Skip to main content

Test JSC & HDIM Payloads

Registration requests (Add Renter, Add Agent, Add Organization) include two Experian device-fingerprinting fields:

FieldRequiredWhat it is
jscPayloadYesOutput of Experian's FraudNet JavaScript Collector — a device fingerprint generated in the end user's browser at submit time
hdimPayloadNoHardware Device Intelligence Module result — initial browser data collected when the page loads

Both are forwarded to Experian for fraud prevention. The Embedded SDK and hosted screening flows collect these automatically — you only need the test values below when calling the REST API directly in UAT.

Test Payloads for UAT

Use these strings when creating a new Consumer, End User, or PMC Organization in the API integration testing environment:

  • POST /api/experian/renters/{renterId}
  • POST /api/experian/agents/{agentId}
  • POST /api/experian/organizations/{organizationId}

(All ID values are assigned by your integrating platform, not by relay.)

jscPayload — send both fields on every registration request:

cWa44j1fgBNlY5Du4UXuKrnZ2CI9XkPrwVL6tqAhbrmQmkqlE4Ww.GEFF0Yz3ccbbJYMLgiPFU77qZoOSix5ezdstlYysrhsui6SFLwke22OxijhO3f9p_nH1u_eH3BhxUC550ibVlNUuAuyPB94UXuGlfUm0NUbNiqUU8jA2Q3wL6k03x0.5EwHXXTSHCSPmtd0wVYPIG_qvoPfybYb5EvYTrYesSp0Qn1cBCbquypZHgfLMC7AwOkE5fuyPBCxUC56MnGWpwoNSUC550ial.rIN913lVa1LL6glV2R0odm_dhrxbuJjkWxv5iMgdVgEL3NvxKMApNJ4VdIXVDK1e6StMtcMtOUTlfe2RjOI0NFgBFY5CljQlpRxvEWMZyr6U5lY6RjNNlY6AQnIVNj5Zvj92rn5hxJ9cU90yP4yJ6xBPNNmrK1kcSFBc8rLLf5BRGwuKnnt.jrkRGZPPEtCPIvy_j9YUhJOw1NUbqnU9Z1OwJjpf9wOTWyW_TBjFlvdL90.rInS2i4yzGMEiselFCLH2Vmoz4XOwZdZVLkvjcger92XlF4XVA4.L901gJ.elF1x_Ff4.A2pWL90ftctDL90ftctDL9.Mge4Nc0TmcKXV4hkf4.snVTCQiBviSyti_Nc645bIwdTq1MhKwk0eOIg6QWFs.kdAEyk.Iy5dAaYYJmGzUXn.gJ.EKQ1gJ0HlF1f4.WL9.dNc635W6PdMA4.Oct_MlsqmgJ0rmfou9lF6MdMTLrwWoctrx9vrYMehysrhsuheSJSNc2fofjuKnHvrYM_hz7S9DSzHixspzHiPMTwPwhjr5xj6KhIeYf4.SHCRgJ0p7prijHiL9.KNc6KNc6KNc6KNc1Vf4.WL9.J1TcKXVS1lF1VIp1gJ.g9Vf4.90Nc0FA4.22q.gJ.iselF1vXke1gJ2c_0Aiu8FHf4.9eMRKJitHKXV4KAi9eMRd9lF1e_r4KAiJ_Nc0KHvXe_r9HgJ.0T0m.Zpuy.AC2

hdimPayload:

