Skip to content
3-D SECURE · NATIVE ACS · EMV 3DS 2

Strong authentication.
Weak friction.

Rigid runs its own ACS, wired directly to Fraud AI. Most challenges never happen because the risk data answers silently. When one is needed, it is a passkey tap in your app, not an SMS code, and the result is recorded against the authorization it protects.

FRICTIONLESS
88%
FRICTIONLESS
MEDIAN CHALLENGE
1.8s
MEDIAN CHALLENGE
APPROVAL RATE
+2.3pt
APPROVAL RATE
Confirm paymentrigid 3DS

aerolineas.com

€412.90

**** 4921 · Ember Credit

Confirm with your passkey

PSD2 SCA · PASSKEY · OTP fallback available

RISK 0.41 → STEP-UP

Passkey passed · 1.8s

HOW A CHALLENGE FLOWS

One risk decision, from checkout to ledger.

Because the ACS and the authorization engine are the same platform, the authentication and the approval are one story about one transaction.

01

The merchant asks

An e-commerce checkout sends an EMV 3DS authentication request through the directory server to Rigid's ACS, with device, browser and merchant data attached.

02

Fraud AI answers first

The same models that score the authorization score the authentication, in-line, using the cardholder's history and the transaction's risk. Most requests end here, frictionless.

03

Step up only when it matters

Ambiguous or high-risk requests get a challenge: a passkey approval in your app, branded as you, or a one-time code when the cardholder has no app. Decoupled authentication when the cardholder is not at the checkout.

04

The result rides the authorization

The authentication value travels with the authorization, so approval, liability shift and the challenge outcome are recorded against the same transaction and the same ledger entry.

RISK-BASED AUTHENTICATION

The best challenge is no challenge.

Fraud AI's score decides the path in-line. Clean traffic goes through on risk data alone; only genuinely ambiguous authorizations ever see a challenge. The mix below is a typical programme after 30 days of adaptive tuning.

Frictionless · approved on risk data88%
Passkey step-up · in your app10%
OTP fallback · no app installed2%

Typical programme mix after 30 days of adaptive tuning

SCA EXEMPTIONS

Every exemption the regulation allows, applied per market.

Under PSD2 a compliant programme is one that challenges when it must and never when it need not. Rigid tracks the counters and thresholds each exemption depends on, per card, so you can use them to the limit.

Low valueUnder €30, with cumulative and count limits tracked per cardIssuer or acquirer
Transaction risk analysis (TRA)Below the reference fraud rate thresholds at €100, €250 and €500Issuer or acquirer
Trusted beneficiaryMerchants the cardholder has allow-listed, managed from your appIssuer
Recurring and merchant-initiatedSubscriptions and MITs after the first authenticated paymentOut of SCA scope
Secure corporate paymentsDedicated corporate processes and protocolsIssuer
Delegated authenticationWallets and merchants authorised to authenticate on the issuer's behalfIssuer
WHO FEELS THE DIFFERENCE

For the cardholder

  • No SMS codes typed from another screen
  • A tap they already know from unlocking their phone
  • Fewer false declines on legitimate purchases abroad

For the issuer

  • One fraud decision across authentication and authorization
  • Exemptions used to the limit regulation allows
  • Liability shift evidence attached to every transaction

For the merchant

  • Higher approval rates with the same protocol they already run
  • Fewer abandoned checkouts at the challenge step
  • Consistent behaviour across your programmes and markets
FAQ

3-D Secure, answered

What is an ACS and why does the issuer run it?

The access control server is the issuer's side of 3-D Secure: it decides whether to authenticate a cardholder frictionlessly or to challenge them, and it produces the authentication value the merchant sends with the authorization. When the ACS and the authorization engine share one risk score and one data set, the decision is better and there is nothing to reconcile.

Is 3-D Secure the same as strong customer authentication?

3-D Secure is the protocol; strong customer authentication is the PSD2 requirement. EMV 3DS 2 is the standard way to satisfy SCA for card payments online, and its risk-based authentication and exemption framework are what keep most payments frictionless while staying compliant.

Which challenge methods are supported?

Passkeys (Face ID, fingerprint or device PIN) inside your app as the default, with a one-time code fallback for cardholders without the app, and decoupled authentication for cases where the cardholder is not at the checkout.

Which versions of the protocol are supported?

EMV 3-D Secure 2.2 and 2.3 across app-based, browser and 3RI flows, with graceful handling of merchants and acquirers on older versions.

WHO BUILDS ON IT

Who 3-D Secure is for, and what they get.

The same platform, used differently by different teams. Each card names the segment, the outcome, and the products that carry it.

Neobanks & consumer fintechs

A branded card in weeks, with onboarding your compliance team runs

Virtual cards tokenized to Apple Pay and Google Pay on day one, KYC flows configured per programme, Fraud AI on every tap, and disposable cards for subscriptions and privacy.

Banks & EMIs with a core

Keep your ledger and your decision, replace the network side

Gateway mode asks your endpoint for every authorization and posts instructions back to your books. Stand-in processing keeps cards working inside limits you declare when your core is unreachable.

Credit & BNPL programmes

Credit and prepaid on the same rails, with SCA handled

Debit, prepaid and credit account ranges on Visa and Mastercard, 3-D Secure with exemptions applied per market, and Fraud AI that sees the whole programme, not one card at a time.

See a challenge you'd actually approve of.

Live demo: the same transaction through the frictionless, passkey and OTP paths, and the ledger entry each one leaves behind.