_type:
                  type: string
                  description: Event type identifier.
                  x-onerway-constraints:
                    - kind: values
                      text: Fixed to `issuing.card3dsEvent` for this webhook.
                  x-onerway-signature-participation: included
                created_at:
                  type: string
                  description: Event creation time in ISO 8601 format.
                  x-onerway-signature-participation: included
                version:
                  type:
                    - string
                    - "null"
                  description: Webhook API version selected when the subscription is created.
                  x-onerway-value:
                    nullable: true
                    when:
                      en: No explicit webhook version is configured.
                      zh: 未配置明确 webhook 版本时可为 `null`。
                  x-onerway-signature-participation: included
                data:
                  type: object
                  properties:
                    cardId:
                      type: string
                      description: Card ID.
                    txnOrderNo:
                      type: string
                      description: Transaction order number.
                    type:
                      type: string
                      description: 3DS authentication type. Currently fixed to `OTP`.
                      enum:
                        - OTP
                      x-enum-descriptions:
                        OTP: One-time password authentication.
                    card3dsValues:
                      type: string
                      description: 3DS one-time password. Treat this value as sensitive authentication
                        data; do not log or retain it after use.
                    description:
                      type:
                        - string
                        - "null"
                      description: 3DS event description.
                      x-onerway-value:
                        nullable: true
                        empty: true
                        when:
                          en: Returned as `null` or an empty string when no description is available.
                          zh: 无事件描述时返回 `null` 或空字符串。
                    transactionTime:
                      type: integer
                      description: Transaction time as a Unix timestamp in milliseconds.
                    expireTime:
                      type: integer
                      description: One-time password expiration time as a Unix timestamp in
                        milliseconds.
                    currency:
                      type: string
                      description: Transaction currency.
                    amount:
                      type: number
                      description: Transaction amount.
                    merchantName:
                      type: string
                      description: Merchant name.
                  description: Card 3DS event business data.
                  x-onerway-signature-participation: included
            examples:
              otp_created:
                summary: 3DS one-time password created
                value:
                  request_id: replace_with_event_id
                  event_type: issuing.card3dsEvent
                  created_at: 2026-01-01T00:00:00Z
                  version: "1.0"
                  data:
                    cardId: example_card_id
                    txnOrderNo: example_transaction_order
                    type: OTP
                    card3dsValues: "123456"
                    description: ""
                    transactionTime: 1767225600000
                    expireTime: 1767225900000
                    currency: USD
                    amount: 125.5
                    merchantName: Example Merchant
      responses:
        "200":
          description: Return HTTP 200 with `respCode=20000` after the 3DS event is
            received and accepted. Onerway retries when the response code is not
            `20000`.
          content:
            application/json:
              schema:
                type: object
                properties:
                  respCode:
                    type: string
                  respMsg:
                    type: string
                required:
                  - respCode
                  - respMsg
              examples:
                return_success:
                  summary: Return success JSON
                  value:
                    respCode: "20000"
                    respMsg: success
```
