# Support
source: https://developer.mastercard.com/consent-management/documentation/support/index.md

## FAQ {#faq}

### Enrollment and Consent Scope {#enrollment-and-consent-scope}

You can enroll a maximum of 350 cards per call when using the Bulk Card Consent API. If you need to enroll more than 350 cards, split them across multiple requests. For details on the request format, see [Bulk Card Enrollment](https://developer.mastercard.com/consent-management/documentation/use-cases/transaction-notifications/bulk-card-enrolment/index.md). No. When creating a project, add both the Consents API and the Transaction Notifications API to the same project. This ensures your credentials work across both services. See the [Quick Start Guide](https://developer.mastercard.com/consent-management/documentation/quick-start-guide/index.md) for details. You can test challenge, frictionless, and failure scenarios in Sandbox using the provided test cards. Each test card triggers a different 3DS outcome. See [Testing](https://developer.mastercard.com/consent-management/documentation/testing/index.md) for the full list of test cards and expected results. No. Consent Management \& Enrollment does not provide an SDK. You can use the Mastercard [OAuth client libraries](https://github.com/Mastercard?q=oauth) for request signing and the [Reference App](https://developer.mastercard.com/consent-management/documentation/developer-tools/reference-app/index.md) for working implementation examples. No. Consent Management \& Enrollment works with Automatic Billing Updater (ABU) to automatically update a previously enrolled card when it expires or is stolen/lost and replaced with a new card.

### API Operations and Error Handling {#api-operations-and-error-handling}

Cause: A consent is bound to the original card reference and card number updates are not supported.

Solution: Delete the existing consent, then create a new consent for the replacement card. See [API Reference](https://developer.mastercard.com/consent-management/documentation/api-reference/index.md).
Authentication is triggered by the cardholder's bank (issuer). When a cardholder initiates enrollment either through the Mastercard UI or your own UI, the issuer determines if the cardholder must be authenticated (using 3DS, for example). Yes, if you are PCI compliant. You can build your own UI using the Consent APIs. The Mastercard team reviews your UI to ensure cardholders understand how their data is shared and stored. For more information, see [Consent using Consent Management \& Enrollment APIs](https://developer.mastercard.com/consent-management/documentation/use-cases/transaction-notifications/single-card-enrolment/apis/index.md). The partner does not receive transaction notifications on a card with expired consent. The partner must capture the cardholder's consent again to receive transaction notifications on that card. You set consent expiration in days in the consent creation request. During onboarding, the maximum consent duration is decided and configured for your use case. If your consent expiration equals the agreed-upon duration, you can leave the consent expiration field blank. For the request format, see [API Reference](https://developer.mastercard.com/consent-management/documentation/api-reference/index.md). Not always. If you act on behalf of an issuer or co-brand partner and the cardholder has previously granted consent for data sharing, no further authentication may be needed. This is particularly applicable when registering cards using [Bulk Card Enrollment](https://developer.mastercard.com/consent-management/documentation/use-cases/transaction-notifications/bulk-card-enrolment/index.md). Contact us at [transaction.notifications@mastercard.com](mailto:transaction.notifications@mastercard.com) for more details on enrolling such cards. Cause: The hosted UI flow focuses on capture and authentication, not lifecycle deletion.

Solution: Delete consent through the API endpoints in [API Reference](https://developer.mastercard.com/consent-management/documentation/api-reference/index.md).

### Access, Pricing, and Security {#access-pricing-and-security}

Follow the [Onboarding Checklist](https://developer.mastercard.com/consent-management/documentation/tutorials-and-guides/onboarding-checklist/index.md) to request Production access. If you need additional assistance, contact us at [transaction.notifications@mastercard.com](mailto:transaction.notifications@mastercard.com). Email us at [transaction.notifications@mastercard.com](mailto:transaction.notifications@mastercard.com) to get tailored pricing for your use case. Cause: Strict CSP values can block issuer challenge pages during 3DS authentication.

Solution: Review Mastercard CSP guidance for issuer challenge loading and align your `frame-src` policy as needed:
[EMV 3DS CSP guidance](https://developer.mastercard.com/mastercard-gateway/documentation/security-and-fraud/authentication/3d-secure-auth/)

## Get Help {#get-help}

Email us at [transaction.notifications@mastercard.com](mailto:transaction.notifications@mastercard.com) with any questions. Include your project name, CID, and a description of the issue or request.

Consent Management \& Enrollment Service is currently running with a select few customers, to request access to production system please contact us at [transaction.notifications@mastercard.com](mailto:transaction.notifications@mastercard.com).
