What is 3D Secure?
Problem Statement
You want to understand what 3D Secure is, why it matters for card payments, and how it works with Chargebee.
Solution
3D Secure (3DS) is an authentication protocol implemented by card networks to verify the identity of a cardholder during online card payments. If you have bought something online and been redirected to your bank's page—or prompted in your banking app—to confirm the purchase, that step is 3D Secure in action.
During a 3DS payment, the cardholder proves they are the legitimate card owner. Authentication can use a one-time password, biometric verification, or another method stored separately from the card number. The issuing bank—not the merchant—decides whether additional verification is required for a given transaction.
3DS 2.0 and PSD2 SCA
3DS 2.0 is the current version of the protocol. It improves on 3DS 1.0 with better mobile support, a smoother cardholder experience, and more flexible authentication. Issuing banks that do not support 3DS 2.0 may still authenticate through 3DS 1.0, which typically redirects the cardholder to a separate window to enter a password or OTP.
In Europe, 3DS is the primary way merchants meet Strong Customer Authentication (SCA) requirements under the Revised Payment Services Directive (PSD2). SCA is a payment security regulation from the European Banking Authority that requires multi-factor authentication for many online card payments in the European Economic Area (EEA) and the United Kingdom.
SCA generally applies when:
- Your merchant account is with a processor or acquirer in the EEA, and you collect payments from cards issued in the EEA, or
- Your business is based in Europe or has a significant customer base there.
To learn where SCA applies and how it relates to your business, see What is SCA and where does it apply?. For Chargebee's full PSD2 and SCA guidance—including supported gateways, configuration steps, and fallback handling—see PSD2 and Strong Customer Authentication.
How 3DS appears to cardholders
When 3DS is triggered, the cardholder may see one of two flows:
- Frictionless flow: The payment gateway sends background data—such as device fingerprint and IP address—to the issuing bank. If the bank is satisfied, no extra step is shown and the payment proceeds.
- Challenge flow: The issuing bank requires explicit verification. The cardholder is prompted to authenticate—for example, through an OTP, banking app approval, or biometric check—before the payment can complete.
If the cardholder cannot or does not complete authentication, the payment fails.
Liability shift
When a payment is successfully authenticated with 3DS, liability for certain fraudulent chargebacks can shift from the merchant to the cardholder's issuing bank. The exact scope of liability shift depends on your payment gateway, card network, and region. Confirm the details with your gateway provider.
How 3DS works with Chargebee
Chargebee is not a payment gateway. Chargebee facilitates 3DS through your connected gateway and hosted checkout flows. The gateway collects the data needed for authentication and communicates with the issuing bank. Ultimately, the issuing bank decides whether a transaction requires 3DS verification.
To use 3DS with Chargebee:
- Enable 3DS in your gateway account. See How can I enable 3DS 2.0 in my gateway account?.
- Enable 3D Secure in Chargebee under Settings > Configure Chargebee > Payment Gateways >
{gateway you use}> Cards > Manage. - Complete the remaining SCA checklist steps in Chargebee—dunning, dunning emails, and Pay Now—so customers can recover when off-session payments require authentication. See What changes do I need to make to become SCA compliant?.
For a deeper look at what Chargebee controls during a 3DS transaction, see What is Chargebee's role in a 3DS transaction?.
Off-session payments—such as subscription renewals and trial-to-paid conversions—are usually treated as merchant-initiated transactions and often proceed without a challenge. If an issuing bank still requires authentication, the payment can fail and Chargebee can route the invoice into dunning. See What are Off-session payments? What will happen if Off-session payments require 3DS?.
Information
Chargebee supports 3DS only for gateways listed in PSD2 and Strong Customer Authentication. Gateway support and configuration details can differ by processor. Contact your gateway provider for account-specific 3DS behavior.
Important notes
- 3DS requirements and exemptions are set by regulators, card networks, and issuing banks—not by Chargebee.
- Enabling 3DS at your gateway does not mean every transaction will show a challenge screen. Many payments complete through the frictionless flow.
- If you need help choosing or migrating to a 3DS-supported gateway, contact Chargebee Support.
Was this article helpful?