# POST /api/merchants/{id}/three-d-secure-bindings/{providerType}/test-connection

3-D Secure: probes the merchant's provider account and reports whether it answered.

The probe never touches a payment path, and carries back no vendor response body and no
credential material. A candidate body is used for the probe and nothing else: it is never
persisted, never logged, and never echoed in the response.

**Operation ID:** `merchantThreeDSBindingTestThreeDSBindingConnection`

## Authorization

Requires: Merchants.Merchants.Update, merchant scope.

Required permissions:
- `Merchants.Merchants.Update`

## Parameters

| Name | In | Required | Type | Description |
| --- | --- | --- | --- | --- |
| id | path | yes | string(uuid) | The merchant id. |
| providerType | path | yes | ThreeDSProviderType | The provider to probe. |
| suppressNulls | query | no | boolean | If true, omit properties with null values. |

## Request Body

Optional candidate credentials to probe instead of the stored ones, so a boarding can be
tested before it is saved. Omit the body to probe the binding as stored.

**Content type:** `application/json`

Schema: `MerchantThreeDSBinding`

Properties:
- `providerType` (object): Which 3-D Secure provider this entry binds the merchant to. A null provider type is treated  as no binding at all rather than as `Fake`, so an incompletely  boarded row cannot silently become a live selection.
- `isEnabled` (boolean): Master enable flag for this provider on this merchant. When `false` or null, the binding  is not used even though the row exists.
- `policyMode` (object): How hard the merchant wants authentication applied. Null means the platform default, which  callers read as `Off`.
- `apiKey` (string): The vendor API key. Not a secret in the sense the JWT secret is (it is sent as a request  header and appears as a JWT audience), so it round-trips on reads; it is still never logged. Required: When IsEnabled is true.
- `jwtSecret` (string): The shared secret the request JWT is signed with.                   <b>Stored encrypted.</b> It is stripped, not decrypted, on every read that leaves the server:  the admin UI and the API both see null here and re-send the secret only when the operator  changes it. Only the server-side call to the provider ever uses the plaintext.
- `jwtSecretConfigured` (boolean): Whether a JWT secret is stored for this binding, for the editor that is never allowed to see the  secret itself.
- `endpointEnvironment` (object): Which of the vendor's environments this binding points at. Null reads as  `Sandbox`.
- `requestorUrl` (string): The merchant-facing origin the vendor validates authentication requests against: the HPP or  checkout origin the cardholder's browser is on. HTTPS only. Conditional: When RequestorUrl is not empty. Required: When IsEnabled is true.
- `challengeEnabled` (boolean): Whether the merchant permits the vendor to raise an interactive challenge. Null reads as not  enabled.
- `protocolVersion` (string): The 3-D Secure protocol version to request, from  `SupportedProtocolVersions`. Null means the provider's own  default. Conditional: When ProtocolVersion is not empty.
- `providerRegistrationId` (string(uuid)): Optional pointer at a vendor-side registration record for this merchant, for vendors that  board a merchant out of band and hand back an identifier. Nullable because most bindings  carry credentials and nothing else, and because a deleted registration should leave an  inspectable dangling reference rather than a hard failure.