rO0ABXNyACdjb20udGhlNDEuY29tbW9ucy5jcnlwdG8uQ3J5cHRvRW52ZWxvcGUAAJbgqPhc8wIAA0wABWFsaWFzdAASTGphdmEvbGFuZy9TdHJpbmc7WwAMZW5jcnlwdGVkS2V5dAACW0JbABBlbmNyeXB0ZWRQYXlsb2FkcQB-AAJ4cHQABGhkaW11cgACW0Ks8xf4BghU4AIAAHhwAAACAEZU0lNyXXLTrXq7LRNe1Ymyi6_eMd8wKYzz-yqUstOHW7qNwQLXy_WjpUAszxg2-TeD5bJmRVuA9V0vWEHQSoTGuOMddh5sAYEKKLmPZOvSr_yfPLMGgvGX9f05QJzJ9hhNiqFoEYCuCuf5deg3565lmkUtgHtBbbBo_gtTP10LuNe0z2o9WDbY-QWJvdmNZ1hgjS5HplKbJNgwFsJDZJgBMv79qcFyRSP_PoVTSFmh3o1TpBadAKTZyxERPXPTw1PP3bxmhYDDNAcsREZPlalrkPbljabmGOXcAaXga3jTFMP5Vxq4X5IkOql7mu2Dl-VH44LVcjkXHQdW_lvR_zQD22nBxjSY120bPHa2hoFYstRJZCjnD1-UKTmn-aVDbEKDQfWzJCpYO6t8wBS5pMbPV0NusNZ7jxacmGINem0_QUIQWhPpDh-EkgZZTv1vOL4A858usYWzsg4F_jCSfuquK3gj8l-zDPskGhTiS3oAMi1ZtkvrHMO_738Ck2H7brkG65f20pqCufkYL2m1Vm-A-w7rjj6DZMB5kC0erpDj8WYY6OPRbx2WFBfmYpRwdG-01XIMR2OjEC-zQ1XyXFKJ9PZwCfdKBesgTi9Mi-ec4ZYYGgtyQfQRrQhNfg0nuzP1lJJdATu09xIBt6DIkym3ylVQa6EzWxsLY7Q5Xg7MdXEAfgAFAAACEBVIWKPDwaxrfwtbRtQGvMKD9cIG-t9z68gpu2cgI0PtS0_aAnMl2HAPeXdpYPVDQnXh8Qi6X8l9jUwIE4wYU5MMtmjF83EZZKlGNQM7UG20OYUqzoDytS4Qj6eSGFRJnh95HVmmWNL7_VGgw0I4nEVf8dEf0ORurFInMRfee42StkjsbAEKx3AszCNYZ5xrA63sSTo7Yiz2L6wB8o-sTLQlathGiZPhWJ6v5e0af0QpgQejrjhzj9l7M4GkaYDMp5VtfqtnvI8stMMurELE7EJJkYi4Hi8b7zmyWziP-iK6dPBu0iiS6C5eLU_jdNK4BWywHEUUZRiD1BOa9um2xL130lZejcddQVhrSlTlgmkYD7aVxk_dQqDFiHrv-jg4X01Qc6Lk1TmRkuBup-yhiv-rrPWKGjaoDsMZbR0646wAQPZIM3Xgfit3DtVb9-bdvprzCxdcIi9aCPj_g3Y7DyJgQfV0jLmyFLthulIyNKBFTohjpfZvnQnLL-1M4sbi8IAXX-b6p93Ia-4ocGqx_fUw_kH9j9RGfVEjxgZnJaVUG6qLMnBn8RlHhF_RuD_5Qa5KbTrqeoE7klGwKiWbpCYCUuSNSW9bduWrAw29nXKIj4goWUY-yGEQueQXxGifLb5NCZZBDssqrfPQknxlj_mayC_HprNcUwqG9GB5pcZhw4liifKX3TsoDmsZo5Nv3w
UAT only

Test payloads work only in the UAT/sandbox environment. In production, Experian evaluates the real collector output as part of identity verification — requests with fabricated payloads may fail device recognition or be flagged for fraud.

note

UAT does not validate payload content — any string matching the field constraints is accepted (e.g. relay's own test tooling sometimes uses short stand-ins like test-jsc-payload). The full-length payloads above are the recommended values because they exercise the same request shape as production traffic.

Field Constraints

ConstraintjscPayloadhdimPayload
RequiredYesNo (recommended — always send it)
Max length4,000 characters4,000 characters
Allowed characters' a-z A-Z 0-9 & . _ -' a-z A-Z 0-9 & . _ -

How Real Payloads Are Generated

In production, the embedded screening form loads Experian's FraudNet JavaScript Collector, which exposes a browser API used in two phases:

  1. Page load — the collector contacts Experian's device-intelligence service and produces the HDIM payload.
  2. Form submit — the collector generates a fresh JSC payload (it is never cached, so its timestamp matches the risk event).

Real payloads are opaque blobs in the same format as the test values above.

Treat real payloads as sensitive

Never log, cache, or store real jscPayload/hdimPayload values — relay's services scrub them from logs automatically, and your integration should do the same.