Skip to main content
The Payment Method Tokens API can create a setup token for credit or debit cards that have:
  • No verification
  • Smart authorization
  • 3D Secure verification
Send a call for each card type to test your integration works as expected.

Prerequisites

You’ll need a Payment Method Tokens API cards integration.

No verification

For cards with no verification, the card data passed to the API is checked only for format.

Sample request for setup token with no verification

  1. Change ACCESS-TOKEN to your sandbox access token.
  2. Change REQUEST-ID to a unique alphanumeric set of characters, for example, a time stamp.
Copy and modify the following code sample to create a setup token associated with a credit or debit card with no verification. Endpoint: Create a setup token

Sample response for setup token with no verification

A successful request returns the following:
  • An HTTP response code of 200 or 201. Returns 200 for an idempotent request.
  • The ID of the token in the id field.
  • HATEOAS links

Smart authorization

Smart authorization runs a zero-value or minimal-value authorization to validate the card is real and active. Some issuing banks or regions don’t support zero-value authorization, so a minimal-value authorization is run. The seller must manually cancel minimal-value authorizations or the customer will have a small pending charge on their card.

Sample request for setup token with smart authorization

  1. Change ACCESS-TOKEN to your sandbox access token.
  2. Change REQUEST-ID to a set of unique alphanumeric characters such as a time stamp.
  3. Use the card as the payment source and complete the rest of the source object for your use case and business.
  4. Pass the verification_method parameter with SCA_WHEN_REQUIRED to verify card data.
  5. Update the return_url value with the URL where the payer is redirected after they approve the flow.
  6. Update the cancel_url value with the URL where the payer is redirected after they cancel the flow.
Copy and modify the following code: Endpoint: Create a setup token

Sample response for setup token with smart authorization

A successful request returns the following:
  • An HTTP response code of 200 or 201. Returns 200 for an idempotent request.
  • A status of APPROVED
  • The ID of the token in the id field.
  • HATEOAS links

3D Secure

Use 3D Secure authentication to reduce the likelihood of fraud and improve transaction performance with supported cards. In some countries, authorizing a card can trigger a 3D Secure contingency. 3D Secure verification may occur in PSD2 countries, including members of the EU. For 3D Secure verification, pass SCA_ALWAYS or SCA_WHEN_REQUIRED in the payment_source.card.attributes.verification.method field for the create order request. The API response returns the order status as PAYER_ACTION_REQUIRED.

Sample request for setup token with 3D Secure

  1. Change ACCESS-TOKEN to your sandbox access token.
  2. Change REQUEST-ID to a set of unique alphanumeric characters such as a time stamp.
  3. Use the card as the payment source and complete the rest of the source object for your use case and business.
  4. Pass the verification_method parameter with SCA_ALWAYS to verify card data.
  5. Update the return_url value with the URL where the payer is redirected after they approve the flow.
  6. Update the cancel_url value with the URL where the payer is redirected after they cancel the flow.
Copy and modify the following code:

Sample response for setup token with 3D Secure

A successful request returns the following:
  • An HTTP response code of 200 or 201. Returns 200 for an idempotent request.
  • A status of PAYER_ACTION_REQUIRED
  • HATEOAS links

Convert approved setup token to payment token

After the payer completes verification, make a POST request on the payment token endpoint to convert the approved setup token to a payment token. To retrieve 3D secure verification data associated with a setup token, make a GET request on the setup token endpoint.

Sample request

Sample response

A successful request returns the following:
  • An HTTP response code of 200 OK
  • A status of APPROVED
The issuing bank can still issue an authorization if a card fails the AVS and CVV checks. In this case, the setup token is created with an APPROVED status and the processor responses are returned to you. The eci_flag parameter indicates that 3D Secure was not completed. You can choose whether to use a card that did not complete 3D Secure or failed AVS and CVV checks:
  • To use the card, make a POST request on add-payment-token. Convert the approved setup token to a full payment token.
  • To reject the card, don’t add the payment token or convert it to a full payment token.
In the sandbox, create a setup token and a 3D Secure token. Validate a card with card data from 3D Secure test scenarios.

Test AVS and CVV response codes

Generate AVS and CVV response codes when running tests in the PayPal sandbox. Use test card numbers.

Generate AVS response

Set address_line_1 to the following values to generate an AVS response.

Generate CVV response

Set the CVV to the following values to generate a CVV response: