Stripe "authentication_required" decline: SCA retry flow for invoices
Handles Stripe authentication_required declines on invoices under SCA/PSD2. Use when European (and similar) card payments need 3D Secure completion before the invoice can be paid. Not for non-authentication declines.
TL;DR
authentication_required means the bank demands the cardholder complete 3D Secure; no retry without authentication will succeed. Send the customer to complete the payment intent's next action (the 3DS challenge), then confirm. Build this as a first-class flow: email the customer a secure link that resumes the payment intent.
Error
```text
code: authentication_required
payment_intent status: requires_action
## Steps
1. On invoice.payment_failed with code authentication_required, retrieve the payment intent and its next_action.
Expected: You have the 3DS challenge URL or client secret to present.
2. Email or message the customer a secure link that opens your payment page with the payment intent client secret.
Expected: The customer can authenticate out of band.
3. On your payment page, confirm the payment intent so the 3DS challenge runs.
Expected: The bank challenge completes and the intent moves to succeeded.
4. Listen for invoice.payment_succeeded to close the loop, and invoice.payment_failed for a second decline.
Expected: Your system state matches Stripe regardless of outcome.
5. For future invoices, consider setup intents with off-session permission so renewals authenticate silently where allowed.
Expected: Fewer invoices hit the manual challenge path.
## When to use
- Invoices fail with authentication_required
- You bill cards in SCA regions (EEA, UK)
- Off-session renewals need a 3DS fallback flow
## When not to use
- The decline code is do_not_honor or insufficient_funds (no authentication will help)
- The customer is present and can pay in-session (just run 3DS inline)
- You use bank debits or wallets with different auth models
## Compatibility
Stripe Payments with 3D Secure 2; payment intents requires_action flow. SCA applies to EEA/UK-issued cards.
## Variant phrasings
### ### Stripe SCA invoice payment failed 3DS
### ### requires_action invoice retry flow
### ### off-session payment authentication_required
## Root cause
PSD2's Strong Customer Authentication requires issuers to challenge card-not-present payments that are not exempt, and renewals often are not exempt. Stripe surfaces this as authentication_required because the money cannot move until a human proves it is really the cardholder.
## Edge cases
- Some transactions qualify for exemptions (low value, recurring); Stripe requests them automatically
- The challenge link expires with the payment intent; regenerate if the customer delays
- Test with 3DS test cards to rehearse the whole loop before production
## Provenance
Resolved from the public thread: https://vectle.com/posts/pst_98vjDXHEPnyS06OSrocAuw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.