Developers
One mobile integration. Clear APIs.
Shastra returns on-device risk context to merchant policy. Kavaach handles native 3DS when authentication is required. Mitra adds transaction visibility and policy control across either product. Shastra and Kavaach can each be adopted independently; Mitra is optional.
Shastra integration
Score mobile transaction risk on-device: 0–100, higher means higher risk.
-
attachToCheckoutView
(rootView) Starts permissioned signal collection on the merchant's checkout view hierarchy, where enabled and disclosed.
-
deviceDecision(context?)
Returns bindingId, recognized state, score, and reason codes. Optional merchant-supplied context (amount, currency) enriches the score. No network round-trip.
// Optional — context the merchant already has
val context = RiskContext.builder()
.amountMinor(50000)
.currency("USD")
.build()
// Resolved locally during initialize()
val device = service.deviceDecision(context)
device.bindingId // "bnd_8f2a…b2a1"
device.recognized // true
device.priorAuths // 47
device.boundSince // 2025-07-14
device.score // Sample: 18 / 100; higher means higher risk
device.reasonCodes // [RECOGNIZED_DEVICE, …]
// Your policy, your call
if (device.recognized && device.score < policy.frictionlessCeiling) {
checkout.requestFrictionless()
}
Illustrative API shape, for orientation.
No blocking backend round-trip. Score produced locally, on-device.
Kavaach integration
Authenticate natively with your existing 3DS Server.
-
initialize(context, config, locale, uiCustomization)
Once per transaction. Validates credentials, receives configuration, starts signal collection.
-
getAuthenticationParameters
(brand) Returns device data for your server to assemble the AReq. No 3DS message is modified.
-
doChallenge(activity, challengeParameters, receiver, timeOut)
Renders the issuer's native challenge inside the app, only if required. Returns the result to your app.
// 1 — once per app process
val service = KavaachThreeDS2Service.getInstance()
service.initialize(context, config, locale, uiCustomization)
// 2 — once per transaction
val txn = service.createTransaction(directoryServerId, "2.2.0")
val params = txn.authenticationRequestParameters
// 3 — your server sends the AReq, unchanged
val ares = yourThreeDSServer.authenticate(params)
// 4 — challenge only if the issuer asks for one
if (ares.requiresChallenge) {
txn.doChallenge(
activity, challengeParameters, receiver, timeOut = 5
)
}
Illustrative API shape, for orientation.
Your server orchestration is unchanged. AReq, CReq, CRes travel per spec.
Mitra visibility & policy control
Merchant-owned policy. Issuer-controlled authentication decisions.
Mitra connects Shastra risk context with Kavaach authentication outcomes in one transaction view. Merchant-managed thresholds and rule controls are being added so teams can tune policy without changing application code. Mitra remains optional; Shastra and Kavaach work independently.
Explore MitraPlatform
| Android | Shastra available · Kavaach available for evaluation · ≈800 KB Kavaach SDK |
|---|---|
| iOS | Shastra in development · Kavaach in development |
| Protocol | EMV 3DS 2.2 / 2.3 support; confirm the exact supported protocol versions for the evaluated build |
| Shastra model | On-device inference · <1 MB model |
| Inference | Local inference; no blocking backend round-trip |