three-ds:invalid_context | No | The authenticate() argument is not an object. | Pass . |
three-ds:missing_session_id | No | sessionId is missing or empty. | Pass the same session_id used for submit(). |
three-ds:missing_session_secret | No | sessionSecret is missing or empty. | Pass the session_secret for the same session. |
three-ds:missing_card_token | No | cardToken is missing or empty. | Pass BindResult.token from a successful submit(). |
three-ds:invalid_action | No | The handle() argument is not a gateway action object with a string type. | Pass the gateway 3DS action unchanged. |
three-ds:in_progress | No | A 3DS flow is already running on this ThreeDS instance. | Wait for the running flow to settle, or use a separate instance for a parallel flow. |
urn:radiumone:three-ds:cancelled | Yes | The AbortSignal passed in options was aborted. | Do not authorize. The shopper may start 3DS again. |
urn:radiumone:three-ds:challenge-timeout | Yes | No terminal status within the challenge or decoupled window (at most 5 minutes). A CSP connect-src that blocks the gateway API origin also ends here. | Do not authorize. Offer to start 3DS again; check connect-src if it happens every time. |
urn:radiumone:three-ds:provider-unavailable | No | The 3DS gateway call failed without a usable response (network error, timeout, empty 5xx or malformed body). The outcome is unknown. | Do not authorize. Check the 3DS status server-side before retrying. |
urn:radiumone:three-ds:action-not-found | No | 404 with no gateway URN for the 3DS action reference (unknown, purged, or endpoint unavailable). | Do not authorize. Start a new 3DS attempt. |
urn:radiumone:three-ds:unsupported-action | No | The gateway returned an action type this SDK version does not know. | Do not authorize. Upgrade the SDK. |
urn:radiumone:three-ds:action-malformed | No | A gateway action is missing required fields; or resume() found no pending redirect or a non-terminal status. | Do not authorize. On a return page, only call resume() when getPendingRedirect() is non-null. |
urn:radiumone:three-ds:render-mode-unsupported | No | The gateway sent a gateway_hosted challenge, which this SDK does not support. | Do not authorize. Contact support. |
urn:radiumone:three-ds:challenge-display-unsupported | No | challengePresentation ‘redirect’ was requested but the challenge is not redirectable or returnUrl is missing. | Pass returnUrl, or use challengePresentation ‘auto’ or ‘iframe’. |
urn:radiumone:three-ds:http-{status} | Varies (gateway) | A 3DS gateway call failed with a JSON body but no URN. retryAllowed is the body’s retry_allowed, else true for 5xx. | Do not authorize. Retry only when retryAllowed is true. |
urn:radiumone:rate-limit-exceeded | Varies (gateway) | 3DS request rate limit hit. Status polling retries it automatically; other calls reject. | Wait retryAfter seconds, then retry. |
urn:radiumone:three-ds:session-attempts-exceeded | Varies (gateway) | The session’s 3DS attempt budget is spent. | Do not authorize. Create a new session. |
urn:radiumone:three-ds:card-token-invalid | Varies (gateway) | cardToken is not valid for this session. | Pass the BindResult.token from this session’s submit(). |
urn:radiumone:three-ds:session-not-found | Varies (gateway) | The session is unknown or expired. | Do not authorize. Create a new session. |
urn:radiumone:three-ds:session-not-bound | Varies (gateway) | authenticate() was called before the card was bound to the session. | Call elements.submit() first and wait for it to resolve. |