3-D Secure is an EMVCo messaging protocol that adds cardholder authentication to card-not-present payments, sharing risk data between the merchant, the card network, and the issuer across three domains. The modern version, EMV 3DS (3DS2), supports frictionless risk-based authentication and app/biometric challenges, and is the primary mechanism card payments use to meet Strong Customer Authentication requirements. It is branded as Visa Secure, Mastercard Identity Check, and others.
3-D Secure
3-D Secure is the authentication layer on top of a card-not-present payment — the step that proves the person entering the card is allowed to use it. The ‘three domains’ are the merchant’s acquirer, the card network, and the issuer, exchanging risk signals so the issuer can decide whether to wave a transaction through or challenge it.
- Frictionless when it can be - EMV 3DS (3DS2) shares device and behavioral data so most transactions pass without a challenge, and only riskier ones prompt a biometric or one-time code.
- The SCA workhorse - In Europe it is the primary way card payments satisfy PSD2 Strong Customer Authentication.
- Network-branded - Visa Secure, Mastercard Identity Check, and their peers are all 3DS under the hood.
3-D Secure is the card world’s answer to the same question FAPI answers for open banking: how do you make a payment credential safe to present over a hostile network. In my payments scoring it shows up across the card-acceptance surface as the authentication seam, and it is a useful reminder that ‘payment API security’ is two conversations — protecting the API token, and authenticating the human behind the card — that providers have to get right at the same time.
Referenced in API Evangelist papers
This standard shows up in my published research. These reports read the machine-readable evidence provider by provider — and put this standard in the context of a real sector.
The State of US Payments APIs
3-D Secure appears across the card-acceptance surface (TabaPay, gateways) as the cardholder-authentication layer.
Governed by these regulations
A standard is the machine-readable contract; a regulation is the law that requires it. These are the regulations that mandate or drive this standard, catalogued at regulations.apievangelist.com.
Strong Customer Authentication
3-D Secure 2 is the primary way card payments satisfy PSD2's SCA requirement in Europe.
Revised Payment Services Directive (PSD2)
PSD2's authentication mandate drove near-universal EMV 3DS adoption on European card payments.