Security

3DS fallback

Issuer soft declines and access control server timeouts can interrupt authentication before authorisation. 3DS soft decline recovery keeps the payment session active through real-time response interpretation, timeout handling and automated step-up authentication triggers.

Category
Security
Capabilities
6
Available on
All plans
Apply now

Payments engineering teams face systemic revenue loss when issuers reject authentication attempts through soft declines or access control server timeouts. Rather than abandoning the transaction upon encountering an error code, operators require a mechanism to intercept the issuer response and present a challenge to the cardholder immediately.

Cardflo orchestrates auth failover handling by programmatically interpreting issuer soft decline codes in real time. The gateway intercepts these rejection signals and instantly initiates a step-up challenge window, prompting the buyer to authenticate through a biometric check or one-time passcode to salvage the payment session before the authorisation attempt expires.

PCI scope is minimised through hosted fields and network tokens, and sensitive credentials never touch your servers. Strong Customer Authentication is applied intelligently to keep both regulators and conversion teams happy.

3DS fallback overview

Engineers responsible for payment conversion metrics require systemic auth failover handling to capture revenue that would otherwise be lost to technical errors. When an issuer rejects an authentication request with a soft decline code, the merchant system must immediately pivot to a step-up challenge rather than failing the transaction entirely.

Cardflo provides the orchestration logic to interpret access control server responses, manage timeout recovery strategies and re-route the buyer to an active authentication session.

This functionality specifically addresses the mechanical process of recovering from an issuer rejection, which differs entirely from initial exemption requests covered by SCA-optimisation, the payload data required for frictionless-3DS, or the routing decisions executed by smart-3DS-routing.

By mapping issuer-specific error codes to automated step-up authentication triggers, merchants ensure that a temporary technical failure at the issuer level does not result in a lost payment session.

How 3DS fallback works

  1. Intercepting issuer decline responses

    The gateway monitors the real-time response from the access control server following the initial authentication request. If the issuer returns a soft decline error code indicating that a challenge is mandatory, Cardflo intercepts the payload. This programmatic intervention stops the merchant platform from marking the transaction as failed and instead holds the session open for further action.

  2. Initiating the step-up challenge

    Upon detecting the soft decline, the system activates automated step-up authentication triggers to present a challenge window to the user. The buyer completes the required validation, typically via an active banking application or SMS passcode, satisfying the issuer requirement. This secondary flow occurs within the same payment session to prevent user abandonment during the authentication phase.

  3. Submitting the recovered authorisation

    Once the buyer completes the challenge, Cardflo extracts the required authentication values from the access control server response. The gateway passes these cryptographic elements to the acquirer partner network to proceed with a fully authenticated authorisation request. This final step completes the 3DS soft decline recovery cycle, successfully converting a rejected attempt into a settled payment.

Why 3DS fallback matters

Salvaging legitimate transaction revenue

Issuers frequently reject valid authentication attempts due to technical errors or strict internal risk parameters. Without automated 3DS fallback mechanisms, these soft declines result in immediate lost revenue and frustrated buyers. By programmatically loading a step-up challenge instead of failing the session, merchants capture sales that would otherwise terminate prematurely.

Reducing technical support overhead

Payment engineering teams waste significant resources investigating false declines caused by access control server timeouts. Implementing systematic auth failover handling removes the need for manual intervention when an issuer rejects an attempt. The automated extraction of cryptographic values ensures that the final authorisation proceeds without developers having to write custom error-handling logic for every issuer.

Regulatory notes for 3DS fallback

Compliance with European scheme rules

Under current European regulations, issuers hold the final authority over authentication decisions and can mandate a challenge at any time. When an issuer issues a soft decline, the merchant must respect this decision by presenting a compliant step-up interface.

Failure to accommodate these responses leads to scheme penalties and elevated abandonment rates.

The Cardflo gateway ensures that all 3DS fallback mechanisms meet the technical standards defined by the major card schemes.

By capturing the resulting authentication values and passing them to acquirer partners, merchants remain fully compliant with regional mandates while successfully authorising transactions that the issuer initially blocked.

Cryptographic evidence for chargeback defence

To qualify for liability shifts under scheme rules, merchants must provide cryptographic evidence that the cardholder successfully completed an authentication challenge.

When a transaction requires auth failover handling, the system must precisely capture the authentication values generated by the issuer access control server following the step-up phase.

Submitting these exact cryptographic elements within the final authorisation payload is mandatory for maintaining fraud dispute protection.

