SolCard Logo

3D Secure Explained: Why Your Crypto Card Asks for a Code Before It Charges You

ST
SolCard Team
3d secure crypto card

When an online checkout pauses and asks for a code before it charges your card, you are looking at 3D Secure (3DS): a check, defined in the EMV 3-D Secure standard, in which the store passes details about the purchase to the bank or program that issued your card, and that issuer decides whether to approve it silently or ask you to prove it is really you. EMVCo, the body that maintains the standard, describes it as a way to "prevent card-not-present (CNP) fraud" by letting merchant and issuer "authenticate the consumer and approve the transaction," per EMVCo. Most of the time you never notice it. When you do, it is usually a one-time code.

Most guides to 3D Secure are written for merchants. This one is for the person holding the card.

What 3D Secure actually is

3D Secure is an authentication step that runs before a card-not-present purchase, such as an online order or an in-app payment, is sent for authorization.

The version in use today is EMV 3DS, the 2.x generation. EMVCo notes that "v2.1 supports SCA" (strong customer authentication, covered below) and recommends v2.2 or higher "to access the optimum functionality," per EMVCo. Stripe tells its merchants that "major card brands no longer support 3D Secure 1," per Stripe.

Each network runs its own program on top of the standard:

  • Visa Secure. "Visa Secure (previously known as Verified by Visa) is Visa's program that governs Visa transactions using the 3-D Secure standard," per Visa.
  • Mastercard Identity Check. A "global authentication program that builds upon the existing Mastercard SecureCode program and uses the current EMV 3-D Secure protocol," per the Mastercard Identity Check Program Guide.

The names differ; the mechanism is the same. What 3DS2 added is data: the merchant sends "information about the transaction, payment method and device," per EMVCo, so the issuer can approve low-risk purchases without interrupting you.

Frictionless flow vs. challenge flow

Every 3DS check ends in one of two paths.

Frictionless flowChallenge flow
What you seeNothing extra, or a brief loading screenA prompt to verify: usually a one-time code, sometimes a link, biometric, or banking-app approval
What happensThe issuer judges the purchase low-risk from the data it received and authenticates in the backgroundThe issuer wants more proof before it authenticates
Who decidesThe issuer's access control server (ACS)The issuer's access control server (ACS)
Visa's description"Low-risk transactions are authenticated in the background, with no extra steps for the customer""The issuer prompts the customer for verification via a one-time password or biometric confirmation"

Both quotes are from Visa. Mastercard describes the same split: in a frictionless flow the transaction is "authenticated by way of risk-based decisioning, and no additional interaction is required," while a challenge flow means "the cardholder must perform additional steps such as entering a one-time pass code," per the Mastercard Identity Check Program Guide.

Who decides whether you get a code

  1. The merchant (through its payment processor, the acquirer) starts the check. It sends the authentication request with the purchase details. A merchant can ask for 3DS on a single risky order or on every order, and it can say it would prefer a challenge.
  2. The network's directory server routes it. For Mastercard, the directory server also "adds risk scores and data needed to evaluate the risk of the transaction," per the Mastercard Identity Check Program Guide.
  3. The issuer's access control server makes the call. In Visa's words, "the issuer uses an access control server (ACS) to assess transaction risk and authenticate the cardholder," per Visa.

So a merchant can ask for a challenge, but it cannot force one. Stripe says so directly: it "can't guarantee your preference because the issuer determines the ultimate authentication flow," per Stripe.

Authentication is also not the same as approval. 3DS confirms it is you. After that, the purchase still goes through the normal authorization step, where the issuer checks the card and its balance, before any money moves. For how the stages after that work, see how card networks settle.

Why merchants trigger 3D Secure

Merchants accept the extra checkout step for two reasons.

Regulation: strong customer authentication in Europe and the UK

In the European Economic Area, the revised Payment Services Directive (PSD2) requires strong customer authentication when a payer "initiates an electronic payment transaction," per Directive (EU) 2015/2366, Article 97. Strong customer authentication means using "two or more elements" from three categories: something you know, something you have, and something you are.

The detailed rules sit in Commission Delegated Regulation (EU) 2018/389, and two of them explain what you see during a challenge:

  • The code is single-use. An authentication code "shall be only accepted once" (Article 4).
  • The code is tied to the purchase. You must be "made aware of the amount of the payment transaction and of the payee," and the code must be "specific to the amount" and payee you agreed to (Article 5). That is why a well-built challenge screen shows the merchant and the amount.

The same regulation lists exemptions, which is why not every European purchase asks for a code. Remote payments that do not exceed EUR 30 can be exempt, within cumulative limits (Article 16), and a provider running real-time transaction risk analysis can skip authentication for low-risk payments (Article 18).

In the UK, the Financial Conduct Authority states that SCA applies when a payer "initiates an electronic payment transaction."

For card payments, EMV 3DS is how those rules are met in practice, which is why EMVCo notes that v2.1 "supports SCA."

Fraud liability: who pays when a purchase turns out to be fraud

The second reason is commercial. Visa says 3DS helps "shift liability for authenticated or attempted-authentication transactions" to the issuer, per Visa. Mastercard says that after successful authentication through Identity Check, "a merchant realizes the full benefits of liability shift," per the Mastercard Identity Check Program Guide.

It is not universal: Stripe's merchant docs note that liability shift does not always apply and that Visa excludes some business categories, per Stripe. This liability arrangement is between merchant and issuer. It does not describe your own protections as a cardholder, which depend on your card program's terms.

