September 2026 Summaries
1 posts from Evervault
Filter
Month:
Year:
Post Summaries
Back to Blog
3D Secure (3DS) is an online card-payment authentication protocol designed to reduce card-not-present fraud by involving issuers before authorization, evolving from the disruptive password-based 3DS1 to 3DS2’s risk-based, largely frictionless flows and modern verification methods. It operates across merchant/acquirer, card-network interoperability, and issuer domains, with issuer Access Control Servers determining whether transactions are approved silently, challenged, declined, or otherwise handled based on risk data. Businesses use 3DS to meet regulations such as EU Strong Customer Authentication requirements, reduce fraud and chargeback exposure through liability shift, and approve transactions that might otherwise be declined or manually reviewed. Effective strategies differ between mandated and non-mandated markets, emphasizing exemptions, selective risk-based authentication, enriched device and transaction data, challenge preferences, and fallback approaches such as fail-on-challenge. Merchants should interpret authentication statuses and issuer- or network-specific error codes to address data problems, card issues, technical outages, challenge abandonment, and liability implications. The protocol also supports merchant-initiated and recurring payments through 3RI, data-sharing-only flows that may improve authorization without liability shift, and delegated authentication arrangements that can improve customer experience while transferring fraud responsibility. Businesses can use PSP-provided tools, standalone providers, or internally built certified servers, and should measure segmented success, challenge, abandonment, completion-time, and error rates to continually balance fraud prevention, compliance, conversion, and operational flexibility.
Sep 04, 2026
5,326 words in the original blog post.