3-D Secure is the step in an online card payment where the cardholder's own bank confirms it is really them, usually through their banking app or a one-time code. The card schemes sell it under their own names, Visa Secure and Mastercard Identity Check, and in Europe it is how most merchants meet the legal requirement for strong customer authentication.

For a merchant its main attraction is the liability shift. It is also the part most often misunderstood.

What the shift is

Without authentication, an online merchant carries the cost of fraud. If a cardholder says "that was not me", the money goes back and the merchant loses the sale and the goods.

When a payment has been authenticated through 3-D Secure, that liability moves to the card issuer. If a fraud dispute follows, the issuer absorbs it and the merchant keeps the money.

What it covers

Only disputes raised for fraud. That is the whole of it.

What it does not cover

  • Every other kind of dispute. Goods not received, not as described, a cancelled subscription still billed, a refund not processed: authentication has nothing to say about any of these, and the merchant remains liable.
  • Later payments in a subscription. The first payment, made with the customer present, can be authenticated. The renewals that follow are initiated by the merchant, with no cardholder there to authenticate, and carry no shift.
  • Payments where the merchant asked to skip the check. European rules allow exemptions, for low values or for transactions the merchant's provider judges low risk. If the merchant requests the exemption, the merchant keeps the liability.
  • Some merchants and categories. A merchant inside a scheme's fraud or chargeback monitoring programme can lose the shift, and certain categories never receive it in full.
  • Payments that were attempted but not completed properly. The shift depends on the authentication result that came back, and the rules for an attempt differ between schemes.

Frictionless and challenged

Modern 3-D Secure does not always stop the customer. The merchant sends the issuer data about the payment, and the issuer either approves it silently, which is called frictionless, or asks the cardholder to confirm, which is called a challenge. Both count as authenticated, and both normally carry the shift.

That matters because the old objection to 3-D Secure was lost sales at the challenge screen. The better the data a merchant sends, the more payments pass without one.

What it costs you

  • Conversion. Some customers abandon at a challenge, and some issuers' authentication fails for technical reasons.
  • A fee. Many providers charge for each authentication.
  • Nothing in the dispute count, necessarily. A fraud dispute on an authenticated payment may not cost the merchant money, but ask your provider whether it still counts toward the scheme's monitoring ratio.

Using it well

  1. Authenticate where the fraud risk is. High-value orders, first-time customers and unusual patterns are where the shift earns its cost.
  2. Use exemptions deliberately. Skipping the check on a low-risk repeat customer improves conversion, but you are choosing to carry the fraud risk on that payment.
  3. Send complete data. Billing address, email, device information and order history all help the issuer approve without a challenge.
  4. Keep the result. The authentication outcome is the evidence if a fraud dispute is raised anyway.
  5. Do not treat it as a chargeback cure. If most of your disputes are about delivery or cancellations, authentication will not reduce them.

The question to ask your provider

For each kind of payment you take, first purchase, renewal, one-click repeat and exempted, ask who carries a fraud dispute. The answer differs for each, and a merchant who assumes one answer for all of them finds out otherwise through a chargeback.

Sources