{"id":2946,"date":"2026-08-13T12:02:31","date_gmt":"2026-08-13T02:02:31","guid":{"rendered":"https:\/\/www.gpayments.com\/blog\/?p=2946"},"modified":"2026-08-18T12:03:55","modified_gmt":"2026-08-18T02:03:55","slug":"activeaccess-modern-acs-3d-secure","status":"publish","type":"post","link":"https:\/\/www.gpayments.com\/blog\/company-announcements\/activeaccess-modern-acs-3d-secure\/","title":{"rendered":"ActiveAccess Has Evolved for the Next Era of 3D Secure"},"content":{"rendered":"\n<p class=\"PDq2pG_selectionAnchorContainer\" style=\"text-align: left;\" data-start=\"630\" data-end=\"700\">3D Secure has changed considerably since its earliest implementations.<\/p>\n<p style=\"text-align: left;\" data-start=\"702\" data-end=\"968\">Authentication requirements have evolved. Cardholder expectations have changed. Issuers are managing increasingly complex fraud and payment environments, while technology teams are under pressure to modernise infrastructure and reduce dependency on legacy platforms.<\/p>\n<p style=\"text-align: left;\" data-start=\"970\" data-end=\"1035\">An Access Control Server needs to evolve with those requirements.<\/p>\n<p style=\"text-align: left;\" data-start=\"1037\" data-end=\"1170\">That is why we have continued to develop <strong data-start=\"1078\" data-end=\"1094\">ActiveAccess<\/strong>, GPayments\u2019 Access Control Server for issuer-side 3D Secure authentication.<\/p>\n<p style=\"text-align: left;\" data-start=\"1172\" data-end=\"1377\">The latest ActiveAccess brings together support for evolving EMV 3DS requirements, modern technology architecture, greater operational control and improved visibility across the authentication environment.<\/p>\n<h2 style=\"text-align: left;\" data-section-id=\"18njirz\" data-start=\"1379\" data-end=\"1411\">3D Secure continues to evolve<\/h2>\n<p style=\"text-align: left;\" data-start=\"1413\" data-end=\"1506\">The role of the ACS has expanded beyond simply supporting a 3D Secure authentication request.<\/p>\n<p style=\"text-align: left;\" data-start=\"1508\" data-end=\"1751\">Issuers increasingly need to manage multiple authentication approaches, determine when additional cardholder verification is appropriate, understand authentication outcomes and maintain experiences that balance security with customer friction.<\/p>\n<p style=\"text-align: left;\" data-start=\"1753\" data-end=\"1843\">At the same time, EMV 3DS specifications and card scheme requirements continue to develop.<\/p>\n<p style=\"text-align: left;\" data-start=\"1845\" data-end=\"2055\">ActiveAccess is designed to support the latest applicable EMV 3DS 2.3.x requirements alongside existing 2.1 and 2.2 environments, giving issuers a platform built with continued authentication evolution in mind.<\/p>\n<h2 style=\"text-align: left;\" data-section-id=\"pt47rm\" data-start=\"2057\" data-end=\"2112\">Modernising the infrastructure behind authentication<\/h2>\n<p style=\"text-align: left;\" data-start=\"2114\" data-end=\"2239\">Payment authentication may happen in seconds, but the infrastructure behind it needs to operate reliably at enterprise scale.<\/p>\n<p style=\"text-align: left;\" data-start=\"2241\" data-end=\"2433\">Older ACS environments can depend on technology stacks that are increasingly difficult to maintain, integrate into modern delivery environments or align with current infrastructure strategies.<\/p>\n<p style=\"text-align: left;\" data-start=\"2435\" data-end=\"2487\">ActiveAccess has been modernised from the ground up.<\/p>\n<p style=\"text-align: left;\" data-start=\"2489\" data-end=\"2667\">The platform is built on <strong data-start=\"2514\" data-end=\"2525\">Java 21<\/strong> and supports a simplified application architecture, container-ready deployment and flexible database options including PostgreSQL and Oracle.<\/p>\n<p style=\"text-align: left;\" data-start=\"2669\" data-end=\"2806\">For technology teams, this means an ACS architecture that can fit more naturally into contemporary infrastructure and CI\/CD environments.