Skip to content
Web Development

3D Secure Authentication in Ecommerce: How It Works and When to Use It

How 3D Secure works in ecommerce: EMV 3DS frictionless and challenge flows, strong customer authentication, exemptions, liability shift, integration steps, checkout UX and how to measure it.

Quick answer

3D Secure lets the card issuer authenticate the cardholder during an online payment. Modern EMV 3DS sends transaction and device data to the issuer, which either approves silently (frictionless) or asks the cardholder to confirm in their banking app or with a code (challenge). Successful authentication usually shifts liability for fraud chargebacks to the issuer. In the EEA and UK it is generally required for customer-initiated payments unless an exemption applies; elsewhere, use it selectively for higher-risk transactions. Implement it through your payment provider and send complete data to maximize frictionless approvals.

Where This Fits

3DS is one control in a wider fraud strategy covered in ecommerce fraud detection. Failed authentication is a payment failure type covered in payment failure handling, and its role in subscriptions is in recurring payments. Regional rules are summarized in international payments.

How 3D Secure Works

Three parties take part. The merchant side (your provider's 3DS server) gathers transaction and device data. The card network's directory server routes the request to the right issuer. The issuer's access control server assesses risk and decides whether to approve or challenge. The result, including a cryptographic authentication value, is then sent with the authorization request.

EMVCo maintains the EMV 3-D Secure specification, which supports browser and in-app flows and much richer data than the original protocol.

Liability outcomes are typical, not universal; network rules and region decide the specifics.

Frictionless vs Challenge Flows

In a frictionless flow, the issuer approves based on the data it receives and the shopper sees nothing extra. In a challenge flow, the issuer asks the shopper to confirm, usually through a banking app notification, a one-time passcode or biometrics in the app. The share of frictionless approvals depends heavily on data quality: complete billing and shipping addresses, email, phone, device data and account history all help the issuer decide without asking.

Strong Customer Authentication and Exemptions

Under PSD2 in the EEA and the equivalent UK rules, most customer-initiated electronic payments require strong customer authentication, which 3DS provides for cards. Some transactions can be exempted or are out of scope, as summarized in Stripe's SCA guide:

  • Low-value payments: under €30, with cumulative limits after which authentication is required
  • Transaction risk analysis: low-risk transactions where the acquirer or issuer meets fraud-rate thresholds
  • Trusted beneficiaries: where the customer has whitelisted the merchant with their bank, if the issuer supports it
  • Merchant-initiated transactions: out of scope once the agreement was set up with authentication
  • Secure corporate payments: certain dedicated business payment processes

Worth noting

An exemption is a request, not a guarantee. The issuer can decline and ask for authentication, so your integration must be able to run 3DS when a soft decline asks for it. Liability for fraud on exempted payments usually stays with whoever requested the exemption.

Liability Shift

When a payment is successfully authenticated, liability for certain fraud-related chargebacks usually shifts to the issuer. That makes 3DS useful outside mandatory regions for high-risk orders. It does not cover non-fraud disputes such as 'item not received' or 'not as described', and conditions vary by network, region and outcome. Check your acquirer's rules rather than assuming every authenticated payment is protected.

Balancing 3DS, fraud and conversion?

ZSpace Labs can configure risk-based authentication through your provider and measure challenge rates, approvals and fraud by segment.

Start a Project

Integrating 3DS Through Your Provider

Most merchants use their payment provider's 3DS support rather than certifying their own 3DS server. Modern provider APIs handle it inside the payment flow: if authentication is needed, the payment moves to a state such as 'requires action', your front end displays the challenge using the provider's SDK, and the payment continues once the shopper completes it. Adyen's 3D Secure documentation and Stripe's payment lifecycle documentation describe these flows.

  • Send complete data: billing and shipping address, email, phone, account age where supported
  • Use the provider's SDK for device data collection and challenge display
  • Show challenges in a modal or inline frame sized for mobile, not a full redirect, where the provider supports it
  • Handle abandoned or failed challenges as recoverable failures
  • Store the authentication result with the payment for disputes
  • Support authentication requests after exemption declines

Checkout UX for Challenges

Prepare shoppers for the challenge. A short line before payment ('Your bank may ask you to confirm this payment') reduces surprise. Keep the challenge inside your checkout on mobile, avoid timing out the session while the shopper switches to their banking app, and return them to a clear state afterwards. If authentication fails, keep the cart and offer another payment method. Device wallets often avoid a separate challenge; see digital wallet integration.

