Get Ready for the Future! Download the State of Checkout 2025 White Paper Today
Platform

Product & Solutions

Learn more about the only open payments platform built for global commerce

How it Works

Solutions

Open Payments Connectivity
Payment Data Security & Compliance
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Resolve

Reduce siloes, advanced security and billing control

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Company

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Parter Integrations

Partners & Integrations

Integrations Ecosystem
Our Partners

Latest Partner News

Webinars

Paysafe Unveils Strategic Partnership with Spreedly

Featured Partner

PayPal
Product & Solutions

Product & Solutions

Learn more about the only open payments platform built for global commerce

How it Works

Solutions

Open Payments Connectivity
Payment Data Security & Compliance
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Resolve

Reduce siloes, advanced security and billing control

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Pricing
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Developers

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Partners & Integrations

Partners & Integrations

Integrations Ecosystem
Our Partners

Latest Partner News

Webinars

Paysafe Unveils Strategic Partnership with Spreedly

Featured Partner

PayPal
Company

Company

About
Leadership
Careers
Contact Us
News
Company
Log In
See a Demo
Log In
See a Demo
Platform

Product & Solutions

Learn more about the only open payments platform built for global commerce

How it Works

Solutions

Open Payments Connectivity
Payment Data Security & Compliance
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Resolve

Reduce siloes, advanced security and billing control

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Use Cases
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Company

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Blog
Platform

Product & Solutions

Learn more about the only open payments platform built for global commerce

How it Works

Solutions

Open Payments Connectivity
Payment Data Security & Compliance
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Resolve

Reduce siloes, advanced security and billing control

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Use Cases
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Company

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Blog
Log In
See Demo
Back to Blog
Back to News

Payment Security

June 2, 2020

How does browser-based authentication work for 3DS2?

The PSD2 deadline for Strong Customer Authentication (SCA) is fast approaching, and the new protocol addresses a market trend that has needed attention for quite some time now: authentication for mCommerce transactions. This authentication is something that was left out entirely in 3DS version one.

Written by

Janna Johnson

In this article

Share

Related products

No items found.

Lorem Ipsum Dolor Sit

Vel sed vitae enim nec suspendisse ut viverra tincidunt quis

Learn More

Subscribe to our blog

Get practical, actionable insights written by experts from the world of digital payment solutions delivered to your Inbox.

The PSD2 deadline for Strong Customer Authentication (SCA) is fast approaching, and the new protocol addresses a market trend that has needed attention for quite some time now: authentication for mCommerce transactions. This authentication is something that was left out entirely in 3DS version one.

We learned from “What is 3DS2?” that shoppers will now be able to use biometric authentication, such as fingerprint and facial recognition to authenticate themselves from a mobile app. However, non-mobile devices lack the capabilities to take advantage of biometric characteristics for authentication. These functional differences beg the question: where does this leave browser-based authentication in the 3DS2 picture? Let’s dive into the notable improvements on the browser side.

Richer Browser Information

One of the key elements of 3DS2 is the ability to exchange ten times more data than ever before. These 150 new fields capture and exchange data elements such as cardholder account information, purchase information, prior transaction authentication, and device information. The fields captured for device information vary based on the method in which the consumer is performing the transaction: mobile or browser. While there are overlapping fields for the two different methods, there are distinct fields that are captured for browser-based authentication.

3DS2 allows the issuing bank to capture and perform a real-time risk assessment using richer browser information. For example, the 3DS server captures browser-specific fields such as time zone, size of the user’s screen, and the language of the cardholder’s browser.

This data is then passed on to the issuing bank’s access control server (ACS), which uses risk-based authentication to analyze the data and return a risk score for that specific transaction. If the transaction is deemed low risk, the ACS will respond to the authentication request from the 3DS server and approve the transaction as low risk with no further authentication needed.

The value to the customer is an entirely frictionless checkout experience as the authentication process happened behind the scenes of the browser.

Browser-specific fields captured by a 3DS server
Browser-specific fields captured by a 3DS server

Trouble-free Challenge Flow

Approximately 95% of transactions are expected to follow this frictionless process due to the robust data capturing abilities of the 3DS server. Still, there will be a number of transactions deemed high risk due to their size and nature.

For example, some transactions might be deemed high risk merely based on the Merchant Category Code (MCC). Merchants that fall under categories such as cruise lines, limousine services, and furniture dealers are deemed as high risk merchants by credit card associations and might require further authentication.

Other reasons for further authentication might include transactions over a specific transaction amount threshold. The Payment Services Directive version 2 (PSD2) identifies the requirements for a transaction needing Strong Customer Authentication. One of those requirements for SCA includes transactions over 30 euros. In the case of one of these scenarios, the 3DS2 challenge flow includes notable improvements to the customer experience that aims to reduce the high percentage of cart abandonment rates that we saw with 3DS1.

