3D Secure
Also known as: 3DS, Verified by Visa, SCA
An extra authentication step that verifies the shopper and can shift fraud liability.
3D Secure adds a verification step, such as a bank prompt, biometric, or one-time code, to confirm the shopper is the genuine cardholder. It underpins Strong Customer Authentication (SCA) in Europe and can shift liability for fraudulent chargebacks from the merchant to the issuer.
How it works
Two things can happen, and the shopper only notices one of them. On submit, the gateway hands device and order data to a 3DS server, which routes it through the card network's directory to the issuing bank. The issuer scores the risk and answers. Frictionless comes back in about a second, and the shopper sees nothing at all. A challenge drops the shopper onto a bank-controlled screen for a passcode, an app approval, or a biometric. Whichever way it goes, the result is carried into the authorization request that follows.
Liability shift is narrower than most merchants expect. It covers fraud disputes and nothing else, so the customer who says the parcel never arrived, or that the goods were not as described, still charges back to you. It does not apply on transactions where you claimed an exemption and skipped authentication. It will not stop an issuer declining the card outright either. What it does do is real: authenticate successfully and a later fraud claim lands on the issuer, not on your account.
Against that sits conversion. A challenge is an extra step, and some shoppers walk away at it, especially on mobile where the handoff to a banking app can crawl. Pricing varies too: some gateways bundle 3DS into their rate, others bill per authentication attempt, so read the fee schedule before you switch it on across the whole checkout. The US has no mandate to use 3D Secure at all, which is why most American merchants trigger it selectively through risk rules.
Worked example
An online retailer sends every order above $300 through 3D Secure and leaves the rest alone. Take a month with 1,000 of those high-value orders. Say 850 authenticate in the background, invisible to the shopper, and 150 get a bank challenge, of which 10 abandon. The retailer is out 10 sales. In exchange it holds issuer liability on the 990 orders that completed, including whichever of them come back later as fraud claims.
Frequently asked questions
- Does 3D Secure reduce chargebacks?
- It moves fraud liability rather than stopping disputes. Authenticate a transaction successfully and a later fraud claim is charged to the issuing bank instead of your account. Claims about delivery, product quality, or a subscription the customer swears they cancelled are untouched, and for most merchants those make up the larger share of disputes.
- Is 3D Secure required in the United States?
- There is no US mandate. Strong Customer Authentication rules require most online card payments in the UK and European Economic Area to be authenticated, and 3D Secure is how cards meet that test, but nothing equivalent applies in the US. Most US merchants run it selectively, on high-value orders, address mismatches, or new customers, because applying it to every sale costs more conversion than it saves in fraud.
- Will 3D Secure hurt my checkout conversion?
- Only on the sessions that get challenged, and under 3DS 2 that share is usually small. Most authentications settle in the background, because the issuer gets enough device and order data to decide without troubling the shopper. Your measurable loss sits at the challenge step, mobile worst of all, so track abandonment there rather than watching your overall rate.