Connector · Card payment authentication

EMV 3-D Secure, at your card checkout.

How our Fraud & risk module uses EMV 3-D Secure to authenticate cardholders on online card payments: what the protocol is, how the card issuer decides, and how we get you live.

Website
emvco.com
Modules
Fraud & risk
Standard
EMVCo

What EMV 3-D Secure is

EMV 3-D Secure is a messaging protocol that lets a merchant and a card issuer exchange data to authenticate the cardholder on an online card payment. It is maintained by EMVCo, the technical body owned by American Express, Discover, JCB, Mastercard, UnionPay and Visa, and it works in browsers and inside mobile apps.

For many payments the issuer approves on the data alone and the customer simply pays; for riskier ones it asks for more, such as a one-time passcode or biometrics. It supports the strong customer authentication PSD2 requires in Europe, which is why it is one of the card payment checks of our Fraud & risk module.

What it does in your platform

  • Fraud & risk

    Sends card payments through 3-D Secure so the card issuer can authenticate the cardholder before the payment goes ahead. The module's risk score and your rules shape how each payment is handled, and the result, frictionless or challenged, becomes part of its risk record.

How the connection works

The protocol runs between the 3DS Server on the merchant side, the card scheme's Directory Server and the issuer's Access Control Server, with a 3DS SDK inside mobile apps. We reach it through your acquirer, gateway or processor.

  1. A customer pays by card

    In your app or on the web. The module scores the payment against your rules before anything else happens.

  2. Data goes to the issuer

    Through the 3DS Server and the scheme's Directory Server, details of the payment and the device reach the issuer's Access Control Server.

  3. The issuer decides

    If the data reassures it, the issuer approves without a challenge and the customer sees nothing. If not, it asks for more.

  4. The customer is challenged

    With a one-time passcode, biometrics or an approval in their bank's app, shown inside your app through the 3DS SDK or in the browser.

  5. The result travels on

    The issuer's answer goes with the payment to authorisation, and the module records it in the payment's risk history, visible in the backoffice.

Next to other signals

3-D Secure sits next to the module's other card checks: Visa and Mastercard risk scores, your velocity limits and spending rules, and the scores of fraud engines such as Sardine, SEON, Sift or Feedzai.

EMVCo has also published a white paper on carrying FIDO authentication data, the technology behind passkeys, in 3-D Secure messages. Changing acquirer or 3DS provider later does not change your apps.

When EMV 3-D Secure fits best

A strong fit when

  • You take card payments online or in your app, from cardholders in Europe.
  • You want most good payments approved without a challenge, and risky ones authenticated.
  • You want each payment's authentication result recorded next to its risk score.

Also worth a look

  • Visa and Mastercard risk scores, which the module also reads on card payments.
  • A fraud engine such as Sardine or Sift, to score card payments before they reach 3-D Secure.

How we get you live

  • The 3DS provider

    We help you get 3-D Secure through your acquirer, gateway or processor, or a 3DS Server provider, using products approved by EMVCo.

  • The rules

    We set with you when 3-D Secure is requested and what the module does with each result: frictionless, challenged or failed.

  • The keys

    Credentials for your 3DS provider go into your platform's secrets and nowhere else.

  • A full test run

    We run frictionless, challenged and failed payments end to end in test before your first real card payment.

Questions

Asked about this connector.

How do we get started with 3-D Secure?

Talk to us. We help you get 3-D Secure through your acquirer, gateway or processor, set the rules with you and test frictionless and challenged payments end to end before going live.

Will every customer see a challenge?

No. For many payments the issuer approves on the data alone and the customer simply pays. Challenges are for payments the issuer sees as riskier.

Does 3-D Secure work inside our mobile app?

Yes. EMV 3-D Secure supports purchases inside mobile apps, with any challenge shown in the app through a 3DS SDK, as well as in browsers.

Which version should we use?

EMVCo recommends version 2.2 or higher for the full set of features, and we set up the version your acquirer and the card schemes support.

  • Visa and Mastercard risk scores

Start your project

Tell us the idea. We'll show you the platform.

One call is enough to map your product to the modules that already exist.

  • Response in under one business day
  • NDA on request
  • No obligation
What are you building?