Merchant plug-in


A merchant plug-in is a software module designed to facilitate 3D-Secure verifications to help prevent credit card fraud. The MPI identifies the account number and queries the servers of the card issuer to determine if it is enrolled in a 3D-Secure program and returns the web site address of the issuer access control server if it is found. Merchants are responsible for using an SSL/TLS MPI at their servers.
Each card issuer is required to maintain an ACS used to support cardholder authentication. A customer authenticates to this ACS by providing their username and password and the ACS signs the result. This signature is then passed through the customer's browser and to the MPI. The plug-in verifies the ACS signature and decides if it wishes to proceed with the transaction.
Commercial MPI software is available from a number of vendors.