Skip to content
Ready to get started, Let's Go! Talk to Sales

Glossary

3-D Secure (3DS)

3-D Secure is a card-network authentication protocol that verifies a cardholder's identity during an online transaction (via their bank's risk checks or a challenge like a one-time passcode) and shifts fraud chargeback liability from the merchant to the issuer.

3-D Secure (branded as Visa Secure, Mastercard Identity Check, and American Express SafeKey) adds a cardholder authentication step to card-not-present payments. The “three domains” are the merchant/acquirer, the card network, and the issuer, which cooperate to answer a question neither AVS nor CVV can: is the person at the checkout actually the cardholder?

How it works

With 3DS 2, the merchant’s payment flow sends a rich set of transaction and device data to the issuer before authorization. In the majority of cases the issuer’s risk engine authenticates silently, a “frictionless” flow the customer never sees. Higher-risk attempts get a challenge: a one-time code to the cardholder’s phone, or approval in their banking app. The result is an authentication cryptogram submitted with the authorization.

The commercial effect is the liability shift: fraud-coded chargebacks on successfully authenticated transactions generally become the issuer’s loss, not the merchant’s. In Europe, 3DS is effectively mandatory: PSD2’s Strong Customer Authentication rules require it for most online card payments. In the US it is optional, and merchants weigh the fraud protection against checkout friction and the risk that challenges cost conversions; a common strategy is selective 3DS, invoking it only on transactions a fraud model scores as risky.

Why it matters

For merchants with fraud exposure (high tickets, digital goods, resellable inventory), 3DS is the strongest tool available, and using it selectively requires a processor whose API exposes 3DS per transaction rather than as an all-or-nothing setting.

QorPay supports 3-D Secure on QorCommerce, invocable per transaction through the v3 API, with authentication results carried through to authorization and dispute records.

In the docs: 3-D Secure ↗