← Reference · Home · Print this page

Finance · Payments

EMV 3-D Secure (Online Card Authentication)

Reference entry · last updated 20260910

EMV 3-D Secure (EMV 3DS) is a protocol for authenticating consumers during card-not-present payments. It enables merchants and card issuers to exchange transaction, payment, and device information.[1]

1. First principles: authentication

Authentication assesses whether the person using a card is its legitimate user. Authorization is the payment approval stage. An authenticated customer can still encounter a declined payment.[2]

2. Frictionless and challenge flows

The issuer uses supplied information to assess a transaction. Authentication may complete without an extra customer step, or the issuer may request a challenge such as a one-time code or biometric check.[1]

3. Fraud-liability effects

Successful 3DS authentication can shift liability for eligible fraud-related chargebacks to the issuer. Network rules, transaction eligibility, and exceptions determine the result. Authentication does not remove non-fraud disputes or the need to respond to an inquiry.[2]

4. Strong customer authentication

EMV 3DS can support strong customer authentication requirements, including those associated with European PSD2 rules. The protocol is used beyond that jurisdiction; its use alone does not establish regulatory compliance for every transaction.[1]

5. See also

6. References

  1. EMVCo. EMV 3-D Secure.
  2. Stripe. 3D Secure authentication flow.