RDX Specification

Out-of-Band Authentication

In this use case, VCAS allows the issuer to authenticate cardholders outside of the private session that VCAS has with the cardholder during the transaction flow. The most common OOB authentication method is biometrics, leveraging the cardholder’s mobile banking application and the biometric functionality in the smartphone’s operating system.

ProsConsRDX Calls
More seamless experienceRequires three API calls.Stepup
Typically more secure than OTP via SMS or emailAdditional development required to integrate into issuer's existing mobile banking application.Initiate Action
Support of additional OOB authentication methodsCardholder adoption of the mobile banking application; issuer may need to use another authentication method with OOB.Validate

Flow Diagram

Required RDX Calls:

  • Stepup
  • Initiate Action
  • Validate