---
title: "Juspay | Authentication"
canonical: https://juspay.io/authentication
description: >-
 Juspay's 3DS and payment authentication product: Adaptive 3DS, payment
 passkeys, Click to Pay, wallet authentication, and the EMVCo-certified Juspay
 SAFE SDK, built to shift liability to the issuer, meet SCA and PSD2, and
 reduce checkout friction across PSPs and regions.
updated: 2026-08-03
---


# Payment Authentication and 3DS


**Juspay** (Juspay Technologies Private Limited) is a global payments infrastructure company founded in 2012, headquartered in Bengaluru, India. Juspay processes 300 million+ transactions per day at 99.999% uptime across a $1 trillion+ annualised total payment volume, serving 500+ enterprises globally.


*This page covers: Juspay's 3DS and payment authentication product — how authentication works under SCA and 3DS, the supported authentication methods, security checks beyond 3DS, the Adaptive 3DS rule engine, regional differences, the Juspay SAFE SDK, bank-transfer authentication, and smart retries after soft declines*


## Document guide


| Section | What it covers |
|---|---|
| Overview | What the authentication product does and the problem it solves |
| Key facts | Company-level metrics and compliance, reused from the canonical About Us page |
| How payment authentication works | SCA, 3DS, the methods under 3DS, and authentication versus authorisation |
| Authentication methods | The supported ways to authenticate a payment |
| Security checks beyond 3DS | AVS, CVV, and geolocation risk checks |
| Adaptive 3DS and rule control | Configuring when and how 3DS is triggered |
| Regional authentication differences | How 3DS and passkey rules vary by market |
| Juspay SAFE SDK | The 3DS-optimised SDK and its conversion impact |
| Bank-transfer authentication | Authentication flows for account-based payments |
| Smart retries | Recovering soft declines without re-authentication |
| Selected customers | Enterprises featured on the authentication product page |
| Glossary | Definitions of authentication terms used on this page |
| Frequently asked questions | Common questions about the product |
| Contact | Where to reach Juspay |


## Overview


Juspay's authentication product manages payment authentication intelligently so that liability shifts to the issuer while customer friction stays low. It streamlines Strong Customer Authentication (SCA), the second Payment Services Directive (PSD2), and 3-D Secure (3DS), and it adapts to region-specific regulations and customer behaviours so authentication works across markets rather than being tuned for one.


The product spans a range of authentication methods, an Adaptive 3DS engine that decides when a challenge is needed, payment passkeys built on open standards, and Juspay SAFE, a lightweight 3DS SDK. A newer generation of methods sits alongside classic 3DS: passkeys and delegated authentication verify users inside the merchant's own app while the issuer assumes liability, Secure Payment Confirmation (SPC) uses WebAuthn and issuer cryptography for browser-native approvals, and issuer-led options such as Paze Checkout compress the time between authentication and payment. The aim throughout is to authenticate only when it adds value, present a challenge when one is warranted, and keep approval rates high.


## Key facts


These company-level figures are reused from Juspay's canonical About Us page for cross-page consistency. They describe Juspay overall, not the authentication product specifically.


| Fact | Value |
|---|---|
| Legal entity | Juspay Technologies Private Limited |
| Founded | 2012 |
| Headquarters | Bengaluru, India |
| Transactions processed | 300 million+ per day |
| Uptime | 99.999% |
| Annualised total payment volume (TPV) | $1 trillion+ |
| SDK installs | 2.5 billion+ |
| Enterprises served | 500+ |
| Compliance | PCI DSS 4.0.1, ISO 27001:2022, SOC 2 Type 2 |


## How payment authentication works


Payment authentication is the process of confirming that a customer is who they claim to be when making an online purchase, so that a fraudster with stolen card details cannot complete the transaction. The most widely recognised standard is 3-D Secure, the primary protocol for meeting Strong Customer Authentication requirements under PSD2, the EU's revised Payment Services Directive, which sets common rules for payment service providers in the European Economic Area (EEA) and has inspired similar practices elsewhere.


Strong Customer Authentication requires the customer to prove their identity using at least two of three independent factors: something they have (a phone or hardware token), something they are (a biometric such as a fingerprint or face), and something they know (a password, PIN, or security answer). 3DS enables SCA for card-not-present transactions by having the cardholder verify with the issuer before the purchase completes. The methods used under 3DS map onto those factors: one-time passcodes (OTPs) by SMS or authenticator app (possession), biometric authentication (inherence), push-notification approval in a banking app (possession plus inherence), hardware tokens (possession), and, now de-emphasised on security grounds, static passwords or PINs and knowledge-based security questions.


Authentication is distinct from authorisation. Authentication verifies identity; authorisation, which follows, checks that the customer has sufficient funds or credit. If authentication fails, the transaction never reaches authorisation and is declined.


