- Embed automatically detects 3-D Secure for a transaction and handles all the user interactions to complete the transaction.
- Hosted 3DS offers 3-D Secure via the API, allowing capture of card data that then relies on the hosted 3-D Secure to handle the user interaction. This can also be used in combination with Secure Fields.
- Native 3DS provides a fully customizable 3-D Secure experience built directly into your app. Available for web (Secure Fields), iOS (Swift), and Android (Kotlin). Requires merchant account-level 3DS configuration.
- External 3-D Secure data can be passed in to create a card checkout experience including a custom 3-D Secure integration.
Authentication and capture
3-D Secure authenticates the buyer. It doesn’t capture the payment. The transaction’sintent controls
capture. With an intent of authorize, call the capture endpoint once the transaction reaches
authorization_succeeded, including after a 3-D Secure redirect or challenge.
Store a card with 3-D Secure
3-D Secure runs as part of a transaction. Creating a payment method with the create payment method endpoint doesn’t run 3-D Secure, and neither does storing a card in a checkout session. To authenticate a card when you store it, create a transaction with anamount of 0 and store set to true, for example through Embed or Secure Fields.
Failed authentication
When the authentication result isN, the buyer failed authentication
or the issuer denied the transaction. Gr4vy declines the transaction without sending it for authorization,
so the buyer’s bank shows no failed payment. The buyer can try again or use another card.
The exception is N with reason 87, which means the card is excluded from attempts processing. With
Attempt 3DS, continue if not enrolled, the transaction continues without 3-D Secure. With
Force 3DS, decline if not enrolled, it’s declined. See
3-D Secure outcomes for each case.
Issuer-mandated 3-D Secure
This feature is available in most environments, but not all. Contact the
support team to confirm availability for your account.
- No rule matches, or no 3-D Secure rule is configured. Gr4vy attempts 3-D Secure. This is unchanged from the standard behavior.
- A rule skips 3-D Secure. For an issuer with a known mandate, Gr4vy overrides the rule and attempts 3-D Secure instead. Cards without a known mandate continue to skip.
- A rule forces 3-D Secure. Gr4vy forces 3-D Secure for all cards. This is unchanged.
Digital wallets
Gr4vy doesn’t run 3-D Secure for Apple Pay, Paze, and Google Pay device tokens. The wallet authenticates the buyer, and the payment carries a cryptogram instead of a 3-D Secure result. Google Pay can also return a card saved in the buyer’s Google Account (PAN_ONLY) rather than a device
token (CRYPTOGRAM_3DS). Gr4vy processes these cards like any other card, so 3-D Secure can apply. See
3-D Secure with Google Pay.