Merchant Fraud Guide Sections

3D Secure Payment Gateway: A Merchant's Guide

What 3D Secure does, who runs the challenge, and how liability shift really works when you pick a gateway.

You are picking a payment gateway and every provider mentions 3D Secure. Some treat it as a selling point. Few explain what you are actually buying. Here is what the protocol does, who controls it, and where its protection stops.

What 3D Secure is

3D Secure is a worldwide protocol that checks who is paying in real time before an online card payment goes through. Visa developed the original protocol. That early work laid the foundation for the authentication standards now used around the world. It checks the cardholder before the payment is approved. It looks at data like device type, location and past spending. Your customers may know it by its card network names. Visa calls it Visa Secure. Mastercard calls it Identity Check. American Express calls it SafeKey.

For a deeper look at the protocol itself, see 3D Secure credit card authentication.

Why it matters for your store

Small and mid-size businesses are fraud targets. They take many payments where no card is present. That is every sale you make. 3DS helps reduce fraud risk for your business and your customers by verifying the purchaser is the legitimate cardholder. Visa's guide says adopting 3DS authentication can help merchants reduce fraud-related chargebacks and strengthen customer trust. A fraudulent sale can later turn into a chargeback.

How it runs through your gateway

The protocol lets merchants and issuers swap data safely before a sale is approved. Merchants can connect to a 3DS program to add the authentication to their eCommerce site.

Here is the part that surprises merchants. On Stripe, Stripe starts the request. The card issuer decides if the customer must authenticate. The bank that issued the card may require a password, a single-use code, or biometric verification. Or the issuer might request a flow that does not visibly display a 3DS challenge.

You do not control that choice, and you do not control the screen. Stripe's documentation says you cannot change the web check screen. The bank that issued the card picks the fonts and colors. The customer sees the bank's page, not yours.

For the full step-by-step, read how does 3D Secure work at checkout.

Liability shift, and its limits

If a cardholder disputes a 3DS payment as fraudulent, the liability typically shifts from you to the card issuer. That is the real prize, and successful authentication reduces fraud risk and can shift liability away from the merchant.

But read the word "typically" carefully. A passed 3DS check does not promise the liability will shift. You might still receive an Early Fraud Warning even when the payment is covered by the liability shift rule. Think of the shift as what usually happens, not as a guarantee.

Required regions versus optional ones

In some regions, regulation decides for you. 3DS turns on by itself when the law requires it. Strong Customer Authentication is one such rule. Stripe's documentation says its mandatory authentication rules run automatically, whether or not you manually request 3DS. Stripe's documentation also says you can't use Stripe APIs to manually turn off 3DS.

3DS is optional in other regions, and you can use it to reduce fraud. In those markets, you choose whether to ask for it, and the issuer still decides the final flow.

What to look for in a gateway

Compare 3DS support on these points:

  • Current protocol with fallback. Major card brands no longer support 3D Secure 1. Stripe's integration runs 3D Secure 2 when the customer's bank supports it and falls back to 3D Secure 1 otherwise. Ask any gateway what version it runs and what happens when a bank lags behind.
  • Platform coverage. Stripe lets you integrate 3D Secure authentication into your checkout flow on Web, iOS, Android, and React Native. Make sure the gateway covers the platforms you sell on.
  • Flow options. Adyen's docs describe a challenge flow. Here the issuer asks the shopper for extra steps, like a fingerprint or a one-time code. They also describe a data-only flow. It sends a 3D Secure 2 request but skips the customer check. Only Visa and Mastercard offer it.
  • Running 3DS apart from processing. Stripe's documentation says you can run 3D Secure on Stripe. The payment can still process on a third-party gateway. You can also import 3DS results when 3DS runs outside of Stripe. Adyen's docs describe standalone authentication. It checks the customer and returns data. You can use that data to approve the payment later. This split matters if you want to keep your current processor.
  • Control over when it fires. Stripe says you can use Radar or the API to decide when to prompt users for 3DS authentication.

Where 3DS does not apply

Not all transactions support 3DS. Stripe's documentation names wallets and off-session payments as examples. The customer is only prompted to authenticate if 3DS is available for the card. Otherwise the payment proceeds normally, with no added check.

Authentication can also fail. The customer may not complete the bank's challenge, and the sale stops there. See 3D Secure authentication failed for what causes it and what to do.

The honest summary

A gateway with good 3DS support checks identity before the payment goes through. It may shift liability on fraudulent disputes. It also handles rules where the law requires it. It does not stop all fraud, it does not cover every payment type, and it does not let you design the challenge screen. Judge a gateway on a few points. What version does it run? What platforms does it cover? What flows does it offer? Can you run 3DS apart from processing? Then check each provider's current pricing page. Prices change often.

To confirm whether your current setup already runs it, see if you are 3D Secure enabled.

Sources

The rest of 3-D Secure