Payments Glossary · Technology & Rails

3-D Secure

Also called 3DS, EMV 3DS, Verified by Visa, Mastercard Identity Check, SCA

An authentication step on online payments that shifts fraud chargeback liability from you to the issuing bank.

What it is

3-D Secure is an authentication protocol for card-not-present transactions. The merchant sends transaction and device data to the issuer during checkout; the issuer either approves silently based on risk signals (frictionless flow) or challenges the cardholder with a one-time code or app confirmation. Modern EMV 3DS is dramatically better than the original Verified by Visa era — most transactions pass frictionlessly with no customer-visible step at all. The commercial point is liability. In a normal card-not-present transaction, fraud chargebacks are the merchant's problem. On a successfully authenticated 3DS transaction, that liability generally shifts to the issuer. You still have to fight non-fraud disputes — item not received, not as described — but the fraud category moves off your books. 3DS also tends to improve interchange qualification on some card types, and it's standard in modern gateways. NMI, for example, offers 3DS as part of its eCommerce integrations including its Shopify integration.

Why it matters to your business

If you sell online or take card-not-present payments of any size, fraud chargebacks land on you by default, and small merchants lost an estimated 3.4% of revenue to fraud in 2025 at a true cost of $4.61 per dollar of fraud. 3DS is the only mechanism that moves that liability back to the bank. And you don't have to run it on everything. Most gateways let you set rules — trigger 3DS above a dollar threshold, on international cards, or on first-time customers. That's the configuration most merchants never do, and it captures most of the protection with almost none of the friction.

Where it gets contested

The historic complaint about 3-D Secure is conversion loss, and it was earned. The first generation added a clunky redirect and a password nobody remembered, and merchants measured real cart abandonment. That reputation persists a decade after the technology changed, and many merchants still refuse 3DS on the basis of an experience that no longer exists. EMV 3DS's frictionless flow resolved most of it — the majority of transactions authenticate on data alone with no customer interaction. But challenges do still fire, particularly on higher-risk transactions, and every challenge is a chance for a customer to bail. Merchants running high-ticket or unusual-pattern transactions will see more friction than average. The honest framing is that 3DS is a trade: some conversion friction in exchange for fraud liability shift. The right answer depends entirely on your fraud rate and average ticket. A merchant with negligible fraud and a $30 ticket may be better off without it. A merchant with a $2,000 ticket and any meaningful chargeback history is usually better off with it, and can configure it to trigger only above a threshold.

How to check it yourself

Ask your gateway whether 3-D Secure is available on your account and whether you can configure it by rule rather than all-or-nothing. Then look at your chargeback report: if fraud-coded chargebacks are a meaningful share, set a threshold rule this week.

Receipts

Claims above that are checkable, with where to check them. Published so you do not have to take anyone's word for it.

  • 3DS is offered as part of gateway eCommerce integrations including Shopify

    nmi.com ↗
  • Small merchants lost 3.4% of revenue to fraud in 2025, mid-market 4.5% (up 40% YoY), with a true cost of $4.61 per $1 of fraud, while only 37% of merchants use vendor-provided AI/ML fraud tools

    nmi.com ↗
  • EMV specifications including 3-D Secure are governed by EMVCo

    emvco.com ↗