Kavaach · Native 3DS SDK

Ship native 3DS. Keep your server.

Add native mobile 3DS to the server you already operate without funding a separate SDK program. Android is available for evaluation today, iOS is in development, and EMVCo functional certification is underway.

  • ≈800 KB Android SDK
  • Works with your existing 3DS Server
  • EMVCo certification in progress
Rendered by the SDK, in the app Challenge type acsUiType 01 Sample illustrative values
01

Authentication stays in the app

Native challenge screens rendered by the SDK — no redirect out to a browser mid-checkout.

02

Your brand, end to end

White-labeled for your merchants: your name, your URLs, EMVCo UI customization on top.

03

The upkeep is ours

Spec revisions, scheme changes, OS releases, and recertification sit with us, not with you.

Two paths to native 3DS.

Whether you operate a 3DS Server or build merchant apps, Kavaach replaces the browser redirect with native authentication. Pick the path that matches your role.

Kavaach for Servers

Add a native 3DS SDK to your platform without building and maintaining it yourself.

  • White-labeled under your brand for the merchants you serve, with EMVCo UI customization on top.
  • Once certification is complete, the SDK's EMVCo approval applies to the certified SDK release; merchants integrating that approved SDK do not individually certify the SDK implementation with EMVCo.
  • Bundled device attestation signals included at no additional cost.

Footprint

The current Android AAR is reported at approximately 800 KB, with no external dependencies. Confirm the delivered artifact and app-size impact for your target release during evaluation.

Compatibility

Android available for evaluation. iOS is in development. Kavaach is designed to work with the certified 3DS Server you already operate, on EMVCo 3DS 2.2 and 2.3. No orchestration changes and no scheme relationships to redo.

Protocol 2.2 · 2.3 Android available for evaluation iOS in development Integration existing 3DS Server

Maintenance

Vyuha maintains specification changes, OS compatibility, bug fixes, and certification work. Review supported versions and maintenance terms during evaluation.

Certification status

EMVCo functional certification is in progress. Confirm approval status, supported versions, and production readiness before deployment.

Misconfigured 3DS implementations cost merchants 2–5% of approvals — and up to 15% in severe cases.

DECTA research

Questions

What 3DS Servers ask first.

Do our merchants have to re-certify the SDK?

Certification is in progress. Distribution and customization requirements must be confirmed against the final approval and license before rollout. We will review your merchant integration with you.

Who handles spec updates, scheme changes, and recertification?

Vyuha maintains the SDK, including specification changes, OS updates, bug fixes, and recertification work. Support and release terms are agreed in the license.

Does the SDK change our PCI scope?

The SDK is designed for authentication metadata, not card-number collection. PCI scope depends on your complete integration and should be confirmed with your compliance team.

Do we have to change our 3DS Server?

No. Kavaach works with the certified server you already operate. Shastra risk context and Mitra visibility stay separate from the protocol decision path — AReq, CReq, and CRes are not modified. Your orchestration and scheme relationships stay as they are.

What is the certification status today?

EMVCo functional certification is in progress. Talk to us about evaluation access and verify final approval before production deployment.

Enterprise licensing — pricing depends on distribution scope.

Kavaach for Merchants

Keep your 3DS provider. Replace the webview with native.

Native authentication without changing your provider.

Keep the 3DS provider you already use while moving the app-based authentication experience into a native SDK. Kavaach handles the SDK-side 3DS flow without requiring a server migration.

  • Provider-agnostic — designed to work with your existing 3DS Server. No lock-in, no migration.
  • Auto-theme detection — the SDK reads your app's theme and matches challenge screens automatically. No manual styling.
  • Smart Theme — full EMVCo UI customization layered on top of auto-detect, when you want control.
  • ≈800 KB Android SDK with zero external dependencies.
  • Pair with Mitra — the optional visibility & policy control add-on, including 3DS diagnostics a webview does not expose.

Same moment, two experiences

What your merchant's customer actually sees.

A native challenge keeps the customer inside the merchant app. Compare that presentation with a browser handoff in this illustrative example; actual issuer screens and supported customization vary.

  • Native challenge UI stays inside the merchant app, with supported EMVCo customization.
NorthwindSample

Verify your purchase

A native challenge is rendered inside the merchant app.

MerchantNorthwind
Amount$500.00

Illustrative native challenge.

85%

reduction in checkout time with native 3DS2

Visa

70%

reduction in card abandonment

Visa

9%

lift in approval rates on 3DS2 transactions

Visa

45%

reduction in fraud on authenticated transactions

Visa

Visa-reported improvements with 3DS 2.0 native SDK integration. Results vary by implementation and issuer.

What the SDK is doing in that moment

initialize()

Credentials validated, configuration received, signal collection starts.

Device data returned

Handed to your 3DS Server to assemble the AReq. No 3DS message is modified.

Native challenge

acsUiType 01 rendered in-app, only if the issuer asks for a challenge.

Result returned

The authentication completes and the result is returned to your app.

Illustrative timings, elapsed from initialize().

Merchant pricing

Simple annual or monthly licensing. Production pricing will be published before launch.

For engineering teams

A dependency, not a migration.

The SDK provides authentication request parameters to your app. Your server uses them to send the authentication request (AReq). If the issuer requests a challenge, the SDK handles the challenge exchange with the issuer's access control server (ACS).

  • 3DS messages are not mutated

    AReq, CReq, and CRes travel exactly as specified.

  • Your 3DS flow stays yours

    Kavaach works with your existing 3DS Server. Risk intelligence and Mitra visibility do not replace your server or take control of issuer authentication decisions.

  • A clear integration boundary

    Your server owns authentication orchestration. The SDK owns the on-device challenge and returns its result to your app.

Kotlin · Android · illustrative
// 1 — once per app process
val service = KavaachThreeDS2Service.getInstance()
service.initialize(context, config, locale, uiCustomization)

// 2 — once per transaction
val txn = service.createTransaction(directoryServerId, "2.2.0")
val params = txn.authenticationRequestParameters

// 3 — your server sends the AReq, unchanged
val ares = yourThreeDSServer.authenticate(params)

// 4 — challenge only if the issuer asks for one
if (ares.requiresChallenge) {
  txn.doChallenge(
    activity, challengeParameters, receiver, timeOut = 5
  )
}

Illustrative API shape, for orientation.

  1. Your merchant appYour checkout invokes 3DS when your policy calls for it.
  2. Kavaach native SDKProvides authentication parameters and renders the native challenge if the issuer requests one.
  3. Your 3DS Server · issuer ACSMerchant policy decides whether to invoke 3DS. If 3DS is invoked, the issuer controls the authentication outcome and challenge decision.
Optional: Shastra adds on-device risk context to your policy, and Mitra adds transaction visibility. Neither replaces your 3DS Server or takes part in issuer authentication decisions.

The rest of the platform.

Kavaach works on its own. These two use the same native footprint when you want them.

Early integration program

Evaluate native 3DS before certification completes.

Early 3DS Server partners can integrate against Kavaach now, help shape the integration, and be ready to move toward production once certification is complete.