How an ACS can check 3DS app provenance

An app-based authentication request tells the issuer a great deal about the device. It also carries 3DS app provenance, meaning information about the app the transaction came from, and this part goes almost entirely unused. Specifically, it…

The 3DS challenge iframe settings that are now requirements rather than recommendations

Most merchants set up their challenge iframe once, during the original 3DS integration, and have not looked at it since. That was defensible when the guidance was advisory. It is not any more. EMVCo released the EMV 3D Secure Browser Flow…

What happens to 3DS when JavaScript is disabled or unavailable

A small proportion of your browser traffic runs with JavaScript disabled, and 3DS behaves differently there. Privacy configurations, corporate builds, assistive setups, older embedded browsers, and a certain amount of automated traffic you…

The decisions EMV 3DS deliberately leaves out of scope

A standard is usually read as an answer sheet. If two products both implement it, the reasoning goes, they behave the same way, and the remaining differences are commercial. EMV 3DS does not work like that, and the places where it does not…

EMV 3DS Version Management: From Protocol Versions to Device Information

Teams new to EMV 3DS usually assume there is a specification, that it has a version number, and that being on that version means being current. All three assumptions are wrong in ways that cause real planning failures. There is a family of…

The field-level rules behind 3DS requestor data quality

Issuers can only assess the risk data they actually receive. That sentence is uncontroversial and almost never acted on, because the data quality problem in 3DS is not a strategic one. It is a hundred small encoding and population decisions…

What a soft decline is and how to respond to one with 3DS

A merchant sends a card transaction straight to authorisation without authenticating first. The issuer declines it, but not because anything is wrong with the card. The decline means something closer to: authenticate the cardholder and come…

How EMV 3DS can carry age and identity verification

Age verification in 3DS is possible, and almost nobody uses it. If you sell alcohol, run a gambling platform, or operate anything a regulator expects you to keep minors out of, you already have an age verification problem and an expensive answer…

How the SDK and ACS interact during an app-based 3DS challenge

An app-based 3DS challenge looks simple from the outside. The cardholder taps, a screen appears, they enter a code, the payment completes. Underneath, the screen they see is the product of a negotiation that runs across four separate messages,…