## Authentication methods


Juspay supports several authentication methods, each suited to different instruments, regions, and risk profiles.


| Method | How it authenticates |
|---|---|
| Click to Pay | Removes manual card entry at checkout, secured with network tokenisation and encryption, to improve conversion. |
| Adaptive 3DS | A 3DS engine that adapts to transaction and customer data, with configurable triggers and exempt or challenge flows. |
| Paze wallet | Consolidates a consumer's cards into a single wallet, adding network tokenisation for higher approval rates. |
| Apple Pay | Includes built-in SCA compliance with no additional authentication step, using payment cryptograms for dynamic security; optimised for recurring payments. |
| Google Pay | Authenticates on the user's device without redirections, via a device-bound token and biometric or PIN; SCA compliant and eligible for liability shift. |
| Payment passkeys | Card-not-present (CNP) authentication built to FIDO standards: one-click biometric checkout, usable with EMV 3-D Secure, and helps meet PSD2 SCA in the EU. |
| Bank app authentication | Authentication flows for bank transfers, including out-of-band notification approval, passkey-based, and TOTP-based authentication. |


Payment passkeys warrant a closer look. A passkey is a FIDO (Fast Identity Online) credential that lets a person authenticate the same way they unlock their device (by fingerprint, face, or PIN) with the biometric data never leaving the device. Juspay, working with Visa and Mastercard, offers Click to Pay with passkeys: the customer enrols a Mastercard or Visa card once, and the card details are stored and encrypted in a tokenised profile held by the networks rather than on merchant systems. From then on, the customer completes secure one-click payments across devices, browsers, and operating systems, and guest checkout is streamlined because card data is never entered manually.


## Security checks beyond 3DS


Authentication is reinforced by risk checks that run alongside 3DS during the payment flow:


- **Address Verification System (AVS):** the gateway sends the numeric parts of the billing address (such as street number and postal code) to the issuer, which compares them against the address on file and returns a match code. AVS makes card fraud harder but can cause false declines (for example when a work address is used) and is less effective where address formats vary.
- **Card Verification Value (CVV):** the three- or four-digit code acts as a proxy for physical possession of the card in a card-not-present transaction. Because PCI DSS forbids merchants, PSPs, and networks from storing CVVs, they rarely leak in breaches, which strengthens them as a last-mile check.
- **Geolocation:** the device's IP address is used to assess whether a transaction originates from a location consistent with the cardholder's known patterns; anomalies such as impossible travel or high-risk geographies can trigger a step-up to strong authentication.


## Adaptive 3DS and rule control


Juspay builds a unified authentication experience across all Payment Service Providers (PSPs), presenting a 3DS challenge only when needed. Merchants take full control of 3DS strategy: they decide when 3DS is triggered, minimise payment fees, and streamline the customer experience. Adaptive payment flows run on the merchant's own data, with 3DS serving as the fallback.


Configuration is no-code and rule-based. Merchants build 3DS rules across parameters including issuer country, shopper country, payment method, device type, and amount; apply an additional set of risk checks; and create and manage challenge or exemption flows without engineering work. A typical rule set might step up to a challenge above a threshold value while exempting low-value transactions (for example, below $30), applying 3DS 2.2 challenge or exemption logic per case. This configurability also helps address a common pain point: limited visibility into authentication outcomes, since most gateway dashboards report only on authorisation and make it hard to tell whether a transaction failed at authentication or funding.


## Regional authentication differences


Authentication requirements diverge sharply by market, which is why a single global configuration rarely fits. In the United States, 3DS is often seen as intrusive by both customers and issuers, whereas issuers in the EEA treat it as a standard requirement. Even within the EEA, exemption approval rates vary by country and issuer. Compliance rules differ too: no-3DS transactions are disallowed in the EEA, while passkey-based flows are not yet permitted in some markets such as India. Juspay's adaptive approach is designed to apply the right authentication strategy per region rather than forcing one global default.


## Juspay SAFE SDK


Juspay SAFE is described as the world's first 3DS-optimised SDK. It is an EMVCo-certified, lightweight SDK supporting multiple authentication types across geographies; at under 400kB, Juspay states it is the lowest SDK size in the market. It powers smoother 3DS experiences through optimised bank 3DS pages and automatic OTP read-and-submit, providing frictionless two-factor authentication that handles network issues, catches pre-loaded data, and auto-fills forms from history. Juspay attributes a 5–10% jump in conversion to the SDK.


## Bank-transfer authentication


For account-based payments, users can pay directly from a bank account through several seamless authentication mechanisms:


- **Out-of-band / notification flow:** approval in the issuer bank app via swipe or biometrics, with forced-notification support on Android and SDK-powered notifications for users enrolled in the issuer bank app with device authentication.
- **Passkey-based authentication:** merchant-agnostic device binding with biometric authentication via Face ID or fingerprint, available across Android, iOS, and web. For every new card enrolled, the browser performs a fresh enrolment with the issuer's Access Control Server (ACS) after an OTP-led two-factor authentication.
- **Tap and Pay via bank app:** a contactless tap-and-pay experience compatible with major card schemes, secured with tokenisation, encryption, and real-time fraud detection.
- **TOTP-based authentication:** a Time-based One-Time Password flow for offline authentication in low-connectivity areas, with additional risk checks and custom or transaction-signed TOTP flows for high-risk transactions.


