Test JSC & HDIM Payloads
Registration requests (Add Renter, Add Agent, Add Organization) include two Experian device-fingerprinting fields:
| Field | Required | What it is |
|---|---|---|
jscPayload | Yes | Output of Experian's FraudNet JavaScript Collector — a device fingerprint generated in the end user's browser at submit time |
hdimPayload | No | Hardware Device Intelligence Module result — initial browser data collected when the page loads |
Both are forwarded to Experian for fraud prevention. The Embedded SDK and hosted screening flows collect these automatically — you only need the test values below when calling the REST API directly in UAT.
Test Payloads for UAT
Use these strings when creating a new Consumer, End User, or PMC Organization in the API integration testing environment:
POST /api/experian/renters/{renterId}POST /api/experian/agents/{agentId}POST /api/experian/organizations/{organizationId}
(All ID values are assigned by your integrating platform, not by relay.)
jscPayload — send both fields on every registration request:
cWa44j1fgBNlY5Du4UXuKrnZ2CI9XkPrwVL6tqAhbrmQmkqlE4Ww.GEFF0Yz3ccbbJYMLgiPFU77qZoOSix5ezdstlYysrhsui6SFLwke22OxijhO3f9p_nH1u_eH3BhxUC550ibVlNUuAuyPB94UXuGlfUm0NUbNiqUU8jA2Q3wL6k03x0.5EwHXXTSHCSPmtd0wVYPIG_qvoPfybYb5EvYTrYesSp0Qn1cBCbquypZHgfLMC7AwOkE5fuyPBCxUC56MnGWpwoNSUC550ial.rIN913lVa1LL6glV2R0odm_dhrxbuJjkWxv5iMgdVgEL3NvxKMApNJ4VdIXVDK1e6StMtcMtOUTlfe2RjOI0NFgBFY5CljQlpRxvEWMZyr6U5lY6RjNNlY6AQnIVNj5Zvj92rn5hxJ9cU90yP4yJ6xBPNNmrK1kcSFBc8rLLf5BRGwuKnnt.jrkRGZPPEtCPIvy_j9YUhJOw1NUbqnU9Z1OwJjpf9wOTWyW_TBjFlvdL90.rInS2i4yzGMEiselFCLH2Vmoz4XOwZdZVLkvjcger92XlF4XVA4.L901gJ.elF1x_Ff4.A2pWL90ftctDL90ftctDL9.Mge4Nc0TmcKXV4hkf4.snVTCQiBviSyti_Nc645bIwdTq1MhKwk0eOIg6QWFs.kdAEyk.Iy5dAaYYJmGzUXn.gJ.EKQ1gJ0HlF1f4.WL9.dNc635W6PdMA4.Oct_MlsqmgJ0rmfou9lF6MdMTLrwWoctrx9vrYMehysrhsuheSJSNc2fofjuKnHvrYM_hz7S9DSzHixspzHiPMTwPwhjr5xj6KhIeYf4.SHCRgJ0p7prijHiL9.KNc6KNc6KNc6KNc1Vf4.WL9.J1TcKXVS1lF1VIp1gJ.g9Vf4.90Nc0FA4.22q.gJ.iselF1vXke1gJ2c_0Aiu8FHf4.9eMRKJitHKXV4KAi9eMRd9lF1e_r4KAiJ_Nc0KHvXe_r9HgJ.0T0m.Zpuy.AC2
hdimPayload:
rO0ABXNyACdjb20udGhlNDEuY29tbW9ucy5jcnlwdG8uQ3J5cHRvRW52ZWxvcGUAAJbgqPhc8wIAA0wABWFsaWFzdAASTGphdmEvbGFuZy9TdHJpbmc7WwAMZW5jcnlwdGVkS2V5dAACW0JbABBlbmNyeXB0ZWRQYXlsb2FkcQB-AAJ4cHQABGhkaW11cgACW0Ks8xf4BghU4AIAAHhwAAACAEZU0lNyXXLTrXq7LRNe1Ymyi6_eMd8wKYzz-yqUstOHW7qNwQLXy_WjpUAszxg2-TeD5bJmRVuA9V0vWEHQSoTGuOMddh5sAYEKKLmPZOvSr_yfPLMGgvGX9f05QJzJ9hhNiqFoEYCuCuf5deg3565lmkUtgHtBbbBo_gtTP10LuNe0z2o9WDbY-QWJvdmNZ1hgjS5HplKbJNgwFsJDZJgBMv79qcFyRSP_PoVTSFmh3o1TpBadAKTZyxERPXPTw1PP3bxmhYDDNAcsREZPlalrkPbljabmGOXcAaXga3jTFMP5Vxq4X5IkOql7mu2Dl-VH44LVcjkXHQdW_lvR_zQD22nBxjSY120bPHa2hoFYstRJZCjnD1-UKTmn-aVDbEKDQfWzJCpYO6t8wBS5pMbPV0NusNZ7jxacmGINem0_QUIQWhPpDh-EkgZZTv1vOL4A858usYWzsg4F_jCSfuquK3gj8l-zDPskGhTiS3oAMi1ZtkvrHMO_738Ck2H7brkG65f20pqCufkYL2m1Vm-A-w7rjj6DZMB5kC0erpDj8WYY6OPRbx2WFBfmYpRwdG-01XIMR2OjEC-zQ1XyXFKJ9PZwCfdKBesgTi9Mi-ec4ZYYGgtyQfQRrQhNfg0nuzP1lJJdATu09xIBt6DIkym3ylVQa6EzWxsLY7Q5Xg7MdXEAfgAFAAACEBVIWKPDwaxrfwtbRtQGvMKD9cIG-t9z68gpu2cgI0PtS0_aAnMl2HAPeXdpYPVDQnXh8Qi6X8l9jUwIE4wYU5MMtmjF83EZZKlGNQM7UG20OYUqzoDytS4Qj6eSGFRJnh95HVmmWNL7_VGgw0I4nEVf8dEf0ORurFInMRfee42StkjsbAEKx3AszCNYZ5xrA63sSTo7Yiz2L6wB8o-sTLQlathGiZPhWJ6v5e0af0QpgQejrjhzj9l7M4GkaYDMp5VtfqtnvI8stMMurELE7EJJkYi4Hi8b7zmyWziP-iK6dPBu0iiS6C5eLU_jdNK4BWywHEUUZRiD1BOa9um2xL130lZejcddQVhrSlTlgmkYD7aVxk_dQqDFiHrv-jg4X01Qc6Lk1TmRkuBup-yhiv-rrPWKGjaoDsMZbR0646wAQPZIM3Xgfit3DtVb9-bdvprzCxdcIi9aCPj_g3Y7DyJgQfV0jLmyFLthulIyNKBFTohjpfZvnQnLL-1M4sbi8IAXX-b6p93Ia-4ocGqx_fUw_kH9j9RGfVEjxgZnJaVUG6qLMnBn8RlHhF_RuD_5Qa5KbTrqeoE7klGwKiWbpCYCUuSNSW9bduWrAw29nXKIj4goWUY-yGEQueQXxGifLb5NCZZBDssqrfPQknxlj_mayC_HprNcUwqG9GB5pcZhw4liifKX3TsoDmsZo5Nv3w
Test payloads work only in the UAT/sandbox environment. In production, Experian evaluates the real collector output as part of identity verification — requests with fabricated payloads may fail device recognition or be flagged for fraud.
UAT does not validate payload content — any string matching the field constraints is accepted (e.g. relay's own test tooling sometimes uses short stand-ins like test-jsc-payload). The full-length payloads above are the recommended values because they exercise the same request shape as production traffic.
Field Constraints
| Constraint | jscPayload | hdimPayload |
|---|---|---|
| Required | Yes | No (recommended — always send it) |
| Max length | 4,000 characters | 4,000 characters |
| Allowed characters | ' a-z A-Z 0-9 & . _ - | ' a-z A-Z 0-9 & . _ - |
How Real Payloads Are Generated
In production, the embedded screening form loads Experian's FraudNet JavaScript Collector, which exposes a browser API used in two phases:
- Page load — the collector contacts Experian's device-intelligence service and produces the HDIM payload.
- Form submit — the collector generates a fresh JSC payload (it is never cached, so its timestamp matches the risk event).
Real payloads are opaque blobs in the same format as the test values above.
Never log, cache, or store real jscPayload/hdimPayload values — relay's services scrub them from logs automatically, and your integration should do the same.
Related Resources
- Test Consumers — sandbox identities to pair with these payloads
- Getting Started — full registration walkthrough