Payments glossary · Security

3-D Secure (3DS)

3-D Secure (3DS) is a protocol that lets the card issuer authenticate the cardholder during an online payment, either silently using risk data or with a challenge such as a banking-app approval, and it can shift fraud liability from the merchant to the issuer.

How 3-D Secure works

The current version, EMV 3-D Secure, is maintained by EMVCo and branded by the card schemes, for example as Visa Secure and Mastercard Identity Check. During checkout the merchant's 3DS provider sends the issuer data about the transaction, the payment method and the customer's device. The issuer approves low-risk payments in the background (a frictionless flow) or asks the customer to verify with a one-time passcode, biometrics or a banking app (a challenge flow). It works in web browsers and inside mobile apps.

3DS is the main way card payments meet strong customer authentication (SCA) rules in the EEA and UK. Where a payment qualifies for an SCA exemption, such as a low-value transaction or one approved through transaction risk analysis, the merchant's provider can request the exemption, but the issuer has the final say and may still require a challenge.

The commercial benefit is the liability shift: under card scheme rules, fraud-related chargebacks on authenticated transactions generally become the issuer's responsibility rather than the merchant's. The costs are added friction, which can reduce conversion if challenges are frequent, and provider fees. In markets where authentication is not mandatory, many merchants apply 3DS selectively to higher-risk orders.

Compare providers

Related terms

Sources

  1. EMVCo: EMV 3-D Secure
  2. Visa: 3D Secure – your guide to safer transactions

← All payments terms