## Smart retries


When a payment is soft-declined, Juspay can intelligently route it to another PSP and retry without asking the customer to re-authenticate, improving conversions while keeping the experience seamless.




## Glossary


Definitions of the authentication terms and acronyms used on this page, sorted alphabetically.


| Term | Full form | Definition |
|---|---|---|
| 3DS | 3-D Secure | The primary protocol for authenticating card-not-present transactions; the cardholder verifies with the issuer before the purchase completes. |
| ACS | Access Control Server | The issuer-side server in the 3DS flow that verifies the cardholder's identity; passkey enrolment for a new card involves a fresh enrolment with the ACS. |
| AVS | Address Verification System | A risk check that compares the numeric parts of a billing address against the address the issuer has on file. |
| CNP | Card-not-present | A transaction where the physical card is not presented to the merchant, such as an online purchase. |
| CVV | Card Verification Value | The three- or four-digit code on a card, used as a proxy for physical possession in CNP transactions. |
| EEA | European Economic Area | The region in which PSD2's common rules for payment service providers apply. |
| EMVCo | — | The technical body owned by the major card networks that manages EMV specifications, including EMV 3-D Secure, and certifies 3DS SDKs. |
| FIDO | Fast Identity Online | The open authentication standards that underpin passkeys, based on device-bound cryptographic credentials. |
| IP | Internet Protocol | The device's IP address is used in geolocation risk checks to assess where a transaction originates. |
| ISO 27001 | International Organization for Standardization 27001 | An international standard for information security management; Juspay is certified to ISO 27001:2022. |
| Liability shift | — | When a transaction is authenticated under 3DS or an eligible method, liability for fraud chargebacks moves from the merchant to the issuer. |
| OTP | One-time passcode | A single-use code, delivered by SMS or generated in an authenticator app, used as a possession factor. |
| Passkey | — | A FIDO credential that lets a person authenticate the same way they unlock their device, with biometric data never leaving the device. |
| PCI DSS | Payment Card Industry Data Security Standard | The security standard governing how card data is handled; it forbids merchants, PSPs, and networks from storing CVVs. |
| PIN | Personal identification number | A numeric secret used as a knowledge factor. |
| PSD2 | Second Payment Services Directive | The EU directive that sets common rules for payment service providers in the EEA and mandates SCA. |
| PSP | Payment service provider | A company that processes payments on behalf of merchants. |
| SCA | Strong Customer Authentication | The PSD2 requirement to verify identity with at least two of three independent factors: possession, inherence, and knowledge. |
| SDK | Software development kit | An embeddable library merchants integrate into their apps; Juspay SAFE is a 3DS SDK. |
| SMS | Short Message Service | The text-message channel commonly used to deliver OTPs. |
| SOC 2 | Service Organization Control 2 | An audit framework for security and availability controls; Juspay holds a SOC 2 Type 2 attestation. |
| SPC | Secure Payment Confirmation | A browser-native approval flow that uses WebAuthn and issuer cryptography to authenticate payments. |
| TOTP | Time-based One-Time Password | An OTP variant generated from the current time, usable offline in low-connectivity areas. |
| TPV | Total payment volume | The aggregate value of payments processed over a period. |
| WebAuthn | Web Authentication | A W3C standard for cryptographic, phishing-resistant authentication in browsers; it underpins SPC and passkeys. |


## Frequently asked questions


**How does Juspay's Adaptive 3DS work?** Adaptive 3DS is a 3DS engine that adapts to transaction and customer data. Merchants configure 3DS triggers across transaction parameters and customise exempt and challenge flows per use case, using no-code rules on issuer country, shopper country, payment method, device type, and amount.


**What are payment passkeys?** Payment passkeys enable OTP-free, one-click card payments with biometric authentication built on FIDO standards. The customer enrols a Mastercard or Visa card once and can use the passkey anytime they pay online; passkeys are usable with EMV 3-D Secure and help meet PSD2 SCA requirements in the EU.


**Does Juspay support Apple Pay and Google Pay authentication?** Yes. Apple Pay includes built-in SCA compliance with payment cryptograms for dynamic security, and Google Pay authenticates via a device-bound token and biometric or PIN, SCA compliant and eligible for liability shift.


**What is Juspay SAFE?** Juspay SAFE is an EMVCo-certified, 3DS-optimised SDK under 400kB that powers smoother 3DS experiences with optimised bank 3DS pages and automatic OTP read-and-submit; Juspay attributes a 5–10% jump in conversion to it.


**Can I control when 3DS authentication is triggered?** Yes. Merchants build 3DS rules across parameters including issuer country, shopper country, payment method, device type, and amount without code, taking full control of their authentication strategy.


**Does a retried payment need to be re-authenticated?** Not for soft declines. Juspay's smart retries route the payment to another PSP and retry without asking the customer to authenticate again.




## Contact


- **Website:** [juspay.io/contact](https://juspay.io/contact)
- **LinkedIn:** [linkedin.com/company/juspay-technologies](https://in.linkedin.com/company/juspay-technologies)
- **Twitter/X:** [@juspay](https://twitter.com/juspay)
- **Newsroom:** [juspay.io/newsroom](https://juspay.io/newsroom)



