If you operate an online casino or sportsbook and accept card payments, 3-D Secure is no longer optional background knowledge. It sits at the intersection of fraud prevention, liability management and player experience, and getting it wrong costs real money on both ends of the transaction.
What 3-D Secure Actually Is
3-D Secure (3DS) is an authentication protocol developed by EMVCo that adds an identity-verification layer to card-not-present (CNP) transactions. The name refers to the three domains involved: the acquiring bank, the issuing bank, and the card scheme network (Visa, Mastercard, and others). When a player enters card details at checkout, 3DS allows the issuing bank to confirm the cardholder's identity before authorising the payment.
The original version, 3DS1, relied on a redirect to a static password page. The current standard, 3DS2, replaces that with a data-rich, frictionless flow. It passes up to 150 data points, including device fingerprint, browser metadata and transaction history, to the issuing bank's access control server. If the risk score is low, the payment completes without any extra step for the player. Only higher-risk transactions trigger a one-time passcode or biometric challenge.
The Three Flows Every Operator Should Understand
- Frictionless flow: The issuer authenticates the transaction silently using shared data. No player action is required. Conversion rates remain high.
- Challenge flow: The issuer requests additional verification, typically an SMS code or an in-app biometric. The player must complete this step before the payment proceeds.
- Decoupled authentication: Introduced in 3DS2.2, this allows authentication to happen outside the checkout session, which is useful for recurring or pre-authorised payments common in subscription and wallet top-up models.
Why iGaming Operators Face Unique Pressure Here
Card schemes and regulators treat gambling transactions as elevated risk by default. Chargeback rates in iGaming consistently run higher than in most other verticals, and issuing banks apply tighter scrutiny to merchant category code 7995 (the standard gambling MCC). This means a payment that sails through 3DS on a retail site may still trigger a challenge, or a decline, on your platform.
Beyond fraud, liability shift is the commercial argument for full 3DS adoption. When a properly authenticated 3DS2 transaction is disputed by a cardholder, the liability for the chargeback moves to the issuing bank rather than sitting with your acquiring bank and, ultimately, with you. For operators processing high volumes, that shift materially reduces chargeback exposure and the associated fees.
Exemptions and When to Use Them
PSD2 in Europe introduced the concept of transaction risk analysis (TRA) exemptions, allowing low-value or low-risk transactions to skip authentication entirely. However, iGaming operators need to be careful here. Many acquirers serving the gambling sector decline to apply TRA exemptions because the regulatory environment in specific jurisdictions requires strong customer authentication (SCA) on all gambling-related deposits. Confirm with your payment provider which exemptions are available on your merchant account before configuring your gateway.
Recurring transactions, such as automatic top-ups or stored payment methods, follow a separate path. Only the initial transaction in a recurring series typically requires full SCA; subsequent charges can be processed as merchant-initiated transactions (MITs) without re-authentication, provided the original mandate was properly authenticated.
Practical Implementation Steps for Operators
- Confirm your payment gateway or PSP supports 3DS2 natively and can pass the full data set required for frictionless authentication.
- Audit your checkout flow for the device and browser data collection scripts that feed the 3DS2 risk assessment.
- Segment your transaction monitoring: track frictionless rate, challenge rate, authentication failure rate and post-authentication decline rate separately.
- Align your responsible gambling controls with your authentication logic. For example, deposit limits can be enforced at the session layer before the payment request is sent.
- Review your acquiring agreement for chargeback thresholds. Some acquirers serving iGaming apply scheme-monitoring programme rules from Visa or Mastercard that penalise operators above a set chargeback ratio regardless of 3DS outcomes.
What a Low Frictionless Rate Tells You
If your frictionless rate is below 70 percent, something in your data pipeline is likely underperforming. Common causes include missing device fingerprint data, incomplete billing address fields, or a payment flow that strips headers before they reach the access control server. A consistently high challenge rate raises player abandonment at the deposit step, which is one of the most damaging points in the player journey to lose volume.
At OnlineShine, we regularly audit operator payment stacks as part of our operations service and find that 3DS configuration errors, not fraud levels, are the most common reason iGaming platforms pay more in chargebacks than they should.
Looking Ahead
EMVCo continues to iterate on the 3DS specification. As of mid-2025, 3DS2.3 features including improved non-browser authentication for in-app deposit flows are in active rollout by major card schemes. Operators building or rebuilding native mobile casino apps should ensure their SDK integration supports the latest specification to maintain competitive frictionless rates.