The former 3DS1 challenge flow required customers to authenticate themselves using a protocol that redirected the user away from the merchant’s website to the issuing bank — leaving the checkout screen entirely. At the bank’s website, the only way to authenticate was by logging into his/her account using a static password. In the case of a lost or unknown password, users either needed to go through a full reset or, in the case of about 50% of these users, abandoned their cart.

Former 3DS1 Frictionless Flow

One of 3DS2’s notable improvements allows the user to authenticate themselves without leaving the merchant’s page. The new and improved 3DS2 challenge flow allows a one-time password (OTP) to be sent to the user’s phone to verify the transaction. This smoother flow requires far less effort on the customer’s side which is expected to significantly decrease cart abandonment rates.

3DS2 challenge flow

Improved Customer Experience

Merchants have been searching for ways to combat eCommerce fraud for years. Technological innovations have paved the way for the shopping experience to become more convenient as customer’s shift from shopping in physical stores, to online, to their mobile devices. While noble efforts have been made in the payments industry to keep fraud low as more payments shifted from card present (CP) to card not present (CNP) transactions, most efforts have fallen short.

The first version of 3DS was introduced in 1999 and left much to be desired. The intent of the initial protocol was to provide the ability to authenticate transactions. While meeting this need, adoption rates were not positive due to dwindling conversion rates and a lack of a positive customer experience. Luckily, 3DS2 is receiving a much needed face-lift that aims to make up for its short comings.

3DS2 improves the user experience by allowing the customer to complete the checkout flow in a secure and uninterrupted way. For the ~5% of transactions that will require a challenge, the new browser flow will allow the customer to stay on the merchant’s page to authenticate themselves in a quicker and more efficient manner. These new improvements will ideally increase conversion rates and decrease cart abandonment while still keeping security front and center.

Download the Payments Orchestration eBook Below

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Read more
Written By
What browser-specific information does 3DS2 capture for risk assessment?

3DS2 captures browser-specific fields such as time zone, size of the user's screen, and the language of the cardholder's browser. This richer browser information is passed to the issuing bank's access control server (ACS) to perform real-time risk assessment and generate a risk score for each transaction.

What percentage of transactions are expected to complete without requiring additional authentication in 3DS2?

Approximately 95% of transactions are expected to follow the frictionless process in 3DS2. These low-risk transactions are approved behind the scenes of the browser without requiring further authentication, providing customers with an entirely frictionless checkout experience.

What types of merchants or transactions are more likely to be flagged as high risk and require additional authentication?

Transactions are deemed high risk based on factors such as the Merchant Category Code (MCC)—merchants like cruise lines, limousine services, and furniture dealers are considered high risk by credit card associations. Additionally, transactions that exceed a specific transaction amount threshold may require further authentication.

Reach out to our team
Download Free
Get My Report
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Learn More
Reach out to our team
Download Free
Get My Report
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Written by

Janna Johnson

Janna Johnson was a Payments Product Manager at Spreedly, where she focused on authentication, orchestration, and the systems that shape how secure payments function in practice. Her work centered on 3DS2, multi-factor authentication, and helping organizations balance security, compliance, and customer experience across global payment environments.During her time at Spreedly, Janna led product initiatives spanning payment orchestration, fraud and authentication tooling, payment recovery, and checkout experiences across a wide range of global payment methods. She brought a strong interest in how payment and authentication systems influence financial access, economic participation, and the broader role payments play in enabling faster, more inclusive global commerce.Janna wrote about payment authentication, orchestration, and compliance, with a focus on helping teams understand how security, user experience, and payment performance intersect in modern payment systems.

Lorem Ipsum Dolor Sit

Vel sed vitae enim nec suspendisse ut viverra tincidunt quis

Learn More

Related Articles

Addressing New PCI DSS 4.0 Security Concerns With Payments Orchestration

Payment Security

Rachel Fine

November 22, 2023

Arc'teryx and the 2019 PSD2 Mandate

Payment Security

Lorra Gosselin

June 23, 2020

Benefits of Performing Security Risk Assessments

Payment Security

Aaron Finley

June 15, 2022

Back to Blog

Get Regular Updates From Payments Experts

Subscribe to our newsletter and we’ll send you a monthly update of all of our new content so you don’t miss out on new data, new insights, and news from the world of payments. 

Insights and updates you actually care about

Get practical, actionable insights written by experts from the world of digital payment solutions delivered to your Inbox.

By subscribing, you agree to our Privacy Policy and Terms.

Find Us On

Company
  • Pricing
  • About
  • Careers
  • Contact Us
  • Partners
Resources
  • Support
  • Guides
  • FAQ
  • News
  • Webinars
  • Trust Center
Developers
  • Developer Guides
  • Documentation
  • See Demo
  • Status

Find Us On

Privacy SettingsTermsPrivacyStatus
© 2026 Spreedly, Inc. All rights reserved.