Solidgate logo in black and white.

Challenge flow

What is challenge flow?

Challenge flow is the authentication path in which the is asked to verify their identity before a payment is authorized. The issuer requests it when it wants proof of identity that the transaction data alone doesn't provide.
It's one of two outcomes of a 3D Secure authentication request. The other is frictionless flow, where the issuer authenticates on the submitted risk data alone and the cardholder never sees an extra step. In a challenge, the checkout hands the cardholder to a screen controlled by their issuing bank, which asks for a one-time passcode, an in-app approval, or a . Challenge flow belongs to , where there's no physical card or PIN pad to confirm who is paying.

Key facts

  • Part of: the 3D Secure protocol, which authenticates the cardholder before the payment reaches authorization
  • Triggered by: the issuer's assessment of the authentication request, or a regulatory requirement such as in the EEA and UK
  • Verification methods: one-time passcode by SMS or email, approval inside the issuer's banking app, biometrics such as fingerprint or face recognition
  • Alternative path: frictionless flow, where the issuer authenticates with no cardholder interaction
  • Liability effect: under scheme rules, a successfully authenticated transaction moves fraud-chargeback liability to the issuer through . The exact conditions differ by scheme and region.
  • Applies to: card-not-present transactions, including one-off checkout payments and the first payment in a subscription

How it works

  1. Authentication request – the merchant's sends the transaction into 3D Secure with device, browser, and order data attached.
  2. Issuer risk assessment – the scores that data against what it knows about the account and the cardholder's history. A confident result ends in frictionless authentication; an uncertain one ends in a challenge.
  3. Challenge presented – the cardholder sees the issuer's authentication screen, either embedded in the checkout, as a redirect, or as a push notification in the banking app.
  4. Cardholder responds – the cardholder enters the passcode, approves in the app, or passes the biometric check, and the issuer verifies the response.
  5. Result returned – the issuer sends the authentication outcome back, and the payment moves to if the challenge succeeded. A failed or abandoned challenge stops the payment before authorization.

Why it matters

  • Consumer card payments in the EEA and UK fall under the SCA rules introduced by , so a checkout with no working challenge path can't complete a payment when the issuer asks for one.
  • A successful challenge moves fraud-chargeback liability from the merchant to the issuer, which removes the merchant's exposure on disputes filed as unauthorized use.
  • An issuer that wanted authentication and didn't get it returns a soft decline: a that invites a retry of the same transaction through 3D Secure with a challenge, rather than a permanent refusal.
  • Every step in a challenge is a point where the cardholder can drop out. A passcode that arrives late, or a banking app the cardholder isn't enrolled in, ends the checkout before the transaction reaches authorization.

Common issues

  • Undelivered passcodes – SMS codes fail on roaming numbers, changed phone numbers, and carrier delays, and the challenge times out with no response.
  • Unenrolled cardholders – a cardholder meeting 3D Secure for the first time completes enrollment inside the challenge itself, which adds steps and drop-off at the worst moment.
  • Broken returns to checkout – a challenge opened as a redirect or inside an in-app browser can fail to hand the session back, so the payment stalls after the cardholder has already authenticated.
  • Challenges on unattended payments – and other run with no cardholder present. Routed to a challenge, they fail; exists to authenticate them without one.
  • Rejected exemption requests – a transaction submitted with a the issuer declines to honour returns to a challenge anyway, and the saved step never materialises.

Related terms