3D Secure Authentication Failed
The error means the cardholder's bank did not finish its identity check. Here is what happened, what you control, and what to tell the customer.
The customer typed the card in. The basket was full. Then the checkout showed "3D Secure authentication failed" and the sale was gone. Here is what that message means, and what you can do about it. If the term is new to you, start with our 3D Secure guide.
What the error actually means
3D Secure is a protocol that adds a security layer to card transactions. It helps cut fraud risk. It checks that the buyer is the real cardholder. The check happens first. Only then can the payment be approved. It looks at things like the device, the location, and past spending.
So the error means one thing. The cardholder's bank did not finish confirming that the person at your checkout is the real cardholder. The payment stops there. It is not a judgment about your store, and it is not proof the customer is a thief.
The issuer drives the flow, not your checkout
This is the part merchants get wrong. The requirement for the customer to authenticate comes from the card issuer. Your payment provider starts the check. But the issuer decides what happens next.
Issuers can ask for different 3DS flow types. Some of them never show the customer a 3DS challenge at all. Sometimes the customer sees nothing at all. Other times it asks the shopper to do more. This can be a fingerprint or a second code. That is a challenge flow.
Adyen offers a third option, called the data-only flow. It submits a 3D Secure 2 request without asking the shopper to authenticate. It is only available for Visa and Mastercard. So a 3DS check does not always show the customer a challenge.
Customers may know it by its brand names. These include Visa Secure, Mastercard Identity Check, and American Express SafeKey. That is why the same check shows up under different names. Our pages on 3D Secure credit card flows and Visa 3D Secure cover the brand side.
Common reasons the check fails
A few causes cover most cases.
The customer abandoned or failed the challenge. The bank asked for a one-time code, a password, or a fingerprint. The customer did not finish it. Wrong code, closed window, gave up.
Not every card gets the check. The customer is only prompted to authenticate if 3DS is available for the card. If not, the payment just goes through. So one card can get a 3DS prompt and another none.
Your integration broke it. If you embed the 3DS iframe, do not use the sandbox attribute on it. Some issuers' code breaks when it is sandboxed. This one is on you, and it is worth checking before you blame the customer.
Why your gateway rejects the payment
Sometimes the customer fails the challenge. Then your 3D Secure payment gateway rejects the payment. That can look like double punishment. It can be a rule running without you.
Stripe's rules that force authentication fire on their own. They fire whether or not you ever request 3DS. Stripe's Strong Customer Authentication rules also run automatically. They block any payment that was not checked, unless it is exempt. Your gateway is following a mandate, not picking on this one order.
Can you turn it off or force it on?
Stripe says you can't use its APIs to manually turn off 3DS. Stripe also can't guarantee your 3DS preference. The issuer picks the final flow. You can ask for 3DS, and the issuer can still run it another way.
Outside mandated regions, 3DS is optional and you can use it to reduce fraud. Visa's data shows card-not-present fraud rates are 7.5 times higher than card-present rates. It makes up nearly 89% of all payment fraud. That is the case for turning it on where you can.
What to tell the customer
Keep it short and blame-free. Ask them to try the payment again, since a challenge can fail on a mistyped code. Suggest another card or payment method if the first keeps failing. If it still will not go through, suggest they contact their bank, since the requirement to authenticate comes from the card issuer.
Test failures before customers hit them
Do not wait for a real order to find out your 3DS setup is broken. A test card can be used to trigger 3DS authentication challenge flows while in a sandbox. Run the full challenge in test mode before you go live.
Does a failed check mean fraud?
No. A failure tells you the check did not complete. It does not tell you why. The customer could have mistyped a code.
The reverse is also true. A successful 3DS check does not guarantee the bank will absorb the loss. A passed check is one good signal, not a promise. Read it alongside the rest of the order, the same way you would read any other signal.