3D Secure Authentication
Last updated: March 9, 2022
3D Secure 2 Authentication (3DS2) is a way to both make payments more secure and reduce fraud by using a process called two-factor authentication, which uses a second layer of security. For example, if a customer uses their credit card online, a second layer of security might be in the form of a code sent to their phone, a security question they have to answer, or even their fingerprint.
In Europe, this is often referred to as Strong Customer Authentication (SCA), referring to the mandate from the European Union for banks and card issuers to enforce 3DS2 for all card-based online payments. While other countries, such as the US, may not yet mandate use of 3DS2, banks and card issuers can still choose to enforce it when processing online payments due to security reasons.
How will this affect my customers?
3DS2 mainly affects the payment process for your customers booking online using a credit card. When they enter their card information, they will be required to complete a secondary form of authentication to ensure their payment is secure. Once they complete the secondary form of authentication, their payment will be processed.
How will this affect bookings made on the Dashboard?
Dashboard bookings are generally exempt from 3DS2 authentication.
However, in some cases, the card issuer or bank may still choose to enforce 3DS2. When this happens, the payment won’t be processed and you will be presented with an error. Contact your customer to try the payment with a different card.
As banking regulations continue to change, we recommend businesses that are processing a large number of in-person bookings to use one of our supported card readers to collect payments securely and seamlessly. Note: Payments collected using a supported card reader are always exempted from 3DS2.
Internal-only content. Don't copy and paste to anyone.
FareHarbor is SCA-compliant for the PSD2 regulation in Europe. SCA stands for Strong Customer Authentication and adds additional authentication to credit card transactions as required by banks to reduce fraud and make online payments more secure. This is required by law for companies located in the European Union and European Economic Area, and the UK. Customers who are booking with bank accounts in these countries may also be subject to these requirements.
Note: SCA and 3DS2 are not the same. The mandate itself is called “SCA”, and the mechanism used by card issuers in Europe to remain compliant with it is called 3DS2.
Talking points
- Adds trust to the end user because our payment checkout is even more secure.
- SCA mandate is in effect since September 14, 2019, as part of the PSD2 regulation in Europe. The regulations require changes in how your European customers authenticate online payments.
- There are many variables when helping a client decide whether this requirement will affect their business operations. 3DS2 authentication may be required by the card issuer based on a customer’s credit limits, card purchase history, or the reliability of the vendor (client), etc. If a client has customers who are reluctant to purchase tickets online, you can suggest that they opt instead to use an EMV card reader or take in-person cash payments.
Options for dealing with 3DS2
How do we guide our clients in resolving their roadblocks surrounding an increase in authentication requests? Every case is different, so here is a step-by-step guide with solutions for various scenarios:
Push back to encourage clients to book online more.
Recommend card readers that are usable with a Dashboard or desktop. This is useful for scenarios where:
- the activity and the company location are the same, or
- a verification of the booking / payment (for example, a check-in) is required for participating in the activity.
Recommend card readers compatible with apps. This is relevant for scenarios where:
- the activity and the company location are different, or
- a verification of the booking / payment (for example, a check-in) is required for participating in the activity.
Recommend payment links as an option. This is useful for companies where the activity doesn’t require a booking / payment verification or a check-in.