When to Use 3DS Outside Mandatory Regions

Where 3DS is optional, applying it to every order adds friction and may lower conversion. A common pattern is risk-based: your fraud tool scores the order, low-risk orders proceed without 3DS, higher-risk orders are authenticated, and very high-risk orders are declined or reviewed. Measure the combined effect on conversion, fraud chargebacks and manual review workload.

Measuring 3DS Performance

  • Share of payments sent to 3DS and share exempted
  • Frictionless rate versus challenge rate, by issuer country and card brand
  • Challenge completion and abandonment rates
  • Authorization rate after successful authentication
  • Fraud chargebacks on authenticated versus non-authenticated payments
  • Checkout conversion with and without 3DS for comparable traffic

Advantages and Limitations of 3D Secure

AdvantagesLimitations
Meets strong authentication rules in the EEA and UKChallenges add a step and some shoppers abandon
Usually shifts fraud chargeback liability to the issuerDoes not cover non-fraud disputes or friendly fraud
Rich data lets issuers approve more payments silentlyFrictionless rates depend on data your checkout may not send
Can be applied selectively by risk elsewhereIssuer support and behaviour vary by market
Supported by mainstream providers out of the boxExemptions shift liability back to the requester

How to Implement 3DS Step by Step

  • 1. Confirm requirements for each market you sell into, with your acquirer
  • 2. Use your provider's current payment API that handles authentication inside the payment flow
  • 3. Send complete data in every authentication request
  • 4. Build the challenge UI inline or modal, tested on mobile and with banking app switches
  • 5. Handle 'requires action' and soft declines asking for authentication
  • 6. Decide your exemption and risk strategy with your provider and fraud tools
  • 7. Store authentication results with each payment for dispute evidence
  • 8. Measure frictionless, challenge and abandonment rates by issuer country

Worked Example

An illustrative scenario, not a client case: a UK fashion retailer sees a high challenge rate. Investigation shows its checkout sends no shipping address or phone number in the authentication request. After passing complete data through the provider's API and moving the challenge into an inline modal on mobile, the frictionless share rises and fewer shoppers abandon at authentication.

Common Mistakes

  • Sending minimal data and getting more challenges
  • Full-page redirects that lose mobile shoppers
  • Treating exemptions as guaranteed
  • No path for authentication requested after a soft decline
  • Applying 3DS to every order where it is optional, without measuring
  • Assuming liability shift covers non-fraud disputes

Need 3DS that protects revenue without adding friction?

Talk to ZSpace Labs about payment and authentication integration, Shopify payment configuration or a checkout audit.

Start a Project

Conclusion

3D Secure is a tool for shifting fraud liability and meeting authentication rules. Implement it through your provider, send complete data, keep challenges smooth on mobile, use exemptions and risk-based triggering thoughtfully, and measure frictionless rates and conversion. Related: fraud detection, chargeback management and payment security.

FAQ

Common questions

A card authentication protocol that lets the card issuer verify the cardholder during an online payment, either silently using device and transaction data or by asking the cardholder to confirm through a one-time code or banking app.

Get in touch

Have a project in mind?

Whether you're building a new digital product, improving an existing website, or looking to automate part of your business — let's talk.

Keep exploring
Shopify & Ecommerce
8 min read

Ecommerce Fraud Detection: How to Identify Suspicious Transactions

How ecommerce fraud detection works: fraud types, identity, device, behaviour and order signals, rules and machine learning risk scores, manual review, false positives and how to measure results.

Read article
Web Development
8 min read

Ecommerce Payment Failure Handling: How to Reduce Failed Transactions

How to handle failed ecommerce payments: soft and hard declines, timeouts and unknown outcomes, idempotency, retry rules, shopper error messages, asynchronous confirmation, recovery and monitoring.

Read article
Web Development
8 min read

Ecommerce Recurring Payments: How to Build Reliable Billing Experiences

How recurring card payments work in ecommerce: customer- and merchant-initiated transactions, stored credentials, network tokens, account updater, SCA, retries, dunning, webhooks and customer communication.

Read article