Merchant plug-in
software used to help prevent credit card fraud on e-commerce sites

A merchant plug-in (MPI) is a software module designed to facilitate 3-D Secure verifications to help prevent credit card fraud. The MPI identifies the account number and queries the servers of the card issuer (Visa, MasterCard, or JCB International) to determine if it is enrolled in a 3D-Secure program and returns the web site address of the issuer access control server (ACS) if it is found. Merchants are responsible for using an SSL/TLS MPI at their servers.
Each card issuer is required to maintain an ACS used to support cardholder authentication. A customer authenticates to this ACS by providing their username and password and the ACS signs the result (success or failure). This signature is then passed through the customer's browser and to the MPI. The plug-in verifies the ACS signature and decides if it wishes to proceed with the transaction.
Commercial MPI software is available from a number of vendors.
See also
3D-Secure
Montague, David. "3DS-Implementation That Makes Sense". Fraud Practice.
Begin with the source’s own compact description: “Merchant plug-in” is software used to help prevent credit card fraud on e-commerce sites. The dossier treats that line as a proposition to test through Merchant, plug-in and software, not as a finished interpretation.
Why this record matters
The phrase “software used to help prevent credit card fraud on e-commerce sites” supplies a clear boundary for inquiry. It also exposes the unanswered questions: who defined that boundary, when it became stable and which sources sit outside it.
Datasets, specimens, observations and peer-reviewed methods provide the appropriate test for the technical claims summarized here. The source revision retrieved here is dated Aug 25, 2025. The linked authority identifier is Q6818417. None of the 0 selected statements returned an explicit reference.
Scientific names, classifications and consensus can change while older terminology persists in catalogues and historical literature. The lead is largely declarative, so disagreement and counter-evidence require a deliberate search beyond the opening account. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Check terminology, classification and the date of the cited evidence. Scientific names and technical consensus can change while older records retain historical value.
- Current terminology
- Classification context
- Finding cited technical literature
Primary datasets, specimen catalogues, standards bodies and the most recent peer-reviewed literature.
Three-step research path
- Establish the record: confirm the title “Merchant plug-in”, its source revision and the description used here.
- Expand the search: follow Merchant plug-in primary sources, Merchant plug-in archive and Merchant research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Merchant plug-in”?
- Is the terminology current, historical or disputed?
- Which observation, specimen, dataset or publication supports the account?
Search terms from this dossier
This entry incorporates text from “Merchant plug-in” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.