# 3D Secure response parameters (/limited-release/commerce-platform/accept-payments/advanced/customize/use-3d-secure/view-response-parameters)



You can see the response of the 3D Secure flow by viewing the `LiabilityShift`, `EnrollmentStatus`, and `Authentication_Status` fields in the payload your server returns to your client.

If you've integrated with the JavaScript SDK, you receive the `LiabilityShift` parameter only.

## LiabilityShift [#liabilityshift]

`LiabilityShift` signals whether the issuing bank may accept liability for the transaction.

You can find `LiabilityShift` in the payload your server returns to your client. This is a client and server-side parameter.

| Response   | Description                                 | Recommended action                  |
| ---------- | ------------------------------------------- | ----------------------------------- |
| `POSSIBLE` | Liability might shift to the card issuer.   | Continue with authorization.        |
| `YES`      | Liability has shifted to the card issuer.   | Continue with authorization.        |
| `NO`       | Liability is with the merchant.             | Do not continue with authorization. |
| `UNKNOWN`  | The authentication system is not available. | Do not continue with authorization. |

## EnrollmentStatus [#enrollmentstatus]

`EnrollmentStatus` shows whether the card type and issuing bank are ready to complete a 3D Secure authentication. This is a server-side parameter.

| Response | Description                                                                      |
| -------- | -------------------------------------------------------------------------------- |
| `Y`      | Card type and issuing bank are ready to complete a 3D Secure authentication.     |
| `N`      | Card type and issuing bank are not ready to complete a 3D Secure authentication. |
| `U`      | System is unavailable at the time of the request.                                |
| `B`      | System has bypassed authentication.                                              |

## Authentication\_Status [#authentication_status]

`Authentication_Status` indicates the result of the authentication challenge. This is a server-side parameter.

| Response | Description                            |
| -------- | -------------------------------------- |
| `Y`      | Successful authentication.             |
| `N`      | Failed authentication.                 |
| `R`      | Rejected authentication.               |
| `A`      | Attempted authentication.              |
| `U`      | Unable to complete authentication.     |
| `C`      | Challenge required for authentication. |
| `I`      | Information only.                      |
| `D`      | Decoupled authentication.              |

Based on the results of `EnrollmentStatus` and `Authentication_Status`, a `LiabilityShift` response is returned. The `LiabilityShift` response determines how you might proceed with authentication.

| `EnrollmentStatus` | `Authentication_Status` | `LiabilityShift` | Recommended action                                                   |
| ------------------ | ----------------------- | ---------------- | -------------------------------------------------------------------- |
| `Y`                | `Y`                     | `POSSIBLE`       | Continue with authorization.                                         |
| `Y`                | `Y`                     | `YES`            | Continue with authorization.                                         |
| `Y`                | `N`                     | `NO`             | Do not continue with authorization.                                  |
| `Y`                | `R`                     | `NO`             | Do not continue with authorization.                                  |
| `Y`                | `A`                     | `POSSIBLE`       | Continue with authorization.                                         |
| `Y`                | `U`                     | `UNKNOWN`        | Do not continue with authorization. Request the cardholder to retry. |
| `Y`                | `U`                     | `NO`             | Do not continue with authorization. Request the cardholder to retry. |
| `Y`                | `C`                     | `UNKNOWN`        | Do not continue with authorization. Request the cardholder to retry. |
| `Y`                |                         | `NO`             | Do not continue with authorization. Request the cardholder to retry. |
| `N`                |                         | `NO`             | Continue with authorization.                                         |
| `U`                |                         | `NO`             | Continue with authorization.                                         |
| `U`                |                         | `UNKNOWN`        | Do not continue with authorization. Request the cardholder to retry. |
| `B`                |                         | `NO`             | Continue with authorization.                                         |
|                    |                         | `UNKNOWN`        | Do not continue with authorization. Request the cardholder to retry. |

## Deprecated parameters [#deprecated-parameters]

> **Note:** **Note:** If you integrated 3D Secure before June 2020, the `liabilityShifted`, `authenticationStatus`, and `AuthenticationReason` parameters continue to work on the server but are no longer supported.

| `liabilityShifted` | `authenticationStatus` | `AuthenticationReason` | Reason                                                                                          | Next steps                                                                                                                           |
| ------------------ | ---------------------- | ---------------------- | ----------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| `undefined`        | `undefined`            | `undefined`            | You have not required 3D Secure for the buyer, or the card network did not require a 3D Secure. | You can continue with authorization and assume liability. If you prefer not to assume liability, ask the buyer for another card.     |
| `true`             | `YES`                  | `SUCCESSFUL`           | Buyer authenticated using 3D Secure.                                                            | Buyer authenticated with 3D Secure, and you can continue with the authorization.                                                     |
| `false`            | `ERROR`                | `ERROR`                | An error occurred with the 3D Secure authentication system.                                     | Prompt the buyer to re-authenticate or request for another form of payment.                                                          |
| `false`            | `NO`                   | `SKIPPED_BY_BUYER`     | Buyer was presented with the 3D Secure challenge but chose to skip the authentication.          | Do not continue with the current authorization. Prompt the buyer to re-authenticate or request buyer for another form of payment.    |
| `false`            | `NO`                   | `FAILURE`              | Buyer may have failed the challenge, or the device was not verified.                            | Do not continue with current authorization. Prompt the buyer to re-authenticate or request buyer for another form of payment.        |
| `false`            | `NO`                   | `BYPASSED`             | 3D Secure was skipped as the authentication system did not require a challenge.                 | You can continue with the authorization and assume liability. If you prefer not to assume liability, ask the buyer for another card. |
| `false`            | `NO`                   | `ATTEMPTED`            | Card is not enrolled in 3D Secure. The card issuing bank is not participating in 3D Secure.     | Continue with authorization, as authentication is not required.                                                                      |
| `false`            | `NO`                   | `UNAVAILABLE`          | The issuing bank is not able to complete authentication.                                        | You can continue with the authorization and assume liability. If you prefer not to assume liability, ask the buyer for another card. |
| `false`            | `NO`                   | `CARD_INELIGIBLE`      | Card is not eligible for 3D Secure authentication.                                              | Continue with authorization, as authentication is not required.                                                                      |

In scenarios where `liabilityShifted` was either `false` or `undefined`, you can complete the payment at your own risk, meaning that the liability of any chargeback has not shifted from the merchant to the card issuer.

## Next steps [#next-steps]

[Go live](/api/rest/production/)
