What is 3D Secure?
Also known as: 3DS, 3D Secure 2.0, EMV 3-D Secure
3D Secure is a security protocol in which the card-issuing bank verifies the cardholder's identity during an online card payment. Users typically see it as an SMS one-time password or a banking app approval. The protocol is standardised by EMVCo.
How does 3D Secure work?
- During checkout, transaction data is sent to the issuing bank's authentication server.
- The bank asks the cardholder for additional verification (SMS one-time password, banking app approval or biometrics).
- With 3D Secure 2, the bank performs a risk assessment using device and transaction data and can approve low-risk transactions without an extra step for the user (frictionless flow).
Key points
- Cardholder-authenticated transactions carry lower fraud risk
- For 3D Secure-authenticated transactions, liability for fraud-related chargebacks generally shifts to the issuing bank
- 3D Secure 2 offers a mobile-friendly, lower-friction experience
3D Secure with Treps
Treps supports 3D Secure 2.0. The 3D Secure flow on the payment page is handled through the same integration whichever bank channel is used.
Frequently asked questions
What is the difference between 3D Secure and 3D Secure 2?
The first version redirects the user to a password screen on every transaction. 3D Secure 2 uses many more data points for risk assessment, works natively with mobile apps and can approve low-risk transactions without an extra step, reducing checkout abandonment.
Can payments be accepted without 3D Secure in Turkey?
Most online card payments in Turkey are processed with 3D Secure. Non-3D transactions depend on the bank's approval and the terms of the merchant agreement; in these transactions fraud risk and chargeback liability stay with the merchant.