Confirm a card verification
Advances the verification after any device fingerprinting or issuer challenge. Returns the saved method once approved (repeating it returns the same method), or the challenge to show. After the challenge is shown, follow it with the verification status route until state leaves pending, then confirm again to save the card. The verification is bound to the member that started it: another member’s verification, or an unknown id, returns 404. Responses carry Cache-Control: no-store. Requires a writable member credential.
curl --request POST \
--url https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"verification_id": "6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13"
}
'import requests
url = "https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm"
payload = { "verification_id": "6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({verification_id: '6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13'})
};
fetch('https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'verification_id' => '6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm"
payload := strings.NewReader("{\n \"verification_id\": \"6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"verification_id\": \"6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"verification_id\": \"6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13\"\n}"
response = http.request(request)
puts response.read_body{
"status": 200,
"data": {
"id": "6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13",
"status": "approved",
"created": true,
"payment_method": {
"id": "0192f501-2b3c-7d4e-8f5a-6b7c8d9e0f1a",
"kind": "card",
"brand": "visa",
"last4": "5555",
"expires": {
"month": 3,
"year": 2031
},
"card_holder": "Casey Brooks",
"default": true,
"billing_address": {
"name": "Casey Brooks",
"address1": "742 Evergreen Terrace",
"address2": null,
"city": "Springfield",
"state": "IL",
"postal_code": "62704",
"country_code": "US"
},
"created_at": "2026-07-02T19:44:10.000000Z"
},
"challenge_form": null,
"challenge_url": null
},
"meta": {
"request_uuid": "0192f520-1a2b-7c3d-8e4f-5a6b7c8d9e0f",
"timestamp": "2026-09-30T15:20:00Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}Authorizations
A member credential in the Authorization: Bearer header: a member
session JWT, a portal JWT whose login is linked to a membership in
that company, or an opaque member token. The credential alone
identifies the member and company.
Body
The verification id returned by POST /payment-methods when verification was required. It names the verification for the authenticated member only and grants nothing on its own.
1"6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13"
curl --request POST \
--url https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"verification_id": "6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13"
}
'import requests
url = "https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm"
payload = { "verification_id": "6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({verification_id: '6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13'})
};
fetch('https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'verification_id' => '6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm"
payload := strings.NewReader("{\n \"verification_id\": \"6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"verification_id\": \"6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.fluid.app/api/member/v2026-10/payment-methods/three-ds/confirm")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"verification_id\": \"6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13\"\n}"
response = http.request(request)
puts response.read_body{
"status": 200,
"data": {
"id": "6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13",
"status": "approved",
"created": true,
"payment_method": {
"id": "0192f501-2b3c-7d4e-8f5a-6b7c8d9e0f1a",
"kind": "card",
"brand": "visa",
"last4": "5555",
"expires": {
"month": 3,
"year": 2031
},
"card_holder": "Casey Brooks",
"default": true,
"billing_address": {
"name": "Casey Brooks",
"address1": "742 Evergreen Terrace",
"address2": null,
"city": "Springfield",
"state": "IL",
"postal_code": "62704",
"country_code": "US"
},
"created_at": "2026-07-02T19:44:10.000000Z"
},
"challenge_form": null,
"challenge_url": null
},
"meta": {
"request_uuid": "0192f520-1a2b-7c3d-8e4f-5a6b7c8d9e0f",
"timestamp": "2026-09-30T15:20:00Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}{
"status": 123,
"error": {
"message": "<string>",
"details": {}
},
"meta": {
"request_uuid": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"timestamp": "2023-11-07T05:31:56Z"
}
}