3-D Secure is an authentication protocol in which the card issuer confirms that a cardholder is behind an online transaction. It is known by the brand names Verified by Visa and Mastercard Identity Check, and in the current EMV 3DS version it exchanges dozens of device and order parameters with the merchant. Here is how that exchange works and why a payment sometimes ends at the confirmation step.
How it works
From the request to the authentication result
What happens at the moment of payment
When a merchant supports 3-D Secure, it sends an authentication request to the issuer before authorization. That request carries the amount, the currency, order data and technical signals about the device: browser, language, time zone, IP. The issuer scores the risk and decides whether those signals are enough or a dialogue with the cardholder is needed. The result comes back as a separate response, and only then does the authorization request follow. This is why a failure at the authentication stage looks like an ordinary decline, even though the balance was never checked.
Frictionless flow and challenge flow
The frictionless flow is the scenario where the issuer approves authentication on risk data alone, with no cardholder involvement: you see a short pause and then the result. The challenge flow opens a dialogue: an issuer window appears asking for a one-time code, an approval in the bank app or a biometric check. Which flow applies is decided per transaction — amount, transaction history, merchant category and the completeness of the transmitted data all play a part. The same merchant can produce different flows on different attempts.
Where the one-time code comes from
The code is generated by the card issuer and delivered over the channel registered for the card: an SMS to the registered number, a push into an app, an email to the linked address. The merchant never sees the code and cannot resend it — the «send again» button in the confirmation window addresses the issuer. For TrustVCC cards that come with access to confirmation codes, that access is shown in the card details together with the billing address: open the card in your account and take the data from there.
Regulatory rules: SCA
In the EEA and the UK, strong customer authentication (SCA) is required under PSD2, so most online transactions must be confirmed. Regulation does provide exemptions — low value, trusted beneficiary, merchant-initiated subscription payments — but they are applied by the issuer, not by the buyer. The practical consequence: for cards in EUR and GBP and for European merchants the confirmation step appears noticeably more often, and payments are worth planning around it.
Why the confirmation window does not appear
A common technical cause is blocked pop-ups and iframes: the issuer window opens on top of the merchant page, and browser extensions or strict privacy settings suppress it. Other cases: the payment session timed out, the page was refreshed mid-check, or checkout was open in two tabs at once. In all of them the merchant receives an «authentication not completed» result and ends the transaction. Pay in a normal window without blockers, do not switch tabs during the check, and carry the step through to the end.
A refusal at the authentication step
If authentication does not succeed, the merchant may skip the authorization request entirely or send it flagged as unauthenticated — in which case the issuer decides, and usually refuses. The important part is that the balance is not the cause: topping the card up changes nothing here. What needs attention is the confirmation step itself — access to the code channel, the issuer window, the time allowed for entry. Responsibility is split between issuer and merchant, and neither discloses the details of the decision.
Subscriptions and recurring charges
The first confirmed subscription charge normally goes through authentication, while later ones run as merchant-initiated transactions with no cardholder dialogue. That is the standard design, but it has a consequence: the card must stay active and funded when the next charge arrives, because there will be no confirmation window to remind you. Keep the amount of the next payment on the card in advance, especially when the charge is tied to a date rather than to an action of yours.
Frequently asked questions
Why does the confirmation code not arrive?
The code is sent by the issuer over the channel registered for the card, not by the merchant. If that channel is unreachable or the issuer window never opened, the transaction ends as failed authentication. TrustVCC cards that come with code access show it in the card details in your account.
Can 3-D Secure be switched off for a payment?
No. Whether confirmation is required, and in what form, is decided by the issuer together with the merchant based on the amount, the transaction category and regulatory rules. It is not something the buyer can disable.
Why did one payment go through without a code and another asked for one?
The issuer chooses between the frictionless and challenge flows per transaction, weighing the amount, currency, merchant category, history and the completeness of the device data supplied. Different outcomes on the same site are normal protocol behaviour.
Does 3-D Secure protect against chargebacks?
Completed authentication shifts liability for fraud-based disputes to the issuer side under network rules. It does not remove disputes on other grounds, such as goods or services that were never received.
Is confirmation needed for every subscription charge?
As a rule, authentication happens on the first charge and when terms change, while recurring payments run as merchant-initiated. That is why the card must hold enough funds on the renewal date — there will be no confirmation window to act as a reminder.