What you see as a cardholder

A frictionless check shows you nothing, or a spinner for a moment. A challenge usually looks like this:

  1. A window from your card issuer appears over the checkout, or you are redirected to it. Merchants cannot restyle it; "the bank that issued the card controls the fonts and colors," per Stripe. Visa's guidelines require the issuer's logo in the upper left and the Visa logo in the upper right, per Visa.
  2. It shows the purchase details. Visa's sample screen reads "To verify payment to Electronic Store for โ‚ฌ259.95, Digital Bank will send you a one-time code," per Visa.
  3. A code arrives by text message or email, depending on what the issuer offers; Visa notes "issuers can choose which delivery channels to make available," per Visa.
  4. You enter it in that window, and checkout continues to the normal authorization.

Why 3DS matters more for prepaid crypto cards

For a prepaid card, including a crypto card, 3DS can decide whether the card works at a given merchant at all.

A merchant's fraud rules can do two different things with 3DS:

  • Request it. The merchant asks for authentication. If the card does not support 3DS, some processors let the payment continue without it. Stripe's docs say that if 3DS is not available for a card, "the payment proceeds normally," per Stripe.
  • Require it. The merchant pairs the request with a block rule, so any payment that did not go through 3DS is refused. Stripe's Radar documentation includes example rules that block payments without a 3DS flow, per Stripe.

Some merchants choose the second option, at least for some orders. At those merchants, a card whose program is not enrolled in 3DS, or whose challenge the cardholder cannot complete, has no path to checkout. And even when a card is enrolled, a failed challenge stops the purchase: on a failed authentication, Stripe tells merchants "you need to try a different payment method, or you can retry 3DS," per Stripe.

So two questions matter for any prepaid card you use online: does the program support 3D Secure, and can you actually receive its challenge codes? A code sent to an inbox you no longer check makes a supported card fail the challenge.

For a wider look at where virtual cards do and do not fit, see spending crypto with virtual cards.

How SolCard delivers 3D Secure codes

When a merchant's 3DS check on a SolCard card ends in a challenge, the card provider notifies SolCard and SolCard sends the challenge to the email address on your SolCard account, in an email with the subject "Transaction Confirmation." Depending on what the provider sends, the email contains either a numeric confirmation code or a confirmation link. When the provider includes them, the email also shows the merchant name, the amount, and how long the code stays valid, which lets you check it against the purchase you are making.

Two things we will not promise: that the email always arrives, or that it arrives instantly. Email delivery depends on your mail provider accepting the message, and challenges expire. If a code does not show up, check spam and filtered folders, make sure your account email is a real inbox you can open, and restart the checkout for a fresh code rather than waiting on an expired one.

New to how a prepaid crypto card works in general? Start with what is a crypto debit card.

Practical tips for handling 3DS codes

  • Keep your account email reachable. This is where the codes go. If you set up your account with an email forwarding or relay address, confirm that mail actually reaches you, and update the account email if you are moving away from an old inbox.
  • Never share a code. A 3DS code exists to prove you approved a specific purchase. Nobody legitimate needs you to read it out, forward it, or paste it anywhere other than the issuer's verification window during your own checkout. That includes callers or chats claiming to be support.
  • Read the merchant and amount before entering the code, when they are shown. Because the code is tied to a specific purchase, check that the email matches what is in your cart. If it does not, do not enter it.
  • Treat an unexpected code as a warning. A code you did not ask for means someone may be trying to use your card details at a checkout right now. Do not enter or share it. Review your recent card activity and contact support if anything looks wrong.
  • Be wary of links. Some challenges arrive as a link. Only open one while you are actively checking out.

Our crypto security basics for card users covers the wider set of habits, from authenticator apps to avoiding SMS-based two-factor authentication where you can.

FAQ

Why does my card ask for a verification code when I shop online?

The merchant started a 3D Secure check, and your card issuer's access control server decided it wanted proof that you are the cardholder before authenticating the purchase. Visa describes this as the issuer prompting "for verification via a one-time password or biometric confirmation" when it detects a potentially high-risk transaction, per Visa. Many purchases skip the code entirely through the frictionless flow.

What is a 3DS OTP?

A 3DS OTP is the one-time passcode used in a 3D Secure challenge. It is sent by your card issuer or card program, typically by text or email, and entered in the verification window during checkout. Under the EU rules for strong customer authentication, such a code "shall be only accepted once" and is tied to the amount and payee, per Regulation (EU) 2018/389.

Can a merchant force me to enter a code?

A merchant can request 3DS and say it prefers a challenge, but the issuer determines the actual flow, per Stripe. What a merchant can do is refuse payments that did not go through 3DS, which is why some checkouts will not accept a card that cannot complete it.

Where does SolCard send 3D Secure codes?

To the email address on your SolCard account, in an email titled "Transaction Confirmation" that contains either a code or a confirmation link, plus the merchant, amount, and expiry when the card provider supplies them. Delivery depends on your mail provider, so keep that inbox reachable and check spam if a code is missing.

What should I do if I get a code I did not request?

Do not enter it and do not share it with anyone who contacts you about it. An unexpected code suggests someone may be trying to use your card details at a checkout. Review your recent transactions and contact support if anything looks wrong.

The bottom line

3D Secure is the step where an online store asks your card issuer to confirm it is really you. The merchant starts it, the issuer decides whether you see a code, and SCA rules plus liability shift give merchants reasons to use it. Merchants that require 3DS on every card only work with cards that can complete the challenge, and that depends on the code reaching you. On SolCard, it goes to your account email: keep that inbox reachable, and never share what lands in it.

If you want a card that supports these checks for online spending, you can see how SolCard works.

Sources

More in Guides
Globe
SolCard

150M+ places.
One card.

Instantly create and top-up your SolCard with SOL and enjoy hassle-free shopping IRL and online.