<\/p>\n<p style=\"text-align: left;\" data-start=\"2808\" data-end=\"3031\">Modernising the ACS is not simply a technology exercise. Reducing infrastructure complexity can also make it easier for organisations to operate and maintain a critical component of their payment authentication environment.<\/p>\n<h2 style=\"text-align: left;\" data-section-id=\"3gpuu\" data-start=\"3033\" data-end=\"3079\">Giving authentication teams greater control<\/h2>\n<p style=\"text-align: left;\" data-start=\"3081\" data-end=\"3151\">The technology underneath ActiveAccess is only one part of the change.<\/p>\n<p style=\"text-align: left;\" data-start=\"3153\" data-end=\"3234\">A major focus has also been placed on how teams manage authentication day to day.<\/p>\n<p style=\"text-align: left;\" data-start=\"3236\" data-end=\"3405\">ActiveAccess introduces a modern administration experience designed to move more configuration and management into the hands of the teams responsible for authentication.<\/p>\n<p style=\"text-align: left;\" data-start=\"3407\" data-end=\"3542\">For example, challenge experiences can be configured through a structured interface rather than relying solely on file-based processes.<\/p>\n<p style=\"text-align: left;\" data-start=\"3544\" data-end=\"3733\">Teams can manage elements such as challenge messaging, authentication templates and issuer-specific experiences while previewing how those changes will appear across different screen sizes.<\/p>\n<p style=\"text-align: left;\" data-start=\"3735\" data-end=\"3812\">Authentication page flows can also be configured around requirements such as:<\/p>\n<ul style=\"text-align: left;\" data-start=\"3814\" data-end=\"3876\">\n<li data-section-id=\"12vwoar\" data-start=\"3814\" data-end=\"3822\">issuer<\/li>\n<li data-section-id=\"g31j6x\" data-start=\"3823\" data-end=\"3836\">card scheme<\/li>\n<li data-section-id=\"1tjjqon\" data-start=\"3837\" data-end=\"3860\">authentication method<\/li>\n<li data-section-id=\"cr52ke\" data-start=\"3861\" data-end=\"3876\">specific BINs<\/li>\n<\/ul>\n<p style=\"text-align: left;\" data-start=\"3878\" data-end=\"3987\">This gives organisations greater flexibility over how authentication experiences are constructed and managed.<\/p>\n<h2 style=\"text-align: left;\" data-section-id=\"1myyrs0\" data-start=\"3989\" data-end=\"4039\">Greater visibility into authentication activity<\/h2>\n<p style=\"text-align: left;\" data-start=\"4041\" data-end=\"4150\">Understanding what is happening across the authentication environment is critical to managing it effectively.<\/p>\n<p style=\"text-align: left;\" data-start=\"4152\" data-end=\"4259\">ActiveAccess provides interactive dashboard capabilities that give teams visibility across areas including:<\/p>\n<ul style=\"text-align: left;\" data-start=\"4261\" data-end=\"4494\">\n<li data-section-id=\"fdoawn\" data-start=\"4261\" data-end=\"4282\">transaction volumes<\/li>\n<li data-section-id=\"1widjax\" data-start=\"4283\" data-end=\"4314\">authentication success ratios<\/li>\n<li data-section-id=\"11nvyff\" data-start=\"4315\" data-end=\"4358\">challenge and frictionless authentication<\/li>\n<li data-section-id=\"7h0l2l\" data-start=\"4359\" data-end=\"4385\">decoupled authentication<\/li>\n<li data-section-id=\"ca1oc3\" data-start=\"4386\" data-end=\"4403\">decline reasons<\/li>\n<li data-section-id=\"h35w4m\" data-start=\"4404\" data-end=\"4433\">errors and error categories<\/li>\n<li data-section-id=\"1xgmyvu\" data-start=\"4434\" data-end=\"4465\">browser, app and 3RI channels<\/li>\n<li data-section-id=\"5up7uv\" data-start=\"4466\" data-end=\"4494\">individual issuer activity<\/li>\n<\/ul>\n<p style=\"text-align: left;\" data-start=\"4496\" data-end=\"4654\">Users can explore activity across different time periods and issuer environments, providing a clearer operational view of how authentication is being handled.<\/p>\n<p style=\"text-align: left;\" data-start=\"4656\" data-end=\"4813\">The objective is simple: make authentication activity easier to understand and give teams better information when investigating trends or operational issues.