Passwordless authentication has moved from a browser specification to a live capability inside EMV 3D Secure, and issuers who wait for a card scheme mandate before evaluating it will be planning reactively rather than ahead of the curve. Secure Payment Confirmation (SPC), a W3C specification built on top of WebAuthn, lets a cardholder approve a payment using a fingerprint, facial recognition or security key directly inside the browser, without a one-time password or a redirect to a separate app. GPayments confirms SPC support for ActiveAccess directly on its issuing solutions page, describing biometric authentication that lets cardholders ‘approve transactions instantly using fingerprint or facial recognition.’ This article explains what SPC support for issuers actually means technically, why it matters ahead of broader FIDO-based adoption, and what issuers should check before assuming a vendor’s ACS is ready for it.
What Secure Payment Confirmation Is, and Why It Sits Inside EMV 3DS
Secure Payment Confirmation is a W3C API that extends WebAuthn – the same standard behind passkeys and platform biometric sign-in – with payment-specific data, so a signed authentication assertion can carry transaction amount, merchant and currency details as well as proof that a registered authenticator (a fingerprint sensor, facial recognition camera or security key) approved it. EMVCo incorporated support for WebAuthn-based authentication methods, including SPC, into EMV 3DS from protocol version 2.3.1, published in September 2022, positioning SPC as a native option within the 3DS challenge flow rather than a separate authentication channel bolted on afterwards.
In practice, this means an issuer’s ACS can present a cardholder with a biometric prompt inside the existing 3DS challenge, rather than falling back to an SMS one-time password, when the cardholder’s device and browser support WebAuthn/SPC. The benefit is speed and lower abandonment: biometric confirmation typically completes in seconds and does not depend on SMS delivery, which is itself a growing fraud vector through SIM-swap attacks. Because the assertion is cryptographically bound to the specific transaction, it is also inherently more resistant to phishing than a one-time code a cardholder could be tricked into reading out or re-entering on a fake page.
ActiveAccess’s SPC Support: What GPayments Confirms Today
GPayments states directly on its issuing solutions page that ActiveAccess delivers ‘seamless biometric authentication within browsers through Secure Payment Confirmation (SPC),’ allowing cardholders to ‘approve transactions instantly using fingerprint or facial recognition, combining speed, convenience, and compliance with industry standards.’ This is a specific, checkable product claim rather than a roadmap statement, and it sits alongside ActiveAccess’s existing EMVCo Approved status and its certifications across Visa Secure, Mastercard Identity Check, Amex SafeKey and JCB J/Secure.
For an issuer evaluating ACS vendors on passwordless readiness specifically, the useful question is not ‘do you support WebAuthn in general’ but ‘does your ACS support SPC inside the EMV 3DS challenge flow today, and which card schemes have you certified it against.’ GPayments’ issuing page is a direct, citable answer to that question, a meaningfully different position from a vendor that describes biometric authentication only as a planned capability. Issuers should treat this distinction as material during procurement, since a certified, in-production capability can be scoped into a delivery timeline in a way that a roadmap intention cannot.
How SPC Fits Into the Broader FIDO/Passwordless Roadmap
SPC is one expression of a broader industry shift toward FIDO2/WebAuthn-based authentication, which is also driving adoption of passkeys for account login across banking and ecommerce more generally. For issuers, the strategic value of SPC support inside the ACS is that it reuses authenticators cardholders are already registering for other purposes – a passkey set up for mobile banking login can, in principle, also satisfy a payment challenge – rather than requiring a separate enrolment process specific to 3DS. This matters ahead of any formal scheme mandate: card schemes have historically added new authentication methods to EMV 3DS well before making them compulsory, and issuers whose ACS already supports SPC are positioned to route eligible transactions through it as soon as merchant-side and browser support reach critical mass, rather than needing an ACS upgrade at the point a mandate lands. This is a materially different position from waiting until a mandate is confirmed and then starting a vendor selection and certification process from scratch, which can take considerably longer than the transition period a scheme typically allows.
