What is 3D Secure? How does it protect your online payments?
Every time you confirm an online purchase from your phone, whether by SMS, a notification from your bank’s app or fingerprint authentication, you are going through a protocol called 3D Secure. It is the standard required by European regulation to authenticate the real cardholder in every online transaction, and in recent years it has become the main barrier against online payment fraud.
What is the 3D Secure protocol?
3D Secure (Three-Domain Secure, or “3 Secure Domains”) is a security protocol that verifies the identity of a cardholder during an online purchase. Its purpose is to make sure that the person entering the card details is really the owner, and not a third party who obtained them through theft, a data leak or cloning.
The protocol was originally developed by Visa (under the Verified by Visa brand, now Visa Secure) and Mastercard (with SecureCode, now Mastercard Identity Check), although American Express and JCB also have their own versions. They all share the same technical basis: communication between three parties (the merchant, the card-issuing bank and the payment network) to authenticate the transaction before approving it.
With the entry into force of the European PSD2 Directive and the Strong Customer Authentication (SCA) requirement, 3D Secure has gone from being a recommendation to becoming mandatory for most online purchases within the European Economic Area since 31 December 2020.
How a 3D Secure purchase works
The process happens in seconds and is usually invisible to the buyer when everything goes well. The standard flow is as follows.
- You enter your card details on the merchant’s website (number, expiry date and CVV).
- The merchant sends the payment request to the card network (Visa, Mastercard or another network).
- The network checks with the issuing bank whether the transaction requires strong authentication.
- If necessary, the bank asks the cardholder for an additional confirmation. This may be an SMS with a code, a notification in the banking app to approve with fingerprint or face recognition, or a combination of password and temporary code.
- Once the identity has been confirmed, the payment is processed. If the buyer does not pass authentication, the transaction is rejected.
This double validation (something you have, such as your phone, plus something you know or something you are, such as a fingerprint) is what defines the concept of strong authentication required by European payment services regulation.
The evolution from 3DS 1 to 3DS 2
The first version of the protocol, known as 3D Secure 1, came into use in the early 2000s. It worked, but it always asked for a fixed password that many users forgot, forced pop-up windows that interrupted the checkout flow and caused high cart abandonment rates. The cardholder also had to register beforehand with the bank’s service in order to use it.
3D Secure 2 (3DS2) solved those problems. It uses risk-based authentication: the bank and the merchant exchange a much larger amount of contextual data (device, location, purchase history, behaviour pattern) to decide whether the transaction is safe enough to be approved without friction. Most purchases with 3DS2 are completed through a frictionless flow in which the user does not even notice they have been authenticated.
Only when the system detects risk signals (a purchase from a new device, a high amount, an unusual merchant) does the request for additional mobile confirmation appear. That request no longer happens in a separate pop-up window, but within the merchant’s own interface, with the option to use biometrics (fingerprint, face recognition) as well as SMS or an in-app code. 3DS2 has been the standard in force in Europe since the end of 2020. The old version has been discontinued.
Advantages of paying with 3D Secure
For the buyer, 3D Secure offers specific advantages. The first is the direct reduction of fraud risk: even if someone has your card details, they cannot complete the purchase without also having access to your phone or biometrics. The second is the liability shift. If a transaction authenticated with 3DS turns out to be fraudulent, the financial liability falls on the issuing bank, not on the cardholder. Without strong authentication, disputing an unauthorised charge is more complex and depends more on the issuer’s willingness to resolve it.
3D Secure 2 also reduces false declines. Risk-based authentication avoids the unnecessary blocking of valid purchases that was common with the old protocol, and every transaction is recorded with an authentication identifier that makes claims easier if something goes wrong.
However, 3D Secure protects the payment transaction, but it does not verify whether the seller will ship the product or comply with the agreed conditions. Before entering your card details, it still makes sense to check the signs that identify a trustworthy online store, especially in new stores or on websites with prices far below market level.
For merchants, implementing 3DS2 means less fraud, a lower chargeback rate and better conversion compared with the old protocol, thanks to the frictionless flow that approves most regular transactions without extra steps.
How it applies to prepaid cards
Prepaid cards issued under a Visa or Mastercard licence in the European Economic Area use 3D Secure like any other card. The difference is that they combine the security of the protocol with the additional protection of the prepaid model: you can only spend the balance that has been loaded, so even if a transaction were completed by mistake, the maximum loss would be the amount available on the card at that moment.
In Bitsa, every online purchase goes through 3D Secure with confirmation in the app before being charged to the balance. The cardholder receives a real-time notification and must approve the transaction from their phone. The virtual card, especially useful for one-off purchases or for separating spending by category, applies the same protocol as the physical card.
This combination of a prepaid card with 3D Secure is especially useful for managing digital subscriptions, where a controlled balance prevents charges above what you expected. If your subscriptions tend to spiral out of control, having a card with a specific balance sets a real limit, and 3DS protection adds another layer to the setup.
To strengthen overall card security beyond the protocol itself, it is worth enabling two-factor authentication on the account and reviewing transactions frequently. These and other recommendations are covered in the guide on how to protect your money with Bitsa prepaid cards.
3D Secure has gone from technical recommendation to legal obligation across the European Union. Its current version works in the background most of the time and only appears when the system detects risk signals. For users, this combination of automatic security with confirmation when needed is what has allowed online payments to grow without fraud increasing at the same pace.
Frequently asked questions
What is 3D Secure in simple terms?
3D Secure is a security protocol that verifies the identity of a cardholder in every online purchase. It combines card details with a second authentication factor (SMS code, approval in the banking app, fingerprint or face recognition) to confirm that the person paying is really the owner.
Which purchases use 3D Secure?
In the European Economic Area, PSD2 regulation requires strong authentication for most remote electronic payments. There are specific exemptions, such as purchases under €30, certain recurring payments or transactions marked as low risk by the issuer. Outside those cases, double authentication with 3D Secure is the rule.
Can I disable 3D Secure on my card?
Not generally. Since it is a regulatory requirement in Europe, issuers do not allow cardholders to disable it for all transactions. You can manage how you receive authentication (SMS, app, biometrics) from your bank or card provider settings.
What happens if I do not receive the SMS or notification to authenticate?
The transaction is rejected because authentication has not been completed. Check that your mobile number and email are up to date in the issuer’s app, that you have coverage and that the banking app is installed. If the problem continues, contact the provider to review the configured authentication channels.
Does 3D Secure protect against phishing?
It protects against the fraudulent use of your card details, but not against phishing itself. If you land on a fake website that imitates a real merchant and enter your details, the attacker may try to use the card in another store. 3D Secure will block the payment if they cannot authenticate as you. Real protection against phishing starts with identifying the website properly before entering your details.
Do prepaid cards have 3D Secure?
Yes. Prepaid cards issued under a Visa or Mastercard licence in the European Economic Area apply 3D Secure under the same conditions as debit or credit cards. In Bitsa, all online purchases are validated through 3D Secure with confirmation from the app before being charged to the balance.