The orchestration logic parses the secondary challenge response to extract these values, ensuring that even transactions recovered from an initial soft decline remain fully protected against fraudulent chargeback claims.

3DS fallback use cases

Soft decline step-up recovery

Card payments returning issuer soft decline codes require customer authentication rather than another unchanged authorisation attempt, yet inconsistent response mapping can cause recoverable orders to fail. Cardflo identifies eligible codes, initiates a 3DS2 challenge and resubmits the payment with the resulting authentication data.

Challenge window launch failures

A cardholder may accept an issuer step-up, but blocked frames, lost browser context or failed redirects can prevent the access control server challenge from opening. Cardflo supports controlled challenge launch, preserves transaction references and records technical outcomes so payments engineers can distinguish presentation failures from issuer rejections.

Issuer challenge timeout recovery

Issuer challenge sessions can expire while a cardholder completes an app-based biometric prompt, leaving the merchant without a conclusive authentication result. Cardflo applies bounded timeout handling, checks the returned 3DS status and permits a controlled authorisation attempt only when the authentication outcome supports it.

Mobile app step-up handoff

In-app card payments can lose state when an issuer moves the cardholder into a banking app or browser for step-up authentication. Cardflo maintains the 3DS transaction identifiers across the handoff, processes the callback and returns a definitive result to the merchant application before authorisation resumes.

3DS fallback by the numbers

85-95%
Authentication Success Range

Typical authentication success rates when fallback is enabled, as it captures transactions from issuers lacking modern protocol support.

15-25%
Reduction in Technical Errors

The estimated decrease in technical declines observed by merchants when implementing automated versioning and fallback logic.

<500ms
Fallback Latency

The standard processing overhead for the gateway to switch protocols, excluding the time taken for the cardholder to interact with the challenge.

Methodology: these figures are illustrative ranges drawn from published industry data and observed merchant cohorts, not guarantees. Actual results depend on your risk profile, card mix, geography and acquiring setup, and are confirmed only in your own pricing and approval terms.

Ready to route with 3DS fallback?

Talk to our team about a live rollout across our acquirer partners' rails.

Apply now

What you get with 3DS fallback

  • Maps issuer soft decline codes to automated step-up authentication triggers without requiring manual engineering intervention.
  • Intercepts access control server timeouts to instantly load alternative challenge windows for the cardholder.
  • Bypasses authentication errors by parsing the issuer response payload to determine the exact failure reason.
  • Captures cryptographic validation values from successful step-up challenges to submit alongside the final authorisation request.
  • Manages auth failover handling for cross-border transactions where regional issuers enforce strict strong customer authentication.
  • Triggers fallback mechanisms automatically when the primary authentication pathway returns a system failure error code.
See 3DS fallback live across our acquirer partners.

A short scoping call, then a written plan for your MIDs.

Apply now

Questions about 3DS fallback

How do platforms recover soft declines during an authentication timeout?

When an access control server fails to respond within the required timeframe, the gateway registers a technical timeout. Cardflo manages timeout recovery strategies by intercepting the failure code before the merchant system drops the session.

The orchestration layer then initiates a fresh challenge window, allowing the cardholder to complete the authentication step manually. This immediate pivot prevents a total transaction failure and provides the issuer with the cryptographic proof required to authorise the payment request.

What initiates a step-up authentication prompt?

Step-up authentication triggers activate when the issuer explicitly rejects an initial attempt and returns a soft decline error code. The issuer access control server signals that the cardholder must verify their identity to proceed.

Cardflo parses this response payload and automatically surfaces the required challenge interface to the buyer. This ensures that the transaction remains active while the buyer completes the necessary biometric scan or passcode entry required by their banking provider.

How does auth failover handling work across different devices?

Auth failover handling relies on device-responsive challenge windows that adapt to the buyer platform. If a soft decline occurs on a mobile application, the gateway triggers an out-of-band authentication prompt, typically opening the user banking app.

For desktop sessions, the fallback mechanism displays an inline challenge frame. Cardflo manages the transition between the initial decline and the subsequent step-up prompt to ensure the session remains active regardless of the hardware used by the consumer.

Which error codes indicate a soft decline?

Issuers return specific indicator codes in their authentication response payload to signal a soft decline. These codes generally specify that the transaction requires step-up authentication to proceed safely.

The Cardflo gateway maps these varied issuer-specific error formats into a standardised response framework. By correctly interpreting these signals in real time, the system knows exactly when to deploy 3DS soft decline recovery tactics rather than treating the response as a terminal hard decline.

Apply with Cardflo

Ready to improve your payments setup?

Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.

Apply now
Apply now