Where the ACS Market Stands on SPC Support
SPC support is not yet universal across ACS solutions, and issuers should verify vendor capabilities directly rather than assuming feature parity across the market. Support for standards such as WebAuthn and Secure Payment Confirmation (SPC) can vary depending on the ACS implementation, EMV 3DS version and vendor roadmap.
GPayments confirms SPC support for ActiveAccess, providing issuers with the capability to support emerging FIDO-based authentication experiences. When evaluating an ACS, issuers should request clear evidence of SPC support, including relevant certifications, technical documentation and implementation requirements. The absence of publicly available information does not necessarily indicate that a solution lacks the capability, but it reinforces the importance of validating functionality directly with the provider rather than relying on general claims around FIDO or standards alignment.
What Issuers Should Do Now to Prepare
Issuers do not need to wait for a card scheme mandate to start preparing. Confirm with your current or prospective ACS vendor, in writing, whether SPC is certified and in production today rather than on a roadmap; ask which card schemes it has been certified against for SPC specifically; and assess whether your mobile banking app’s existing biometric enrolment could be reused for SPC-based payment confirmation, which shapes the cardholder education required at launch. Because SPC operates inside the browser and depends on device and browser support, issuers should also plan a graceful fallback to existing challenge methods for cardholders on unsupported devices, so passwordless adoption is additive rather than a hard cutover. Finally, loop in the fraud and risk team early: SPC changes the authentication event itself, and risk models that were tuned around OTP-based challenges may need to be revisited once biometric confirmation starts carrying a meaningful share of traffic.
|
GPayments tip: Ask any ACS vendor for their EMV 3DS 2.3.1 certification date and confirm separately whether SPC specifically – not just WebAuthn broadly – is part of that certified scope. The two are related but not identical claims. |
Reference: W3C — Secure Payment Confirmation specification
Frequently Asked Questions
What is Secure Payment Confirmation (SPC) and how does it relate to 3D Secure?
SPC is a W3C specification built on top of WebAuthn that lets a cardholder approve a payment using a fingerprint, facial recognition or security key, with the signed assertion carrying payment-specific data such as amount and merchant. EMVCo incorporated SPC as a supported authentication method inside EMV 3DS from protocol version 2.3.1, published in September 2022.
How can an issuer check whether an ACS vendor genuinely supports SPC today?
Ask the vendor directly whether SPC is certified and running in production, which card schemes it has been certified against for SPC specifically, and request a demonstration inside a live 3DS challenge flow. Public product pages that describe biometric authentication via SPC explicitly, such as GPayments’ issuing solutions page, are a more reliable signal than general FIDO or passwordless marketing language.
Is SPC support relevant for issuers that don’t currently see high false-decline rates?
Yes – SPC reduces abandonment and false declines by replacing SMS one-time passwords with faster, device-native biometric confirmation, but its relevance extends beyond current friction metrics. Because SIM-swap fraud targets SMS OTP specifically, SPC also closes a fraud vector, and having certified support in place means an issuer can adopt it as soon as scheme incentives or mandates favour it.
Conclusion
Passwordless authentication inside 3D Secure is no longer speculative – EMVCo built support for it into the protocol from version 2.3.1, and a handful of ACS vendors, GPayments among them, have confirmed production support for SPC rather than treating it as a future roadmap item. For issuers, the strategic value of confirming SPC support now is optionality: being ready to route eligible transactions through biometric confirmation as soon as browser and merchant-side support reach scale, without needing an ACS upgrade at the point a scheme mandate arrives. GPayments confirms SPC support for ActiveAccess directly, alongside its existing EMVCo Approved status and scheme certifications.
|
Talk to a GPayments Solutions Architect Curious how SPC works inside a live 3DS challenge? Request a demo of ActiveAccess’s Secure Payment Confirmation flow or talk to a GPayments solutions architect. Contact sales@gpayments.com or visit gpayments.com/contact. |