**Content type:** `text/json`

Schema: `MerchantThreeDSBinding`

Properties:
- `providerType` (object): Which 3-D Secure provider this entry binds the merchant to. A null provider type is treated  as no binding at all rather than as `Fake`, so an incompletely  boarded row cannot silently become a live selection.
- `isEnabled` (boolean): Master enable flag for this provider on this merchant. When `false` or null, the binding  is not used even though the row exists.
- `policyMode` (object): How hard the merchant wants authentication applied. Null means the platform default, which  callers read as `Off`.
- `apiKey` (string): The vendor API key. Not a secret in the sense the JWT secret is (it is sent as a request  header and appears as a JWT audience), so it round-trips on reads; it is still never logged. Required: When IsEnabled is true.
- `jwtSecret` (string): The shared secret the request JWT is signed with.                   <b>Stored encrypted.</b> It is stripped, not decrypted, on every read that leaves the server:  the admin UI and the API both see null here and re-send the secret only when the operator  changes it. Only the server-side call to the provider ever uses the plaintext.
- `jwtSecretConfigured` (boolean): Whether a JWT secret is stored for this binding, for the editor that is never allowed to see the  secret itself.
- `endpointEnvironment` (object): Which of the vendor's environments this binding points at. Null reads as  `Sandbox`.
- `requestorUrl` (string): The merchant-facing origin the vendor validates authentication requests against: the HPP or  checkout origin the cardholder's browser is on. HTTPS only. Conditional: When RequestorUrl is not empty. Required: When IsEnabled is true.
- `challengeEnabled` (boolean): Whether the merchant permits the vendor to raise an interactive challenge. Null reads as not  enabled.
- `protocolVersion` (string): The 3-D Secure protocol version to request, from  `SupportedProtocolVersions`. Null means the provider's own  default. Conditional: When ProtocolVersion is not empty.
- `providerRegistrationId` (string(uuid)): Optional pointer at a vendor-side registration record for this merchant, for vendors that  board a merchant out of band and hand back an identifier. Nullable because most bindings  carry credentials and nothing else, and because a deleted registration should leave an  inspectable dangling reference rather than a hard failure.

**Content type:** `application/*+json`

Schema: `MerchantThreeDSBinding`

Properties:
- `providerType` (object): Which 3-D Secure provider this entry binds the merchant to. A null provider type is treated  as no binding at all rather than as `Fake`, so an incompletely  boarded row cannot silently become a live selection.
- `isEnabled` (boolean): Master enable flag for this provider on this merchant. When `false` or null, the binding  is not used even though the row exists.
- `policyMode` (object): How hard the merchant wants authentication applied. Null means the platform default, which  callers read as `Off`.
- `apiKey` (string): The vendor API key. Not a secret in the sense the JWT secret is (it is sent as a request  header and appears as a JWT audience), so it round-trips on reads; it is still never logged. Required: When IsEnabled is true.
- `jwtSecret` (string): The shared secret the request JWT is signed with.                   <b>Stored encrypted.</b> It is stripped, not decrypted, on every read that leaves the server:  the admin UI and the API both see null here and re-send the secret only when the operator  changes it. Only the server-side call to the provider ever uses the plaintext.
- `jwtSecretConfigured` (boolean): Whether a JWT secret is stored for this binding, for the editor that is never allowed to see the  secret itself.
- `endpointEnvironment` (object): Which of the vendor's environments this binding points at. Null reads as  `Sandbox`.
- `requestorUrl` (string): The merchant-facing origin the vendor validates authentication requests against: the HPP or  checkout origin the cardholder's browser is on. HTTPS only. Conditional: When RequestorUrl is not empty. Required: When IsEnabled is true.
- `challengeEnabled` (boolean): Whether the merchant permits the vendor to raise an interactive challenge. Null reads as not  enabled.
- `protocolVersion` (string): The 3-D Secure protocol version to request, from  `SupportedProtocolVersions`. Null means the provider's own  default. Conditional: When ProtocolVersion is not empty.
- `providerRegistrationId` (string(uuid)): Optional pointer at a vendor-side registration record for this merchant, for vendors that  board a merchant out of band and hand back an identifier. Nullable because most bindings  carry credentials and nothing else, and because a deleted registration should leave an  inspectable dangling reference rather than a hard failure.

## Responses

### 200

OK

**Content type:** `application/json`

Schema: `ThreeDSBindingConnectionTestResultDto`

Properties:
- `succeeded` (boolean): Gets or sets whether the provider answered the probe.
- `reason` (string): Gets or sets a short explanation of the outcome, safe to show an operator.
- `steps` (array<ConnectionTestStepDto>): Gets or sets the steps the test ran, in order. The platform always sends a list, empty when the  test ran nothing; the published schema still marks it nullable, as it does every array, so a  generated client should guard as it would any other. `succeeded` and  `reason` are not derived from this list and keep their meaning for a caller that  reads only them.

