3-D Secure is an extra check that the customer's own bank runs on an online card payment before the payment is submitted for approval. It is a standard shared by the card brands, and Clover runs it for you on the payments your store takes online. You may also see it written as 3D Secure, or under a card brand's own name for it.

 

The point of the check is confidence: the bank confirms that the person using the card is the cardholder. When that confirmation succeeds, responsibility for a later fraud chargeback moves to the card issuer, which is covered in 3-D Secure, chargebacks, and liability shift.

 

 

The two things your customer can experience

Your customer will see one of exactly two things. The bank picks which one.

 

What happens What the customer sees
Verified in the background Nothing at all. The bank recognizes the cardholder from the details it already has, and checkout continues exactly as it did before.
One verification step A short window from their bank appears during checkout, usually asking for a one-time code sent by text message, by email, or through their banking app. The customer completes it and checkout continues.

 

Both outcomes are normal. Most payments from familiar cardholders on familiar devices go through in the background.

 

There is one change your customers see on every payment rather than some of them: with 3-D Secure on, Visa requires that customers also provide their cardholder name and email or phone number during checkout, so the payment form collects those through Clover.

 

 

Who decides whether the customer gets the extra step

The card issuer decides, on each payment, using its own risk assessment. That decision is not yours, not ours, and not Clover's, and there is no setting anywhere that forces one outcome or the other.

 

The verification window itself is the bank's own screen. It is not part of your store, so its wording, its look, and the way the code is delivered all belong to the bank. That is also why nobody at your store should ever ask a customer to read out a one-time code: the customer enters it in the bank's own window, and no one else needs it.

 

 

Where the check runs on a WooCommerce store

With both settings on, 3-D Secure runs everywhere your WooCommerce store takes a card through WeeConnectPay: the checkout page, the block-based checkout page (the newer checkout WooCommerce builds from blocks), and the customer payment page a customer reaches from the Pay for this order link in the email for a pending order. It runs in all three transaction modes, Charge at checkout, Hold and charge later, and Order and charge. There is no page where a card payment skips the check, and a verification that fails on the customer payment page is recorded on the order the same way as one that fails at checkout.

 

One step can appear on the customer payment page before the payment form, and it belongs to WooCommerce rather than to the check. A customer who checked out as a guest, and opens the Pay for this order link more than ten minutes after the order was placed from a browser the store does not recognize, is first asked to confirm the order's email address, with the message "To view this page, you must either login or verify the email address associated with the order." They enter the billing email from the order, click Verify, and the payment form appears. A customer signed in to the account that placed the order is not asked. This is WooCommerce's own protection for guest orders, so it appears whether or not 3-D Secure is on.

 

 

Which cards and which countries it covers

3-D Secure support on Clover covers American Express, Discover, Mastercard, and Visa, in the United States and Canada.

 

Whether an individual card takes part still depends on the bank that issued it. A card whose issuer does not participate is simply processed the usual way.

 

 

Verification and approval are two separate steps

Verification answers "is this the cardholder?". Approval answers "will the bank pay for this?". They are separate, and they happen in that order.

 

So a payment can be verified successfully and still be declined afterwards for an ordinary reason such as insufficient funds. In that case the customer sees the usual decline message, "Your card was declined. Please try a different card or contact your bank.", and the payment is treated as a normal decline.

 

3-D Secure also works alongside your other checks rather than replacing them. Card security code and postal code checks keep doing their own job.

 

 

Where you see it on a payment

On your WeeConnectPay dashboard, open Transactions. A payment that went through 3-D Secure carries a small shield marker next to it, and pointing at the shield opens a 3D Secure panel with a Validation line (for example Authenticated) and a Liability line (for example Liability shifted to issuer).

 

Payments taken without 3-D Secure carry no shield, and nothing else about them changes. If none of your payments carry a shield and you expected them to, Turning on 3-D Secure for your store covers the two settings a verified payment needs.