<\/p>\n<h2 style=\"text-align: left;\" data-section-id=\"igbgzm\" data-start=\"4815\" data-end=\"4863\">Supporting flexible authentication strategies<\/h2>\n<p style=\"text-align: left;\" data-start=\"4865\" data-end=\"4948\">There is no single authentication method that is appropriate for every transaction.<\/p>\n<p style=\"text-align: left;\" data-start=\"4950\" data-end=\"5088\">ActiveAccess supports a range of authentication approaches designed to give issuers greater flexibility over how cardholders are verified.<\/p>\n<p style=\"text-align: left;\" data-start=\"5090\" data-end=\"5271\">These include risk-based authentication, OTP, out-of-band authentication, decoupled authentication and modern authentication capabilities aligned with evolving EMV 3DS requirements.<\/p>\n<p style=\"text-align: left;\" data-start=\"5273\" data-end=\"5490\">Configurable risk logic can also be used to help determine whether transactions proceed frictionlessly, require additional cardholder authentication or should be rejected based on the issuer&#8217;s authentication strategy.<\/p>\n<p style=\"text-align: left;\" data-start=\"5492\" data-end=\"5593\">As new authentication approaches continue to emerge, this flexibility becomes increasingly important.<\/p>\n<h2 style=\"text-align: left;\" data-section-id=\"xlc9r6\" data-start=\"5595\" data-end=\"5623\">Built for what comes next<\/h2>\n<p style=\"text-align: left;\" data-start=\"5625\" data-end=\"5715\">ActiveAccess has evolved because the environment around issuer authentication has evolved.<\/p>\n<p style=\"text-align: left;\" data-start=\"5717\" data-end=\"5804\">For GPayments, supporting the latest specifications is only one part of that evolution.<\/p>\n<p style=\"text-align: left;\" data-start=\"5806\" data-end=\"6034\">A modern ACS also needs to consider the infrastructure supporting authentication, the teams operating it, the experience presented to cardholders and the information available when authentication decisions need to be understood.<\/p>\n<p style=\"text-align: left;\" data-start=\"6036\" data-end=\"6184\">ActiveAccess brings those requirements together in a modern platform designed for issuer authentication today and as 3D Secure continues to develop.<\/p>\n<h3 style=\"text-align: left;\" data-section-id=\"ctsa09\" data-start=\"6186\" data-end=\"6237\">Modern authentication starts with a modern ACS.<\/h3>\n<p style=\"text-align: left;\" data-start=\"6239\" data-end=\"6287\"><a href=\"_wp_link_placeholder\" data-wplink-edit=\"true\"><strong data-start=\"6239\" data-end=\"6263\">Explore ActiveAccess<\/strong><\/a>\u00a0<\/p>\n<p style=\"text-align: left;\" data-start=\"6289\" data-end=\"6330\"><a href=\"https:\/\/www.gpayments.com\/contact\/\"><strong data-start=\"6289\" data-end=\"6307\">Request a Demo<\/strong><\/a><code data-start=\"6310\" data-end=\"6330\"><\/code><\/p>\n\n\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>3D Secure has changed considerably since its earliest implementations. Authentication requirements have evolved. Cardholder expectations have changed. Issuers are managing increasingly complex fraud and payment environments, while technology teams are under pressure to modernise infrastructure and reduce dependency on legacy platforms. An Access Control Server needs to evolve with those requirements. That is why we [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":2964,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[5],"tags":[],"class_list":["post-2946","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-company-announcements"],"aioseo_notices":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts\/2946","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/comments?post=2946"}],"version-history":[{"count":7,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts\/2946\/revisions"}],"predecessor-version":[{"id":2963,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts\/2946\/revisions\/2963"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/media\/2964"}],"wp:attachment":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/media?parent=2946"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/categories?post=2946"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/tags?post=2946"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}