Shastra
Device intelligence
Tells you whether this is a device you have seen before, and how it looks today — on the device, before 3DS is invoked.
Explore ShastraKavaach · Native 3DS SDK
Add native mobile 3DS to the server you already operate without funding a separate SDK program. Android is available for evaluation today, iOS is in development, and EMVCo functional certification is underway.
We sent a one-time code to the mobile number ending 5329.
Need help? · Cancel
Native challenge screens rendered by the SDK — no redirect out to a browser mid-checkout.
White-labeled for your merchants: your name, your URLs, EMVCo UI customization on top.
Spec revisions, scheme changes, OS releases, and recertification sit with us, not with you.
Whether you operate a 3DS Server or build merchant apps, Kavaach replaces the browser redirect with native authentication. Pick the path that matches your role.
Add a native 3DS SDK to your platform without building and maintaining it yourself.
The current Android AAR is reported at approximately 800 KB, with no external dependencies. Confirm the delivered artifact and app-size impact for your target release during evaluation.
Android available for evaluation. iOS is in development. Kavaach is designed to work with the certified 3DS Server you already operate, on EMVCo 3DS 2.2 and 2.3. No orchestration changes and no scheme relationships to redo.
Vyuha maintains specification changes, OS compatibility, bug fixes, and certification work. Review supported versions and maintenance terms during evaluation.
EMVCo functional certification is in progress. Confirm approval status, supported versions, and production readiness before deployment.
Misconfigured 3DS implementations cost merchants 2–5% of approvals — and up to 15% in severe cases.
DECTA research
Questions
Certification is in progress. Distribution and customization requirements must be confirmed against the final approval and license before rollout. We will review your merchant integration with you.
Vyuha maintains the SDK, including specification changes, OS updates, bug fixes, and recertification work. Support and release terms are agreed in the license.
The SDK is designed for authentication metadata, not card-number collection. PCI scope depends on your complete integration and should be confirmed with your compliance team.
No. Kavaach works with the certified server you already operate. Shastra risk context and Mitra visibility stay separate from the protocol decision path — AReq, CReq, and CRes are not modified. Your orchestration and scheme relationships stay as they are.
EMVCo functional certification is in progress. Talk to us about evaluation access and verify final approval before production deployment.
Enterprise licensing — pricing depends on distribution scope.
Keep your 3DS provider. Replace the webview with native.
Keep the 3DS provider you already use while moving the app-based authentication experience into a native SDK. Kavaach handles the SDK-side 3DS flow without requiring a server migration.
Same moment, two experiences
A native challenge keeps the customer inside the merchant app. Compare that presentation with a browser handoff in this illustrative example; actual issuer screens and supported customization vary.
A native challenge is rendered inside the merchant app.
Illustrative native challenge.
reduction in checkout time with native 3DS2
Visa
reduction in card abandonment
Visa
lift in approval rates on 3DS2 transactions
Visa
reduction in fraud on authenticated transactions
Visa
Visa-reported improvements with 3DS 2.0 native SDK integration. Results vary by implementation and issuer.
Credentials validated, configuration received, signal collection starts.
Handed to your 3DS Server to assemble the AReq. No 3DS message is modified.
acsUiType 01 rendered in-app, only if the issuer asks for a challenge.
The authentication completes and the result is returned to your app.
Illustrative timings, elapsed from initialize().
Simple annual or monthly licensing. Production pricing will be published before launch.
For engineering teams
The SDK provides authentication request parameters to your app. Your server uses them to send the authentication request (AReq). If the issuer requests a challenge, the SDK handles the challenge exchange with the issuer's access control server (ACS).
AReq, CReq, and CRes travel exactly as specified.
Kavaach works with your existing 3DS Server. Risk intelligence and Mitra visibility do not replace your server or take control of issuer authentication decisions.
Your server owns authentication orchestration. The SDK owns the on-device challenge and returns its result to your app.
// 1 — once per app process
val service = KavaachThreeDS2Service.getInstance()
service.initialize(context, config, locale, uiCustomization)
// 2 — once per transaction
val txn = service.createTransaction(directoryServerId, "2.2.0")
val params = txn.authenticationRequestParameters
// 3 — your server sends the AReq, unchanged
val ares = yourThreeDSServer.authenticate(params)
// 4 — challenge only if the issuer asks for one
if (ares.requiresChallenge) {
txn.doChallenge(
activity, challengeParameters, receiver, timeOut = 5
)
}
Illustrative API shape, for orientation.
Kavaach works on its own. These two use the same native footprint when you want them.
Early integration program
Early 3DS Server partners can integrate against Kavaach now, help shape the integration, and be ready to move toward production once certification is complete.