Implementing Dynamic Data Collection (DDC) with Threedsmax: A Practical Guide
Learn how to add Dynamic Data Collection to your 3DS2 flow with the Threedsmax Java library, see a concrete example, trade‑offs, and how to verify the data reaches the ACS.
08 Nov 2025, 11:42 UTC

Problem: Missing Device Context in 3DS2 Authentication
When a merchant sends an AuthRequest to the ACS, the payload often contains only static transaction data. 3DS2 requires richer device metadata—screen size, time zone, user agent—to assess risk accurately. Without this context, the ACS may reject the transaction or return a poor challenge, hurting conversion rates.
Thesis: Use Threedsmax’s Dynamic Data Collection (DDC) to Supply Device Metadata
Threedsmax exposes a DdcRequestBuilder that automatically packages device information into the deviceData field of the AuthRequest. The ACS will echo this data back in the challenge payload, allowing the merchant to log, audit, and satisfy PCI‑DSS requirements.
Prerequisites & Setup
- Threedsmax library ≥ 2.5.0 (DDC support was added in this release).
- Java 11+ (Threedsmax 2.x requires at least Java 11).
- Access to a 3DS2 ACS that supports DDC (most modern processors do).
- Basic Maven or Gradle project setup.
Add the dependency to your build file:
<dependency>
<groupId>com.threedsmax</groupId>
<artifactId>threedsmax</artifactId>
<version>2.5.1</version>
</dependency>
implementation 'com.threedsmax:threedsmax:2.5.1'
Building the DDC Payload
The DdcRequestBuilder provides a fluent API. At a minimum you should set the device time and screen size; other fields are optional but recommended.
import com.threedsmax.ddc.*;
// 1. Create the builder
DdcRequestBuilder builder = new DdcRequestBuilder();
// 2. Populate optional fields
builder.setDeviceTime(System.currentTimeMillis());
builder.setScreenSize("1920x1080");
builder.setUserAgent("Mozilla/5.0 (Windows NT 10.0; Win64; x64)");
// 3. Build the DDC payload
DdcRequest ddc = builder.build();
When you call ddc.toJson(), the library serialises the data into a JSON object that looks like:
{
"deviceTime": 1734059914000,
"screenSize": "1920x1080",
"userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
}
Injecting DDC Into the AuthRequest
The AuthRequest is built using AuthRequestBuilder. Add the DDC payload before sending the request:
import com.threedsmax.*;
AuthRequestBuilder authBuilder = new AuthRequestBuilder();
// Set mandatory transaction fields
authBuilder.setAmount(1000);
authBuilder.setCurrency("USD");
authBuilder.setMerchantId("12345");
// Attach DDC
authBuilder.setDeviceData(ddc.toJson());
AuthRequest authRequest = authBuilder.build();
// Send to ACS
ThreedsmaxClient client = new ThreedsmaxClient("https://acs.example.com/auth");
AuthResponse response = client.authenticate(authRequest);
Verify that the outbound HTTP payload contains a deviceData key under threeDSRequestorAuthenticationData. This confirms that the DDC is being transmitted.
Parsing the DDC Response
When the ACS returns a challenge, the device data is echoed back. Use DdcResponseParser to extract it:
import com.threedsmax.ddc.*;
String challengeJson = response.getChallengePayload();
DdcResponseParser parser = new DdcResponseParser(challengeJson);
Map<String, String> returnedData = parser.getDeviceData();
// Log or audit
System.out.println("DDC returned: " + returnedData);
Check that the values match those you set earlier. If they differ, the ACS may have overridden them or the request was malformed.
Trade‑Offs and Limitations
- Payload Size & Latency – Adding DDC increases the
AuthRequestsize by a few hundred bytes. In high‑volume environments this can add measurable latency, especially over 3G/4G links. - ACS Compatibility – Some legacy ACS endpoints ignore
deviceDataand return an error code (e.g.,DDC_NOT_SUPPORTED). Verify your processor’s documentation. - Data Accuracy – The DDC fields are optional. If you omit critical data, the ACS may still treat the transaction as low‑risk, but you lose the benefit of richer context.
- Version Dependency – DDC is only available in Threedsmax 2.5.0+. Using an older library will cause a
NoSuchMethodErrorwhen callingDdcRequestBuilder.
Practical Validation Checklist
- Confirm dependency version:
mvn dependency:tree | grep threedsmax. - Run a unit test that builds an
AuthRequestwith DDC and prints the request JSON. Look fordeviceData. - Send the request to a test ACS (e.g., EmvCo sandbox). Trigger a challenge by setting
challengeWindowSize. - Inspect the challenge payload for a
deviceDatasection. Use the parser to extract it. - Compare the parsed values to the ones you set; they should match.
- If the ACS returns an error, check the error code and confirm that DDC is supported in your environment.
Takeaway & Next Steps
Adding Dynamic Data Collection via Threedsmax is a straightforward code change that can dramatically improve authentication quality and compliance. By following the example above, you ensure that device metadata is captured, transmitted, and logged. Evaluate your system’s latency tolerance and ACS compatibility before enabling DDC in production. Once validated, roll out the change and monitor challenge rates to quantify the benefit.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.