Lesson 10 / 25
Strong Customer Authentication and 3D Secure
When the issuer asks the customer to prove who they are.
requires_action and the challenge flow
Strong Customer Authentication (SCA) is a requirement in the European Economic Area and the UK (under PSD2 rules) that many online payments are authenticated with two factors. Similar rules exist elsewhere, such as additional authentication for many card payments in India. For cards the usual mechanism is 3D Secure: the issuer may show a challenge (a bank app approval or a one-time code). In Stripe, a PaymentIntent that needs this moves to status requires_action. stripe.confirmPayment and Checkout handle the challenge for you; issuers can also grant exemptions, and Stripe requests them where appropriate.
Beyond a simple card charge
Regulation, saved cards and local payment methods change how a payment is confirmed.
Handling authentication without a redirect
Stripe.js with redirect only when required.
const { error, paymentIntent } = await stripe.confirmPayment({
elements,
confirmParams: { return_url: 'https://example.com/order/complete' },
redirect: 'if_required', // stay on the page unless the method needs a redirect
});
if (error) {
showMessage(error.message); // e.g. authentication failed or card declined
} else if (paymentIntent.status === 'succeeded') {
showMessage('Payment received.'); // still fulfil from the webhook
} else if (paymentIntent.status === 'processing') {
showMessage('Payment processing. We will email you when it completes.');
}
Test the challenge with documented test cards
In test mode, card 4000 0025 0000 3155 requires authentication, so you can see the 3D Secure modal. Check the testing docs for other authentication scenarios.
Quick check: Which PaymentIntent status means the customer must complete an extra step such as 3D Secure?
- requires_action
- requires_capture
- succeeded
- canceled
Answer
requires_action — Stripe.js handles the next action when you confirm on the client.