What EMV 3-D Secure is
EMV 3-D Secure is a messaging protocol that lets a merchant and a card issuer exchange data to authenticate the cardholder on an online card payment. It is maintained by EMVCo, the technical body owned by American Express, Discover, JCB, Mastercard, UnionPay and Visa, and it works in browsers and inside mobile apps.
For many payments the issuer approves on the data alone and the customer simply pays; for riskier ones it asks for more, such as a one-time passcode or biometrics. It supports the strong customer authentication PSD2 requires in Europe, which is why it is one of the card payment checks of our Fraud & risk module.
What it does in your platform
Fraud & risk
Sends card payments through 3-D Secure so the card issuer can authenticate the cardholder before the payment goes ahead. The module's risk score and your rules shape how each payment is handled, and the result, frictionless or challenged, becomes part of its risk record.
How the connection works
The protocol runs between the 3DS Server on the merchant side, the card scheme's Directory Server and the issuer's Access Control Server, with a 3DS SDK inside mobile apps. We reach it through your acquirer, gateway or processor.
A customer pays by card
In your app or on the web. The module scores the payment against your rules before anything else happens.
Data goes to the issuer
Through the 3DS Server and the scheme's Directory Server, details of the payment and the device reach the issuer's Access Control Server.
The issuer decides
If the data reassures it, the issuer approves without a challenge and the customer sees nothing. If not, it asks for more.
The customer is challenged
With a one-time passcode, biometrics or an approval in their bank's app, shown inside your app through the 3DS SDK or in the browser.
The result travels on
The issuer's answer goes with the payment to authorisation, and the module records it in the payment's risk history, visible in the backoffice.
Next to other signals
3-D Secure sits next to the module's other card checks: Visa and Mastercard risk scores, your velocity limits and spending rules, and the scores of fraud engines such as Sardine, SEON, Sift or Feedzai.
EMVCo has also published a white paper on carrying FIDO authentication data, the technology behind passkeys, in 3-D Secure messages. Changing acquirer or 3DS provider later does not change your apps.
When EMV 3-D Secure fits best
A strong fit when
- You take card payments online or in your app, from cardholders in Europe.
- You want most good payments approved without a challenge, and risky ones authenticated.
- You want each payment's authentication result recorded next to its risk score.
Also worth a look
- Visa and Mastercard risk scores, which the module also reads on card payments.
- A fraud engine such as Sardine or Sift, to score card payments before they reach 3-D Secure.
How we get you live
The 3DS provider
We help you get 3-D Secure through your acquirer, gateway or processor, or a 3DS Server provider, using products approved by EMVCo.
The rules
We set with you when 3-D Secure is requested and what the module does with each result: frictionless, challenged or failed.
The keys
Credentials for your 3DS provider go into your platform's secrets and nowhere else.
A full test run
We run frictionless, challenged and failed payments end to end in test before your first real card payment.
