Challenge flow
What is challenge flow?
Challenge flow is the authentication path in which the is asked to verify their identity before a payment is authorized. The issuer requests it when it wants proof of identity that the transaction data alone doesn't provide.
It's one of two outcomes of a 3D Secure authentication request. The other is frictionless flow, where the issuer authenticates on the submitted risk data alone and the cardholder never sees an extra step. In a challenge, the checkout hands the cardholder to a screen controlled by their issuing bank, which asks for a one-time passcode, an in-app approval, or a . Challenge flow belongs to , where there's no physical card or PIN pad to confirm who is paying.
Key facts
- Part of: the 3D Secure protocol, which authenticates the cardholder before the payment reaches authorization
- Triggered by: the issuer's assessment of the authentication request, or a regulatory requirement such as in the EEA and UK
- Verification methods: one-time passcode by SMS or email, approval inside the issuer's banking app, biometrics such as fingerprint or face recognition
- Alternative path: frictionless flow, where the issuer authenticates with no cardholder interaction
- Liability effect: under scheme rules, a successfully authenticated transaction moves fraud-chargeback liability to the issuer through . The exact conditions differ by scheme and region.
- Applies to: card-not-present transactions, including one-off checkout payments and the first payment in a subscription
How it works
- Authentication request – the merchant's sends the transaction into 3D Secure with device, browser, and order data attached.
- Issuer risk assessment – the scores that data against what it knows about the account and the cardholder's history. A confident result ends in frictionless authentication; an uncertain one ends in a challenge.
- Challenge presented – the cardholder sees the issuer's authentication screen, either embedded in the checkout, as a redirect, or as a push notification in the banking app.
- Cardholder responds – the cardholder enters the passcode, approves in the app, or passes the biometric check, and the issuer verifies the response.
- Result returned – the issuer sends the authentication outcome back, and the payment moves to if the challenge succeeded. A failed or abandoned challenge stops the payment before authorization.
Why it matters
- Consumer card payments in the EEA and UK fall under the SCA rules introduced by , so a checkout with no working challenge path can't complete a payment when the issuer asks for one.
- A successful challenge moves fraud-chargeback liability from the merchant to the issuer, which removes the merchant's exposure on disputes filed as unauthorized use.
- An issuer that wanted authentication and didn't get it returns a soft decline: a that invites a retry of the same transaction through 3D Secure with a challenge, rather than a permanent refusal.
- Every step in a challenge is a point where the cardholder can drop out. A passcode that arrives late, or a banking app the cardholder isn't enrolled in, ends the checkout before the transaction reaches authorization.
Common issues
- Undelivered passcodes – SMS codes fail on roaming numbers, changed phone numbers, and carrier delays, and the challenge times out with no response.
- Unenrolled cardholders – a cardholder meeting 3D Secure for the first time completes enrollment inside the challenge itself, which adds steps and drop-off at the worst moment.
- Broken returns to checkout – a challenge opened as a redirect or inside an in-app browser can fail to hand the session back, so the payment stalls after the cardholder has already authenticated.
- Challenges on unattended payments – and other run with no cardholder present. Routed to a challenge, they fail; exists to authenticate them without one.
- Rejected exemption requests – a transaction submitted with a the issuer declines to honour returns to a challenge anyway, and the saved step never materialises.


