3-D Secure is an additional verification protocol that confirms the person paying is the actual cardholder. The issuing bank asks for confirmation — an SMS code, an app login or biometrics — and only then is the transaction sent for capture.
How it works
- The customer enters card details in the payment form.
- The request goes to the bank that issued the card.
- The bank decides whether extra verification is needed.
- If it is, the customer confirms with a code, in their app, or with biometrics.
- Once confirmed, the payment continues on its normal path.
What version 2.0 changed
The first version almost always showed the customer a code entry page — and some buyers dropped off there. In 3-D Secure 2.0 the bank receives far more data about the transaction and the device, and in many cases approves the payment with no action from the customer at all. That path is called frictionless.
For a business it means fraud protection no longer equals lost conversion.
Why it matters to the merchant
- Liability shift. When a transaction is authenticated through 3-D Secure, liability for a fraudulent payment moves to the issuing bank in a number of cases instead of staying with the merchant.
- Fewer disputes. It is harder for a customer to claim they did not make the transaction.
- Scheme requirements. For many business categories the check is mandatory.
What 3-D Secure does not solve
The protocol confirms who is paying, not what was sold. If a customer disputes a payment over non-delivery or a mismatch with the description, 3-D Secure will not help — that is a matter of documentation and clear terms of sale.
MulenPay applies 3-D Secure 2.0 together with round-the-clock anti-fraud; see bank card payments.