SardineCon SF/2026

Learn More
Card & payment fraud4 min de leitura

O que é 3-D Secure (3DS)?

SUBSCRIBE

3-D Secure is the extra identity check that stands between an online card payment and a fraudster using a stolen card number. The shopper proves it is really them, and the merchant gets to push most fraud losses back onto the bank.

What is 3DS, in plain English?

3-D Secure adds a security check to online card payments, the kind where the card is never physically seen, also called card-not-present or CNP payments. When it kicks in, the shopper proves who they are before the payment clears, usually by approving it in their banking app, using a fingerprint or face scan, or typing in a one-time code.

The name comes from the three domains it ties together: the issuer (the shopper's bank), the acquirer (the merchant's bank), and the card network in the middle that connects them. Today's version, EMV 3DS (often called 3DS2), was built for phones and biometrics and does most of its work silently. The large majority of payments are waved through with no prompt at all, and only the riskier ones get stopped for a check.

Who actually deals with 3DS?

Everyone in an online card payment touches it, just in different ways:

Who

What they do with 3DS

Shoppers

Confirm their identity at checkout, usually through their bank's app or a one-time code.

Merchants and PSPs

Send payments through 3DS to cut fraud and push chargeback liability onto the bank.

Acquirers

The merchant's bank, which routes the authentication request into the card network.

Issuers

The cardholder's bank, which scores the risk and decides whether to challenge the shopper.

Geography decides how optional it is. In the UK and EU, 3DS is effectively required on most online card payments, because it is how firms meet Strong Customer Authentication (SCA) rules under PSD2. In markets like the United States it is usually a choice, but teams still lean on it hard to fight fraud and move liability.

With 3DS vs without: what changes?

For a payments risk team, turning on 3DS shifts three things at once: how much stolen-card fraud gets through, who eats the loss when it does, and how much friction real shoppers feel.

What changes

Without 3DS

With 3DS

Stolen-card fraud

Merchant is exposed

Bank check blocks most attempts

Who pays a fraud chargeback

Usually the merchant

Usually the issuer

Checkout friction

None added

Some, mostly on risky payments

SCA rules (UK and EU)

Not met

Met

That last column is the catch: friction is the price of the protection. Every added step makes some real shoppers give up, so 3DS is a dial you tune, not a switch you flip. The whole game is challenging the risky payments while letting good ones sail through.

How does a 3DS payment flow?

Behind one tap at checkout, the payment moves through all three domains in about a second. Each step below is tagged with the party doing the work:

  1. Shopper & merchant — Checkout. The shopper enters their card details on the merchant's site or app.
  2. Card network — Request routed to the bank. The merchant's 3DS setup sends transaction and device details to the shopper's bank through the card network.
  3. Issuer • the bank — Risk check, then one of two paths. The bank scores the payment in real time using the device, the amount, and the account's history.
    • Low risk — Frictionless. Approved silently. The shopper sees no prompt at all.
    • Higher risk — Challenge. The shopper proves it is them: bank app, biometric, or one-time code.
  4. Card network — Result and liability. The authentication result returns to the merchant. A passed check shifts most fraud liability to the issuer.
  5. Shopper & merchant — Authorization. The payment runs through normal authorization and the money moves.

One tap at checkout, about a second from end to end.

Where does 3DS trip teams up?

  • Real-time OTP phishing. A live scam can talk a victim into reading out the one-time code, which defeats the check. A passed 3DS is strong evidence, not proof.
  • Over-challenging. Set the bar too high and you block real customers and lose sales. Watch your challenge rate and abandonment right next to your fraud rate.
  • Exemptions. Under SCA, low-value payments, trusted merchants, and transaction risk analysis can skip the challenge. Used well they protect conversion, used sloppily they reopen the fraud gap.
  • Liability is not the same as no fraud. Shifting liability changes who pays, not whether fraud happened. Track both.

Quick questions

Does 3DS stop all fraud?

No. It is strong against stolen card numbers on card-not-present orders, because the fraudster still has to clear the issuer's check. It does little against authorized-push and scam fraud, where the genuine cardholder is manipulated into approving the payment or reading their one-time code to a fraudster. Treat a passed 3DS as strong evidence of authenticity, not proof.

Does the liability shift always apply?

Not always. On most authenticated consumer card-not-present transactions, a fraud chargeback moves to the issuer. But carve-outs exist: some commercial and corporate cards, certain regions, and non-fraud reason codes stay with the merchant, and first-party or friendly-fraud disputes are a separate fight. Confirm against the current scheme rules for the specific reason code in play.

Who decides frictionless vs challenge, and can the merchant influence it?

The issuer makes the call, but the merchant heavily influences it. The richer and cleaner the data you send in the 3DS request, such as device, billing, and prior transaction history, the more confidently the issuer can approve frictionless. Thin or messy data pushes more payments into a challenge, which costs conversion.

How do SCA exemptions fit in?

Under SCA, the acquirer or merchant can request exemptions such as low-value, transaction risk analysis (TRA), or trusted beneficiary to skip the challenge on low-risk payments. The tradeoff: claiming an exemption usually means keeping the fraud liability yourself instead of shifting it to the issuer. Teams weigh the conversion gain against the liability they take back on.

Can I still get a chargeback after a successful 3DS?

Yes. The liability shift only covers specific fraud reason codes. You can still see friendly or first-party fraud, where the real cardholder disputes a purchase they actually made, plus non-fraud disputes like item-not-received or subscription complaints. 3DS does not touch those.

Is 3DS the same as SCA?

No. SCA is the regulatory requirement for two-factor authentication on payments under PSD2. 3DS is the technical tool most card payments use to meet it. 3DS can satisfy SCA, but SCA also covers other payment flows, and 3DS is used in markets that have no SCA rule at all.

Do recurring and merchant-initiated payments need 3DS every time?

Usually just the first one. The initial setup or first customer-initiated payment typically needs authentication, then later merchant-initiated charges such as subscriptions and top-ups are often flagged as out-of-scope or exempt and run without a challenge. Getting that first transaction and the flags right is what keeps the rest smooth.

Go deeper

O que saber junto com 3-D Secure (3DS)