Skip to main content

TS12 SCA Workflows

These workflows implement TS12, the payment Strong Customer Authentication (SCA) profile for the EUDI Wallet defined in ETSI TS 119 462. It lets the wallet act as an SCA element for payments.

SCA is mandated under PSD2 Article 97(1) for electronic payment initiation, for accessing a payment account online, and for other actions that carry a risk of fraud. The EUDI Wallet supports all three authentication factor categories (knowledge, possession, inherence) and Dynamic Linking.

TS12 defines four SCA workflows, each driven by an SCA Attestation that the user's Account Servicing Payment Service Provider (ASPSP) issues into their Wallet Unit.

SCA Attestation Types​

Attestation TypeClaimsPurpose
Payment Service UserNoneLogin and risk-based step-up authentication
Payment Cardpan_last_four, scheme, scheme_logoPayment Authorisation and Recurring Payment Mandate
Payment Accountiban, bic, currencyPayment Authorisation, Recurring Payment Mandate, and Account Information Access

Transaction Types​

WorkflowType IdentifierAttestation UsedDescription
Login and Risk-based Authenticationurn:eudi:sca:login_risk_transaction:1Payment Service UserStep-up SCA for sensitive actions (e.g. login from a new device)
Payment Authorisationurn:eudi:sca:payment:1Payment Account, Payment CardAuthorise a payment via a PISP or directly
E-mandateurn:eudi:sca:emandate:1Payment Account, Payment CardAuthorise a payment mandate (single, open-ended, recurring or instalment)
Account Information Accessurn:eudi:sca:account_access:1Payment AccountAuthorise an AISP to access account data

Each workflow follows the same 5-step developer pattern: obtain an API key, create a credential definition, issue a credential, create a presentation definition, and send a verification request with transaction data.

Learn more​