Skip to main content
The EU’s PSD2 (Payment Services Directive) requires Strong Customer Authentication (SCA) for online card payments. 3D Secure 2 (3DS2) satisfies the SCA requirement by verifying the cardholder’s identity during the transaction. PCI Booking handles the 3DS2 flow on your behalf, so you can add frictionless authentication to your payment process without building the 3DS integration yourself.

Before You Start

  • You only collect cards and someone else charges them. Set ThreeDS=true on the capture request. Nothing else is needed.
  • You charge the cards. Register your merchant details first, or one row per merchant if you charge for several. See 3DS Merchant Setup.
Without your own merchant details, 3DS runs under PCI Booking’s default merchant, which covers Visa and Mastercard only.

How PCI Booking Handles 3D Secure

The SCA-relevant case for PSD2 is capturing the card directly from the cardholder: using the Hosted Card Entry Form, the entire integration is one parameter - add ThreeDS=true to the request. PCI Booking triggers the 3DS2 challenge automatically during card capture, the cardholder authenticates in-session (satisfying SCA), and you receive the fully authenticated token in the callback. No call sequence or separate endpoint is needed for this path - in particular, store-3d-token is a different, unrelated endpoint (only for attaching a 3DS result obtained outside PCI Booking) and isn’t needed here. PCI Booking also supports 3DS data arriving via other routes (a third party’s own MPI, or extracted in-transit from a Tokenization on Request/Response payload) - see 3DS Auth Management for the full set of ways 3DS data can end up on a token, and how it’s used automatically afterward. To configure your 3DS merchant details, follow the 3DS Merchant Setup guide.

Cards You Already Store

A token stored without 3DS data does not get it later on its own. To add 3DS data, capture the card again with ThreeDS=true, using the Hosted Card Entry Form or Card By Link. This creates a new token, so delete the old one afterward. If a third party authenticated the cardholder, attach their result to the existing token with Store 3DS Authentication.

Try It Live

The card entry form demo runs this flow on a hotel checkout page: card capture with 3D Secure, then a charge. The complete checkout example has the HTML and server code for the same flow.

Test Cards

Use PCI Booking’s 3D Secure test cards to exercise all four authentication flows (frictionless, device fingerprint, challenge, and combined). The full card list with OTP codes is maintained in Testing and Going Live.

Frequently asked questions

Does PCI Booking handle the 3DS challenge flow automatically?

Yes. When you use the Hosted Card Entry Form with 3DS enabled, PCI Booking manages the entire 3DS2 flow including device fingerprinting and challenges. Your system receives the final authentication result.

Can I use 3DS with cards received from an OTA?

Yes. If the OTA has already completed 3DS authentication, you can store the authentication data alongside the card token using the Store 3DS Authentication endpoint.