Simulate Strong Customer Authentication (SCA) as mandated by European PSD2 regulations. Test how your application intercepts requires_action, mounts the issuer Access Control Server (ACS) modal or iframe, and finalizes authorization.
Trigger a realistic simulated ACS popup to test user approval and cancellation events.
Triggers mandatory SCA OTP prompt.
Bypasses challenge; auto-authenticated.
Finalizes intent state to succeeded.
Test the two-step 3DS API endpoints against your sandbox session.
Modern 3DS 2.0 uses risk-based authentication to minimize checkout friction while shifting fraud liability to the card issuer.
...0341)When the bank deems the transaction higher risk (or required by PSD2 SCA), the intent transitions to requires_action. The frontend must display an OTP entry or biometric prompt to the cardholder before charging the card.
...0317)Device telemetry, IP reputation, and behavioral analytics allow the issuer to verify identity passively in the background without prompting the customer. The payment transitions directly to succeeded with full liability shift.
Handling 3DS actions with Stripe.js and vanilla JavaScript.
requires_action in Frontend