
The decisions EMV 3DS deliberately leaves out of scope
A standard is usually read as an answer sheet. If two products both implement it, the reasoning goes, they behave the same way, and the remaining differences are commercial.
EMV 3DS does not work like that, and the places where it does not…

EMV 3DS Version Management: From Protocol Versions to Device Information
Teams new to EMV 3DS usually assume there is a specification, that it has a version number, and that being on that version means being current. All three assumptions are wrong in ways that cause real planning failures.
There is a family of…

The field-level rules behind 3DS requestor data quality
Issuers can only assess the risk data they actually receive. That sentence is uncontroversial and almost never acted on, because the data quality problem in 3DS is not a strategic one. It is a hundred small encoding and population decisions…

What a soft decline is and how to respond to one with 3DS
A merchant sends a card transaction straight to authorisation without authenticating first. The issuer declines it, but not because anything is wrong with the card. The decline means something closer to: authenticate the cardholder and come…

How EMV 3DS can carry age and identity verification
Age verification in 3DS is possible, and almost nobody uses it. If you sell alcohol, run a gambling platform, or operate anything a regulator expects you to keep minors out of, you already have an age verification problem and an expensive answer…

How the SDK and ACS interact during an app-based 3DS challenge
An app-based 3DS challenge looks simple from the outside. The cardholder taps, a screen appears, they enter a code, the payment completes. Underneath, the screen they see is the product of a negotiation that runs across four separate messages,…

What Happens After the First Authentication? Understanding Merchant-Initiated Authentication
A subscription has two authentication problems, not one, and they are solved by different parts of the protocol.
The first is straightforward. The cardholder is present, signing up, and can be authenticated the way any other purchase is authenticated.…

How Card Range Data Shapes 3DS Server Reliability
Every authentication request your 3DS Server builds depends on information it obtained earlier, from a different source, about a card range it may not have seen recently. That information is card range data, and it is one of the quieter dependencies…

3DS Out-of-Band Authentication: What Happens When the App Cannot Open
Out-of-band authentication in a native app should be the smoothest experience in the whole protocol. The cardholder is already on their phone, the banking app is already installed, and the approval is one biometric prompt away.
When it works,…

Understanding the Directory Server’s Role and Limits in EMV 3DS
Diagrams of EMV 3D Secure usually show three boxes and two arrows. The merchant's 3DS Server on one side, the issuer's Access Control Server on the other, and something in the middle labelled Directory Server that everyone nods at and nobody…
