curl --request POST \
--url https://sg.sandbox.api.reap.global/simulation/card-transactions/authorization-with-3ds \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'Reap-Version: <reap-version>' \
--data '
{
"cardId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"amount": 100.5,
"originalAmount": 100.5,
"originalCurrency": "<string>",
"channel": "ATM",
"digitalWallet": "APPLE_PAY",
"merchant": {
"name": "<string>",
"city": "<string>",
"postCode": "<string>",
"state": "<string>",
"country": "US",
"mccCode": "<string>",
"mccCategory": "<string>"
},
"triggerFraudAlert": true
}
'const options = {
method: 'POST',
headers: {
'Reap-Version': '<reap-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
cardId: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
amount: 100.5,
originalAmount: 100.5,
originalCurrency: '<string>',
channel: 'ATM',
digitalWallet: 'APPLE_PAY',
merchant: {
name: '<string>',
city: '<string>',
postCode: '<string>',
state: '<string>',
country: 'US',
mccCode: '<string>',
mccCategory: '<string>'
},
triggerFraudAlert: true
})
};
fetch('https://sg.sandbox.api.reap.global/simulation/card-transactions/authorization-with-3ds', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://sg.sandbox.api.reap.global/simulation/card-transactions/authorization-with-3ds"
payload = {
"cardId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"amount": 100.5,
"originalAmount": 100.5,
"originalCurrency": "<string>",
"channel": "ATM",
"digitalWallet": "APPLE_PAY",
"merchant": {
"name": "<string>",
"city": "<string>",
"postCode": "<string>",
"state": "<string>",
"country": "US",
"mccCode": "<string>",
"mccCategory": "<string>"
},
"triggerFraudAlert": True
}
headers = {
"Reap-Version": "<reap-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"cardId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"status": "PENDING",
"merchant": {
"name": "Sephora Digital",
"countryCode": "344"
},
"transaction": {
"amount": "170.0000",
"currency": "HKD",
"timestamp": "2024-01-15T10:30:00Z"
},
"expiresAt": "2024-01-15T10:35:00Z"
}{
"error": {
"code": "SIMULATION_INVALID_STATE",
"message": "<string>",
"detail": {}
}
}{
"error": {
"code": "CARD_NOT_FOUND",
"message": "<string>",
"detail": {}
}
}Simulate 3DS authorization
Simulates a WEBHOOK 3DS challenge for a card authorization. Returns a pending ThreeDsChallenge and delivers CARD_3DS_CHALLENGE_CREATED without creating a transaction. After POST /card-3ds-challenges/{id}/respond with approve: true, authorization completes and CARD_TRANSACTION_CREATED is delivered. With approve: false, the challenge is rejected and no transaction is created (mirrors production). The card must use 3dsChallengeMethod: WEBHOOK.
curl --request POST \
--url https://sg.sandbox.api.reap.global/simulation/card-transactions/authorization-with-3ds \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'Reap-Version: <reap-version>' \
--data '
{
"cardId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"amount": 100.5,
"originalAmount": 100.5,
"originalCurrency": "<string>",
"channel": "ATM",
"digitalWallet": "APPLE_PAY",
"merchant": {
"name": "<string>",
"city": "<string>",
"postCode": "<string>",
"state": "<string>",
"country": "US",
"mccCode": "<string>",
"mccCategory": "<string>"
},
"triggerFraudAlert": true
}
'const options = {
method: 'POST',
headers: {
'Reap-Version': '<reap-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
cardId: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
amount: 100.5,
originalAmount: 100.5,
originalCurrency: '<string>',
channel: 'ATM',
digitalWallet: 'APPLE_PAY',
merchant: {
name: '<string>',
city: '<string>',
postCode: '<string>',
state: '<string>',
country: 'US',
mccCode: '<string>',
mccCategory: '<string>'
},
triggerFraudAlert: true
})
};
fetch('https://sg.sandbox.api.reap.global/simulation/card-transactions/authorization-with-3ds', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://sg.sandbox.api.reap.global/simulation/card-transactions/authorization-with-3ds"
payload = {
"cardId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"amount": 100.5,
"originalAmount": 100.5,
"originalCurrency": "<string>",
"channel": "ATM",
"digitalWallet": "APPLE_PAY",
"merchant": {
"name": "<string>",
"city": "<string>",
"postCode": "<string>",
"state": "<string>",
"country": "US",
"mccCode": "<string>",
"mccCategory": "<string>"
},
"triggerFraudAlert": True
}
headers = {
"Reap-Version": "<reap-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"cardId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"status": "PENDING",
"merchant": {
"name": "Sephora Digital",
"countryCode": "344"
},
"transaction": {
"amount": "170.0000",
"currency": "HKD",
"timestamp": "2024-01-15T10:30:00Z"
},
"expiresAt": "2024-01-15T10:35:00Z"
}{
"error": {
"code": "SIMULATION_INVALID_STATE",
"message": "<string>",
"detail": {}
}
}{
"error": {
"code": "CARD_NOT_FOUND",
"message": "<string>",
"detail": {}
}
}Authorizations
API key as Bearer token
Headers
API version (YYYY-MM-DD)
2025-02-14 "2025-02-14"
Body
Simulate a WEBHOOK 3DS challenge that defers authorization until the partner responds
Card ID
Merchant amount in the project's billing currency, before cardholder fees. Any FX markup or ATM fee that applies to the account is added on top, as in production, so the amount charged to the cardholder can be higher than this value.
x >= 0100.5
0
1234.99
Amount in the original transaction currency. Must be provided together with originalCurrency, and is required when the event lands on a transaction whose original currency is not the billing currency.
x >= 0100.5
0
1234.99
Original transaction currency as an ISO 4217 alpha code (e.g. EUR). Must be provided together with originalAmount.
^[A-Z]{3}$Transaction channel. Defaults to ECOMMERCE when omitted.
ATM, POS, ECOMMERCE, VISA_DIRECT "ATM"
Digital wallet type (e.g. APPLE_PAY, GOOGLE_PAY). Randomly generated if omitted.
APPLE_PAY, GOOGLE_PAY, MERCHANT_TOKEN "APPLE_PAY"
Merchant details. All fields are optional; an omitted field is randomly generated, except country.
Show child attributes
Show child attributes
When true, also raises a detected fraud alert against the resulting charge. The alert arrives asynchronously; wait for the CARD_FRAUD_ALERT_CREATED event. Detection alone does not block the card.
Response
Response for status 200
Unique 3DS challenge identifier
ID of the card this challenge is for
Challenge status
PENDING, APPROVED, REJECTED, EXPIRED "PENDING"
Merchant details
Show child attributes
Show child attributes
Transaction details
Show child attributes
Show child attributes
ISO 8601 timestamp when this challenge expires
"2024-01-15T10:35:00Z"