adyen 3d secure 2
A plain-English explainer skill for what 3D Secure 2 is and how Adyen implements it: the authentication flow, frictionless vs challenge paths, and the liability shift for merchants. Use when a merchant or developer needs to understand Adyen's 3DS2 before integrating, or when 'what is 3D Secure 2' comes up. Triggers: 'what is 3D Secure 2', 'Adyen 3DS2 explained', 'liability shift 3D Secure'. Not for: enabling 3DS in Adyen (see the setup skill), bypassing 3D Secure, non-Adyen providers.
TL;DR
3D Secure 2 is the card-industry protocol that authenticates the cardholder with their bank during an online payment, and Adyen implements it natively inside its checkout and API flows. Most transactions go through a frictionless path (risk data is exchanged invisibly and the payment just completes), while risky ones trigger a challenge where the shopper proves identity with their bank, often via biometrics. The big merchant win is the liability shift: a successfully authenticated transaction moves fraud liability from you to the card issuer.
adyen 3d secure 2Use this when
- You need to understand what 3D Secure 2 does before integrating Adyen
- A stakeholder asks why some Adyen payments show a bank challenge screen
- You are evaluating the fraud-liability tradeoff of enabling 3DS2
- Someone asks what 'liability shift' means in a payments context
Not for
- Step-by-step setup instructions (see the companion skill on enabling 3D Secure in Adyen)
- Bypassing, skipping, or weakening 3D Secure checks (never do this)
- 3D Secure on other payment processors
Steps
- Learn the two paths: frictionless and challenge. In the frictionless flow, Adyen sends device and transaction data to the card issuer behind the scenes; the issuer scores the risk and most low-risk payments are approved with no shopper interaction. In the challenge flow, the issuer asks the shopper to authenticate, usually with their banking app biometrics or a one-time code.
Expected output: you can explain to a teammate why 95% of payments complete silently and a few show a bank screen.
- Understand where Adyen fits in. With Adyen's Drop-in/Components or the API, 3DS2 is handled inside the payment flow: Adyen collects the browser and device data, talks to the card schemes' directory servers, and returns the authentication result alongside the authorization. You dont integrate with the card networks directly.
Expected output: your integration plan has one 3DS2 touchpoint (Adyen), not a separate 3DS provider.
- Know what the liability shift covers. When a transaction is authenticated through 3DS2 (frictionless or challenge), fraud chargeback liability shifts from the merchant to the issuer. Unauthenticated transactions keep liability with you. This is the core business reason merchants enable it, especially in regions with strong customer authentication rules.
Expected output: your risk model distinguishes authenticated transactions (issuer liable) from unauthenticated ones.
- Learn the PSD2/SCA connection. In Europe, strong customer authentication is legally required for most online card payments, and 3DS2 is the standard way to satisfy it. Adyen applies exemptions (like low-value or transaction risk analysis) where allowed so legitimate payments stay frictionless.
Expected output: you know which of your transactions legally require a challenge and which can use exemptions.
- Read the authentication result in Adyen's response. Adyen returns 3DS2 outcome data (authentication status, and whether liability shifted) on the payment result; log and store these fields because they are your evidence in a chargeback dispute.
Expected output: your order records include the 3DS2 authentication outcome for every card payment.
- Plan for challenge UX. Challenges interrupt checkout, so design for them: keep the shopper on your page context, handle timeouts gracefully, and never punish the shopper for a challenge (it is the bank being careful, not the shopper failing).
Expected output: a test challenge payment completes and returns the shopper to a clear order confirmation.
Variant phrasings
- "what is 3DS2 and how does it work"
- "Adyen 3D Secure 2 authentication flow"
- "3D Secure frictionless vs challenge"
- "does 3D Secure shift liability to issuer"
Edge cases and pitfalls
- Liability shift applies to fraud chargebacks, not to all dispute types; 'item not received' claims follow different rules.
- Some issuers still run the older 3DS 1 fallback in edge cases; Adyen handles the fallback, but expect a clunkier shopper experience there.
- Out-of-scope regions (no SCA mandate) still benefit from 3DS2 for high-risk transactions; treat it as a risk tool, not just a compliance checkbox.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstIR-kqhOBVqHOHp_7v4NBQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.