Skip to main content
On this page

Configure 3DS in four layers: eligibility, connection, payment strategy, and shopper experience.

01
Confirm support
Validate the provider, country, card network, and commercial setup.
02
Enable the connection
Choose DEUNA-managed 3DS or a supported provider-managed flow.
03
Apply the strategy
Decide which payments require authentication and which connection processes them.
04
Test the journey
Validate frictionless, challenge, abandonment, timeout, and final-status handling.

1. Confirm eligibility#

Before changing production configuration:

  • Check the connection in the payment gateway catalog.
  • Confirm the countries, card networks, currencies, and transaction operations in scope.
  • Ask your DEUNA TAM to confirm whether DEUNA-managed 3DS, provider-managed 3DS, or both are available for the connection.
  • Confirm whether the issuer challenge can be embedded or requires a top-level redirect.

2. Choose the authentication model#

Your merchant application uses the same pending_3ds and next_action contract for both models. Do not use provider identity to decide how checkout behaves.

Information required for DEUNA-managed 3DS

The exact fields depend on the acquiring connection. Be ready to provide:

ConfigurationDescription
Merchant identifierThe merchant or affiliation identifier registered with the acquirer.
Acquirer BINThe acquiring bank identifier assigned to the merchant setup, when required.
Merchant name and URLThe customer-facing name and secure website URL registered for card acceptance.
Merchant category codeThe MCC assigned to the merchant account.
CountryThe merchant country as an ISO 3166-1 alpha-2 code.

Treat these values as connection configuration. Do not send them from the browser or hard-code them into your client application.

3. Enable 3DS on the connection#

  1. In DEUNA Admin, open Connections.
  2. Select the payment gateway used by the strategy.
  3. Open the connection settings and enable the supported security method.
  4. Select the agreed 3DS model and complete the requested merchant/acquirer fields.
  5. Save the connection, then reopen it and verify that 3DS remains active in the target environment.
Interactive exampleUses sample data and does not make API requests.
Production
Payments

Connections

Discover and manage payment, wallet, and anti-fraud integrations.

Acme LATAM · Production
5 sample connectionsUpdated just now
ConnectionsTypeStatusAction
AdyenPayment gatewayConnected
WorldpayPayment gatewayConnected
PayPalPayment methodConnected
Mercado PagoPayment methodNot connected
RiskifiedAnti-fraud engineNot connected

Connection labels and available fields can differ by provider. The DEUNA capability remains the same: checkout receives a normalized payment state and next action.

4. Apply the payment strategy#

Enabling 3DS on a connection does not by itself define when it should run. In Payment strategies, confirm:

  • which card traffic routes through the 3DS-capable connection;
  • whether authentication is always requested or selected by strategy rules;
  • what happens after authentication succeeds, fails, or cannot be completed;
  • whether retry routing preserves a valid authentication result for a compatible next attempt.
Interactive exampleUses sample data and does not make API requests.
Production
Payments

Payment strategies

Configure default processing and rules for each payment flow.

Acme LATAM · Production

Default processing

Configure default processing and rules for each payment flow.

RuleRoutingStatusAction
Default processingAdyen → WorldpayActive

Specific rules

Configure default processing and rules for each payment flow.

1 sample rulePayment processors
PriorityRuleConditionsRoutingStatus
1High-value ordersAmount over USD 100Adyen → WorldpayActive

See Payment strategies for default, conditional, retry, and risk-routing behavior.

5. Choose the shopper experience#

ProductRecommended implementation
Payment WidgetLet the widget present the supported embedded or redirect challenge and return its lifecycle events.
Payment LinkLet the hosted experience present authentication and use the configured return URL.
Direct APIPrefer a supported DEUNA SDK initNextAction flow. Otherwise, use the returned challenge URL and honor the required presentation mode.
Native appOpen the DEUNA next action in the supported SDK or a secure system web view. Preserve the app return/deep-link path.

Never assume every issuer page can be embedded. Browser security headers, issuer policy, connection support, and account configuration can require a top-level redirect.

6. Production-readiness checklist#

  • Test a frictionless result and verify that no unnecessary shopper step appears.
  • Test a challenge and verify completion, cancellation, back navigation, and app/browser return behavior.
  • Keep pending_3ds unresolved while the shopper is authenticating.
  • Handle challenge expiration and a final denied, cancelled, or expired status.
  • Reconcile the result from signed DEUNA webhooks and the Get order endpoint.
  • Make fulfillment depend on a successful final payment status, not on the challenge screen closing.
  • Confirm the configured sandbox scenarios with your DEUNA TAM; test behavior can vary by 3DS model and payment connection.

Continue with 3DS purchase flow to implement the API and customer-action lifecycle.