### 403

Forbidden

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 401

Unauthorized

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 400

Bad Request

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 404

Not Found

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 501

Not Implemented

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 500

Internal Server Error

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### default

The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

### 429

The request was refused because a rate limit was exceeded, or because something a later retry can clear stopped it. A rate limit refusal carries an `application/problem+json` body: wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling. Any other refusal carries the standard error envelope as `application/json`, and its `error.code` names the cause.

**Content type:** `application/problem+json`

Schema: `RateLimitProblemDetails`

Properties:
- `type` (string) required: The problem type identifier. Always the same value: the failure is the status code itself,  so there is no sub-type for a caller to branch on.
- `title` (string) required: A short, human-readable summary of the problem type.
- `status` (integer(int32)) required: The HTTP status code, repeated in the body as the problem-details format defines.
- `detail` (string) required: A human-readable explanation of this occurrence of the problem.
- `retryAfterSeconds` (integer(int32)) required: How long to wait before retrying, in whole seconds, carrying the same figure as the  `Retry-After` header. Always at least one: a value of zero would invite an immediate  retry that is certain to be rejected again.

**Content type:** `application/json`

Schema: `RemoteServiceErrorResponse`

Properties:
- `error` (RemoteServiceErrorInfo)

## Example request

Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.

The request body is a MerchantThreeDSBinding. See the Request body section below for its fields.

### cURL

```bash
curl -X POST "{{BASE_URL}}/api/merchants/{id}/three-d-secure-bindings/{providerType}/test-connection" \
  -H "api-key: {{API_KEY}}" \
  -H "Content-Type: application/json" \
  -d '{
  "providerType": {},
  "isEnabled": false,
  "policyMode": {},
  "apiKey": "",
  "jwtSecret": "",
  "jwtSecretConfigured": false,
  "endpointEnvironment": {},
  "requestorUrl": "",
  "challengeEnabled": false,
  "protocolVersion": "",
  "providerRegistrationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}'
```

### PowerShell

```powershell
$headers = @{
    'api-key' = '{{API_KEY}}'
}

$body = @'
{
  "providerType": {},
  "isEnabled": false,
  "policyMode": {},
  "apiKey": "",
  "jwtSecret": "",
  "jwtSecretConfigured": false,
  "endpointEnvironment": {},
  "requestorUrl": "",
  "challengeEnabled": false,
  "protocolVersion": "",
  "providerRegistrationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}
'@

$response = Invoke-RestMethod -Method POST -Uri '{{BASE_URL}}/api/merchants/{id}/three-d-secure-bindings/{providerType}/test-connection' `
    -Headers $headers -ContentType 'application/json' -Body $body
```

### TypeScript (SDK)

```bash
npm install @winkpg/winkpg-api
```

```typescript
import { Configuration, MerchantThreeDSBindingApi } from '@winkpg/winkpg-api';

const api = new MerchantThreeDSBindingApi(new Configuration({
  basePath: '{{BASE_URL}}',
  apiKey: '{{API_KEY}}',
}));

const { data } = await api.merchantThreeDSBindingTestThreeDSBindingConnection("3fa85f64-5717-4562-b3fc-2c963f66afa6", "PROVIDER_TYPE", {
  "providerType": {},
  "isEnabled": false,
  "policyMode": {},
  "apiKey": "",
  "jwtSecret": "",
  "jwtSecretConfigured": false,
  "endpointEnvironment": {},
  "requestorUrl": "",
  "challengeEnabled": false,
  "protocolVersion": "",
  "providerRegistrationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
});
```

### TypeScript (raw HTTP)

```typescript
const response = await fetch('{{BASE_URL}}/api/merchants/{id}/three-d-secure-bindings/{providerType}/test-connection', {
  method: 'POST',
  headers: {
    "api-key": "{{API_KEY}}",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "providerType": {},
    "isEnabled": false,
    "policyMode": {},
    "apiKey": "",
    "jwtSecret": "",
    "jwtSecretConfigured": false,
    "endpointEnvironment": {},
    "requestorUrl": "",
    "challengeEnabled": false,
    "protocolVersion": "",
    "providerRegistrationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
  }),
});

const data = await response.json();
```

