How Does 3D Secure Work at Checkout?
A real-time identity check layered onto your online card payments. Here is what happens between checkout and authorization, and what it means for fraud.
The shopper clicks pay. Before the money moves, someone checks that the person holding the card is the person it belongs to. That check is 3D Secure.
What 3D Secure actually is
3D Secure is a set of rules used around the world. It adds a live identity check to online card payments. It runs before the payment is authorized. Shoppers might know it through card network branding such as Visa Secure, Mastercard Identity Check, or American Express SafeKey.
Visa built the first version. It set the stage for the checks the whole world uses today. Visa's guide gives one reason it matters. Visa data shows card-not-present fraud rates are 7.5 times higher than card-present rates, accounting for nearly 89% of all payment fraud.
The three parties
The 3DS ecosystem is made up of three key stakeholders who work together.
The first is you, the merchant. The second is the issuer, the bank that holds the shopper's card. The third is the network, which oversees program rules, data exchange standards and risk policies.
You send data. The issuer judges it. The network sets the rules both sides play by.
What happens between checkout and authorization
3D Secure lets you and the card bank safely swap details before the payment is approved. This is the part most merchants never see.
When the shopper pays, your system passes details to the issuer. The issuer reads data points like device type, location and historical spending. It uses them to decide, right there, whether this looks like the real cardholder.
All of this happens in the moment, before authorization.
Frictionless or challenge
A payment that fits the rules can take one of two paths. The card bank picks which one. It can be a frictionless flow or a challenge flow.
In a frictionless flow, the data was enough. The payment goes through with no more steps for the shopper. The shopper may never know a check ran at all.
In a challenge flow, the issuer asks the shopper for extra interaction. The bank may ask the shopper to prove who they are. They might type a password, enter a one-time code, or use biometric verification. This is the prompt some of your customers see and others do not.
Why merchants use it
3DS checks that the buyer really owns the card. That cuts fraud risk for you and for your customers. A fraudster's order can come back at you later as a chargeback, so catching it early is worth the effort.
There is also compliance. Some rules require a strong check of who is paying. PSD2 SCA in Europe is one. Adyen recommends 3D Secure 2 to comply with them. In other regions 3DS is optional, and you can use it to reduce fraud.
Then there is liability. A passed check cuts fraud risk. It can also move the loss off your plate. If a customer disputes a 3DS payment as fraud, the bank usually takes the loss, not you.
The limits
Read that last paragraph again, because the fine print matters. A passed check does not always shift the blame to the bank. Do not treat an authenticated payment as untouchable.
Not all transactions support 3DS. Wallets and off-session payments are examples where it may not apply. A payment that skips the check gets no protection from it.
There is also conversion to weigh. Adyen's documentation says redirection might lead to lower conversion rates. That can happen through technical errors or shoppers dropping out of the authentication process.
Where to go deeper
This page covers the basics. The current version of the standard is explained in 3D Secure 2. The technical detail lives in the 3D Secure protocol.
If you connect through a payment provider, read about the 3D Secure payment gateway side of things. And when a shopper cannot complete the check, the reasons are covered in 3D Secure authentication failed.