What Happens After the First Authentication? Understanding Merchant-Initiated Authentication

A subscription has two authentication problems, not one, and they are solved by different parts of the protocol. The first is straightforward. The cardholder is present, signing up, and can be authenticated the way any other purchase is authenticated.…

How Card Range Data Shapes 3DS Server Reliability

Every authentication request your 3DS Server builds depends on information it obtained earlier, from a different source, about a card range it may not have seen recently. That information is card range data, and it is one of the quieter dependencies…

3DS Out-of-Band Authentication: What Happens When the App Cannot Open

Out-of-band authentication in a native app should be the smoothest experience in the whole protocol. The cardholder is already on their phone, the banking app is already installed, and the approval is one biometric prompt away. When it works,…

Understanding the Directory Server’s Role and Limits in EMV 3DS

Diagrams of EMV 3D Secure usually show three boxes and two arrows. The merchant's 3DS Server on one side, the issuer's Access Control Server on the other, and something in the middle labelled Directory Server that everyone nods at and nobody…

How Bridging Message Extensions Support New Features in Older 3DS Products

No payments estate upgrades in a single step. Some components move to a new protocol version quickly, others are constrained by vendor release cycles, scheme certification windows or simply by the fact that they work and nobody wants to touch…

What the 3DS Requestor Must Disclose Before an App Collects Device Data

Teams building app-based 3D Secure usually discover the disclosure obligations at the worst possible moment, which is during app store submission, with a release date already committed. The requirements are not onerous. They are just easy to…

How the ACS Information Indicator Tells the Acquiring Side What an Issuer Supports

Most acquiring-side 3DS implementations send the same shaped authentication request to every issuer and find out what happened afterwards. That works, in the sense that transactions authenticate. It also means a good deal of information the…

How the 3DS SDK Gathers, Encrypts, and Transmits Device Data to the ACS

App-based 3D Secure has a reputation for producing better frictionless rates than browser flows, and the reason is usually given as richer device data. That is true, but it is an incomplete answer. The more interesting part is how the data…

When an Issuer Lets the Merchant Authenticate the Cardholder

A cardholder unlocks a retailer's app with their face, browses, and checks out. They are then asked to authenticate again, this time by their bank, using a code sent by text message. The second authentication is weaker than the first and considerably…