### C# (SDK)

```bash
dotnet add package WinkPg.Api.Client
```

```csharp
using WinkPg.Api.Client.Api;
using WinkPg.Api.Client.Client;
using System.Text.Json;

var config = new Configuration { BasePath = "{{BASE_URL}}" };
config.AddApiKey("api-key", "{{API_KEY}}");

var api = new MerchantThreeDSBindingApi(config);
var body = JsonSerializer.Deserialize<MerchantThreeDSBinding>("""
    {
      "providerType": {},
      "isEnabled": false,
      "policyMode": {},
      "apiKey": "",
      "jwtSecret": "",
      "jwtSecretConfigured": false,
      "endpointEnvironment": {},
      "requestorUrl": "",
      "challengeEnabled": false,
      "protocolVersion": "",
      "providerRegistrationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
    }
    """);

var result = await api.MerchantThreeDSBindingTestThreeDSBindingConnectionAsync(Guid.Parse("3fa85f64-5717-4562-b3fc-2c963f66afa6"), "PROVIDER_TYPE", body);
```

### C# (raw HTTP)

```csharp
using System.Text;

using var http = new HttpClient { BaseAddress = new Uri("{{BASE_URL}}") };

var request = new HttpRequestMessage(new HttpMethod("POST"), "/api/merchants/{id}/three-d-secure-bindings/{providerType}/test-connection");
request.Headers.Add("api-key", "{{API_KEY}}");

request.Content = new StringContent("""
    {
      "providerType": {},
      "isEnabled": false,
      "policyMode": {},
      "apiKey": "",
      "jwtSecret": "",
      "jwtSecretConfigured": false,
      "endpointEnvironment": {},
      "requestorUrl": "",
      "challengeEnabled": false,
      "protocolVersion": "",
      "providerRegistrationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
    }
    """, Encoding.UTF8, "application/json");

var response = await http.SendAsync(request);
response.EnsureSuccessStatusCode();
var json = await response.Content.ReadAsStringAsync();
```

### Python (SDK)

```bash
pip install winkpg-api
```

```python
import winkpg_api

configuration = winkpg_api.Configuration(host="{{BASE_URL}}")
configuration.api_key["ApiKey"] = "{{API_KEY}}"

with winkpg_api.ApiClient(configuration) as client:
    api = winkpg_api.MerchantThreeDSBindingApi(client)
    body = winkpg_api.MerchantThreeDSBinding.from_dict({
      "providerType": {},
      "isEnabled": False,
      "policyMode": {},
      "apiKey": "",
      "jwtSecret": "",
      "jwtSecretConfigured": False,
      "endpointEnvironment": {},
      "requestorUrl": "",
      "challengeEnabled": False,
      "protocolVersion": "",
      "providerRegistrationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
    })
    result = api.merchant_three_ds_binding_test_three_ds_binding_connection("3fa85f64-5717-4562-b3fc-2c963f66afa6", "PROVIDER_TYPE", body)
```

### Python (raw HTTP)

```bash
pip install requests
```

```python
import requests

headers = {
    "api-key": "{{API_KEY}}",
    "Content-Type": "application/json",
}

body = {
  "providerType": {},
  "isEnabled": False,
  "policyMode": {},
  "apiKey": "",
  "jwtSecret": "",
  "jwtSecretConfigured": False,
  "endpointEnvironment": {},
  "requestorUrl": "",
  "challengeEnabled": False,
  "protocolVersion": "",
  "providerRegistrationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}

response = requests.request(
    "POST",
    "{{BASE_URL}}/api/merchants/{id}/three-d-secure-bindings/{providerType}/test-connection",
    headers=headers,
    json=body,
)
response.raise_for_status()
data = response.json()
```

## See also

- [All documentation](https://devportal-simpay-sbx.winkpg.io/llms.txt): the machine-readable index of every public page on this site.
