Developers

One mobile integration. Clear APIs.

Shastra returns on-device risk context to merchant policy. Kavaach handles native 3DS when authentication is required. Mitra adds transaction visibility and policy control across either product. Shastra and Kavaach can each be adopted independently; Mitra is optional.

Shastra integration

Score mobile transaction risk on-device: 0–100, higher means higher risk.

  • attachToCheckoutView(rootView)

    Starts permissioned signal collection on the merchant's checkout view hierarchy, where enabled and disclosed.

  • deviceDecision(context?)

    Returns bindingId, recognized state, score, and reason codes. Optional merchant-supplied context (amount, currency) enriches the score. No network round-trip.

Kotlin · Android · illustrative
// Optional — context the merchant already has
val context = RiskContext.builder()
  .amountMinor(50000)
  .currency("USD")
  .build()

// Resolved locally during initialize()
val device = service.deviceDecision(context)

device.bindingId     // "bnd_8f2a…b2a1"
device.recognized    // true
device.priorAuths    // 47
device.boundSince    // 2025-07-14
device.score         // Sample: 18 / 100; higher means higher risk
device.reasonCodes   // [RECOGNIZED_DEVICE, …]

// Your policy, your call
if (device.recognized && device.score < policy.frictionlessCeiling) {
  checkout.requestFrictionless()
}

Illustrative API shape, for orientation.

No blocking backend round-trip. Score produced locally, on-device.

Kavaach integration

Authenticate natively with your existing 3DS Server.

  • initialize(context, config, locale, uiCustomization)

    Once per transaction. Validates credentials, receives configuration, starts signal collection.

  • getAuthenticationParameters(brand)

    Returns device data for your server to assemble the AReq. No 3DS message is modified.

  • doChallenge(activity, challengeParameters, receiver, timeOut)

    Renders the issuer's native challenge inside the app, only if required. Returns the result to your app.

Kotlin · Android · illustrative
// 1 — once per app process
val service = KavaachThreeDS2Service.getInstance()
service.initialize(context, config, locale, uiCustomization)

// 2 — once per transaction
val txn = service.createTransaction(directoryServerId, "2.2.0")
val params = txn.authenticationRequestParameters

// 3 — your server sends the AReq, unchanged
val ares = yourThreeDSServer.authenticate(params)

// 4 — challenge only if the issuer asks for one
if (ares.requiresChallenge) {
  txn.doChallenge(
    activity, challengeParameters, receiver, timeOut = 5
  )
}

Illustrative API shape, for orientation.

Your server orchestration is unchanged. AReq, CReq, CRes travel per spec.

Mitra visibility & policy control

Merchant-owned policy. Issuer-controlled authentication decisions.

Mitra connects Shastra risk context with Kavaach authentication outcomes in one transaction view. Merchant-managed thresholds and rule controls are being added so teams can tune policy without changing application code. Mitra remains optional; Shastra and Kavaach work independently.

Explore Mitra

Platform

Android Shastra available · Kavaach available for evaluation · ≈800 KB Kavaach SDK
iOS Shastra in development · Kavaach in development
Protocol EMV 3DS 2.2 / 2.3 support; confirm the exact supported protocol versions for the evaluated build
Shastra model On-device inference · <1 MB model
Inference Local inference; no blocking backend round-trip

Talk to us