Lesson 10 / 25

Strong Customer Authentication and 3D Secure

When the issuer asks the customer to prove who they are.

requires_action and the challenge flow

Strong Customer Authentication (SCA) is a requirement in the European Economic Area and the UK (under PSD2 rules) that many online payments are authenticated with two factors. Similar rules exist elsewhere, such as additional authentication for many card payments in India. For cards the usual mechanism is 3D Secure: the issuer may show a challenge (a bank app approval or a one-time code). In Stripe, a PaymentIntent that needs this moves to status requires_action. stripe.confirmPayment and Checkout handle the challenge for you; issuers can also grant exemptions, and Stripe requests them where appropriate.

Beyond a simple card charge

Regulation, saved cards and local payment methods change how a payment is confirmed.

Three ideas: 3D Secure and SCA, saving cards for later, and local and dynamic payment methods.
Figure 4.1 — Confirm, authenticate, save and reuse.

Handling authentication without a redirect

Stripe.js with redirect only when required.

const { error, paymentIntent } = await stripe.confirmPayment({
  elements,
  confirmParams: { return_url: 'https://example.com/order/complete' },
  redirect: 'if_required',   // stay on the page unless the method needs a redirect
});

if (error) {
  showMessage(error.message);          // e.g. authentication failed or card declined
} else if (paymentIntent.status === 'succeeded') {
  showMessage('Payment received.');    // still fulfil from the webhook
} else if (paymentIntent.status === 'processing') {
  showMessage('Payment processing. We will email you when it completes.');
}

Test the challenge with documented test cards

In test mode, card 4000 0025 0000 3155 requires authentication, so you can see the 3D Secure modal. Check the testing docs for other authentication scenarios.

Quick check: Which PaymentIntent status means the customer must complete an extra step such as 3D Secure?

  • requires_action
  • requires_capture
  • succeeded
  • canceled
Answer

requires_action — Stripe.js handles the next action when you confirm on the client.