> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.mangopay.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.mangopay.com/_mcp/server.

# API - Feb 23, 2026

## Added

### Authentication type response parameter for card transactions

The API now returns the `AuthenticationResult.AuthenticationType` property on all relevant card transactions, which has the possible values:

* `CHALLENGE` – The issuer requested SCA to be enforced (for example, using 3DS).
* `FRICTIONLESS` – The transaction was exempted from SCA because an exemption was granted by the issuer.
* `DIRECT_AUTHORIZATION` – The transaction was sent to the issuer for authorization without any frictionless or challenge (for example, if SCA doesn't apply).

The property reflects both:

* The final state of the authentication request that Mangopay made to the issuer,
* The decision of the issuer regarding the type of authentication to be enforced (if applicable)

A `null` value typically indicates that authentication was not requested (for example, because the request failed before being sent) or a decision was not received.

The parameter is returned on the following requests:

* [POST Create a Direct Card PayIn](/api-reference/direct-card-payins/create-direct-card-payin)
* [POST Create a Recurring Card PayIn](/api-reference/recurring-card-payins/create-recurring-card-payin) with the CIT payload
* [POST Create a Recurring Card PayIn](/api-reference/recurring-card-payins/create-recurring-card-payin) with the MIT payload
* [POST Create a Preauthorization](/api-reference/preauthorizations/create-preauthorization)
* [POST Create a Preauthorized PayIn](/api-reference/preauthorizations/create-preauthorized-payin)
* [POST Create a Card Deposit Preauthorization](/api-reference/extended-preauthorizations/create-card-extended-preauthorization)
* [POST Create a Deposit Preauthorized PayIn](/api-reference/extended-preauthorizations/create-extended-preauthorized-payin)
* [POST Create a Web Card PayIn](/api-reference/web-card-payins/create-web-card-payin)
* [POST Create a Card Validation](/api-reference/card-validations/create-card-validation)
* [POST Create a Google Pay PayIn](/api-reference/google-pay/create-google-pay-payin)
* [POST Create an Apple Pay PayIn](/api-reference/apple-pay/create-apple-pay-payin)

It is also returned on the objects obtained via the GET endpoints:

* **GET View a PayIn** (for pay-in types above)
* [GET View a Preauthorization](/api-reference/preauthorizations/view-preauthorization)
* [GET View a Deposit Preauthorization](/api-reference/extended-preauthorizations/view-extended-preauthorization)
* [GET View a Card Validation](/api-reference/card-validations/view-card-validation)