Flexible 3DS Authentication in DECTA Gateway

Flexible 3DS authentication in the DECTA gateway gives payments product managers at PSPs and acquirers a way to assess EMV 3DS 2.3.1.1 against older implementations. This article covers the certification, security, approval rate, and compliance criteria worth considering.

July 01, 2025
Flexible 3DS Authentication in DECTA Gateway: Features & Benefits

For payment service providers and acquirers seeking competitive advantage, DECTA's configurable 3D Secure authentication stands out for superior security, enhanced performance metrics, and significant operational benefits.

As one of the first European processors to achieve EMV 3DS 2.3.1.1 certification, DECTA offers authentication capabilities that outperform traditional implementations while reducing costs and complexity.

DECTA's Advanced EMV 3DS 2.3.1.1 Protocol Implementation

DECTA implements the EMV 3DS 2.3.1.1 protocol to support secure, modern payment authentication. The following sections outline DECTA's certification, data intelligence, and risk assessment capabilities with this latest protocol version.

Industry-Leading Certification Achievement

As one of the first payment processors in Europe to gain this capability, DECTA ensures PCI DSS Level 1 standards for merchant solutions. PCI DSS Level 1 is the highest of the four card industry compliance tiers and applies to processors handling the largest transaction volumes, so it is the level most PSP and acquirer procurement checklists ask for by name.

This certification provides PSPs and acquirers with a competitive edge.

Superior Data Intelligence and Risk Assessment

EMV 3DS 2.3.1.1 is the latest payment authentication version, offering, compared to earlier releases, enhanced data exchanges, superior risk assessment capabilities, and increased accommodations associated with newer authentication options such as biometric verification and Secure Payment Confirmation (SPC).

Secure Payment Confirmation (SPC): a browser-level standard that lets a cardholder confirm a payment with a device biometric instead of a redirect to the issuer's challenge page.

While older 3DS versions utilize minimal data points for payment authentication, DECTA operates on the full-featured options afforded by the 3DS 2.x protocol to create more comprehensive risk assessment opportunities and real-time decisions.

The risk signals the protocol carries include:

  • Device fingerprinting
  • Transaction history
  • Pattern recognition
  • Geographic risk factors
  • Temporal risk factors
  • Merchant-specific risk profiles
  • Customer authentication preferences

This allows DECTA to achieve a much higher threshold for frictionless authentication without losing any real-time fraud detection ability.

Frictionless flow: the issuer approves on the data alone and the cardholder sees nothing.

Challenge flow: the cardholder is asked to confirm.

The share of transactions that clear frictionlessly is the single number that separates one 3DS authentication solution from another, because every challenge is a point where a buyer can drop out.

Key Benefits of Flexible 3D Secure Authentication for Businesses

DECTA's EMV 3DS 2.3.1.1 implementation delivers clear benefits worth considering for businesses:

Enhanced Security and Fraud Prevention

DECTA's 3DS authentication solution provides comprehensive fraud prevention for card-not-present (CNP) fraud through:

  • Transaction history and device fingerprinting, which identify the browser or handset behind a transaction and flag when a familiar card appears on an unfamiliar device
  • Real-time fraud detection using machine learning algorithms
  • Liability shift from merchants to issuer banks, which moves the chargeback cost of fraudulent authenticated transactions off the merchant and is the commercial reason merchants accept any authentication friction at all
  • Risk scoring and fraud mitigation logic at both authorization-level and transaction-level fraud management

Improved Transaction Approval Rates and Fewer False Declines

DECTA's 3DS enables greater approval rates by providing cardholder issuers with additional data, reducing false declines and supporting real-time authentication with low-friction challenge flow and frictionless flow.

Regulatory Compliance

EMV 3DS 2.3.1.1 authentication at DECTA achieves compliance with PSD2, the EU regulation that makes Strong Customer Authentication (SCA) mandatory for most online card payments, and with the European Banking Authority (EBA) technical standards that define how SCA is applied.

It also supports the SCA exemptions that let a transaction skip the challenge legally: low-value payments, transaction risk analysis, where a provider's own fraud rate determines the exemption ceiling it can claim, and recurring payments.

Reduced Cart Abandonment

DECTA's SCA-approved frictionless authentication reduces cart abandonment by:

  • Minimizing authentication steps for low-risk transactions
  • Ensuring a seamless user experience
  • Reducing average authentication time

White-Label Customization Capabilities

With DECTA's white-label payment gateway, merchants, PSPs, and acquirers can offer white-label 3DS authentication under their own brand, so the authentication screen never breaks the checkout experience with a third party's name on it. Branded authentication covers:

  • Consistent user interface (UI) design
  • Control over authentication screens based on transaction type
  • Application ecosystem integration
  • Customizable customer-facing elements

Technical Architecture and Integration Advantages

DECTA's technical architecture is designed for EMV 3DS integration across issuer and acquirer services. The sections below set out the integration methods and support for advanced authentication flows.

3DS Authentication Architecture

DECTA's platform provides 3D Secure v2.2 support for issuer services and acquirer services, complying with PSD2 SCA and integrating with a wide range of card systems, payment methods, and acquirer processing options.

Integration Options for 3DS Authentication

DECTA's white-label payment gateway supports:

  • Hosted Payment Page, where the gateway hosts the checkout and authentication entirely, keeping card data off the merchant's servers
  • iFrame integration, which keeps the checkout inside the merchant's own page while the gateway handles the card fields
  • Direct Post, which sends card data straight from the browser to the gateway and reduces PCI scope
  • API integration
  • E-commerce plugins
  • SOAP integration

All integrations are PCI DSS-compliant and compatible with digital wallets, including Apple Pay, Google Pay, Samsung Pay, and Garmin Pay.

Those wallets carry their own tokenized authentication path rather than a standard challenge screen.

Acquirer-Side 3DS Implementation

DECTA applies the latest 3DS 2.x protocol for acquirer processing, supporting SCA exemptions, challenge flow, frictionless flow, tokenization, EMV tokenization, and secure cardholder data handling during transaction processing.

EMV tokenization: replaces the card number with a scheme-issued token so the real number is never exposed during authentication or processing.

Fraud monitoring and risk scoring are integrated at both authorization and transaction levels.

Issuer-Side 3DS Implementation

DECTA offers issuer banks 3DS v2.2 support, meeting Mastercard and Visa requirements.

Authentication flows support in-band and out-of-band (OOB) authentication, push notifications, SMS notifications, biometric authentication apps (iOS, Android), card registration, smartphone registration, and card lifecycle management via issuing API.

Out-of-band (OOB) authentication: the cardholder confirms in a separate banking app rather than on the checkout page, which is the mechanism behind biometric approval and Mastercard's biometric prompt requirements.

APIs allow rapid integration and token provisioning for digital wallets, with extensive API documentation available.

Testing, Security, and Compliance

  • Sandbox environment for full testing parity with live services and API documentation at dapidocs.decta.com, so authentication flows can be tested end to end before any integration is committed
  • PCI DSS Level 1 infrastructure for all payment authentication and processing
  • EMV tokenization for cardholder data security
  • 24/7 technical support
  • Built-in fraud monitoring and fraud reporting tools

With DECTA's EMV 3DS 2.3.1.1, businesses achieve security, compliance, customer satisfaction, and higher conversion rates in online payments and mobile payments.

Talk to DECTA About Your Setup

DECTA works with PSPs, acquirers, and issuers on payment authentication, processing, and compliance across Europe and APAC.

Talk to DECTA