Challenge Flow

Challenge Flow Characteristics

User is prompted to verify their identity via OTP, biometric, or app approval.

Used when:

  • Higher-risk transaction
  • Regulatory requirements
  • New device or unusual behavior

Common Challenge Methods:

  • One-time passcode (OTP)
  • Push notification to banking app
  • Biometric verification (face/fingerprint)

Sequence:

  1. Merchant sends authentication request.
  2. Issuer identifies higher risk.
  3. User is presented with challenge UI.
  4. User completes challenge and transaction continues.

3DS 2 Challenge Flow


3DS Challenge flow: customer perspective