On this page
Delegated Authentication
Delegated Authentication
A mechanism defined in the 3D Secure 2 (3DS2) specification where a merchant or PSP authenticates the cardholder on behalf of the card issuer, then submits proof of that authentication via the 3D Secure 2 (3DS2)|3DS flow. The issuer may accept the claim and grant a frictionless flow without redirecting the shopper to a separate challenge. Delegated Authentication (DA) increases the likelihood of frictionless 3D Secure 2 (3DS2)|3DS outcomes and raises authorisation rates, but does not guarantee them — issuers retain the right to challenge any transaction regardless of a DA assertion.
How it works
EMVCo formally defines Delegated Authentication as a model where issuers transfer responsibility for cardholder authentication to a third party — which may be the merchant or an authorised representative — provided Strong Customer Authentication (SCA - PSD2)|SCA requirements continue to be met (EMVCo 3DS technology page, undated). The merchant or PSP submits the authentication confirmation via the 3D Secure 2 (3DS2)|3DS flow; the issuer accepts the claim. (Rivero, 2026-06-25)
Crucially, the EBA clarifies that while card issuers may outsource the operational provision and technical verification of SCA elements to a third party, the issuer cannot outsource compliance responsibility — the issuer remains fully accountable under PSD2 and the RTS on SCA. (EBA press release, undated)
Responsibility framing: The EBA states the issuer "remains fully responsible" for SCA compliance even under delegated arrangements. Stripe describes delegated authentication as "passing responsibility for authenticating transactions from card issuers to Stripe." These describe operational vs legal responsibility respectively, but the language diverges materially and may create implementation confusion. Sources: EBA press release vs Stripe Newsroom.
DA vs SCA exemptions
Practitioners on r/payments (189 upvotes, 2025-01) describe the distinction: "Exemptions are a request to the issuer saying 'please don't challenge this, we think it's low risk'. DA is saying 'we already authenticated this person, here's the proof'. Issuers are more likely to honor the latter because there's an actual authentication assertion, not just a risk score." (r/payments, 2025-01)
A structural difference: TRA (Transaction Risk Analysis) exemptions have volume caps per PSP tied to a 0.13% fraud rate threshold — if the ecosystem exceeds thresholds, exemptions get pulled. DA does not have the same ceiling and is structurally more robust for scaling. (r/payments, 112 upvotes, 2025-01)
The practitioner benchmarks above (exemption vs DA framing) are from 2025-01. The structural mechanic is confirmed by later sources (Rivero 2026-06-25) but the specific frictionless rate figures should be treated as indicative.
Programme landscape (2026)
Visa programmes
Visa Delegated Authentication (direct merchant certification): Qualifying merchants run the primary SCA verification path themselves under an explicit contractual agreement with the issuer. The merchant submits confirmation via the 3DS flow that SCA was performed. Issuers must formally document three governance structures: the right to decline any merchant, a risk framework governing which merchants receive extended trust, and contractual liability-acceptance logs per merchant and transaction category. (Rivero, 2026-06-25, volatile)
Visa DAF 3DS (Digital Authentication Framework): A prior Visa network-level programme for registered merchant/card-number pairs to skip re-authentication. Sunsets September 2026; no new participants accepted (as-of 2026-06-25). (Rivero, 2026-06-25, volatile)
DAF 3DS vs Delegated Authentication (programme scope): The Rivero source (2026-06-25) makes a sharp distinction — DAF 3DS (sunsetting) is Visa's network-level credential relationship programme, while Delegated Authentication is a separate contractual programme where merchants run the SCA path. Earlier and less precise sources use "delegated authentication" to describe DAF-like frictionless flows interchangeably. Conflation of these two programmes is common in practitioner writing.
Visa Payment Passkey (VPP): Visa's primary succession path from DAF 3DS. A FIDO-based, device-bound authentication method built on public-key cryptography where the private key stays on the cardholder's device and is never transmitted. (Rivero, 2026-06-25)
- Issuer participation requirements effective 18 April 2026 for Europe and AP regions (as-of 2026-06-25, volatile)
- Effective 24 October 2026 for Canada, CEMEA, and LAC regions (excluding Chile) (as-of 2026-06-25, volatile)
Visa Digital Commerce Authentication Program (DCAP): A data-only 3DS flow that passes enriched transaction signals — device identifiers, IP address, full billing address, email — through Visa's network to issuers during authorisation for flows where no 3DS challenge has been triggered. Same effective dates as VPP (18 April 2026 EU/AP; 24 October 2026 Canada/CEMEA/LAC; 18 April 2026 US). The DCAP data-only flow does not carry the liability shift present in a full 3DS-authenticated transaction. (Rivero, 2026-06-25, volatile)
From 17 October 2025, Visa began automatically qualifying transactions for Compelling Evidence 3.0 (CE3.0) through Visa Secure, including Visa Data Only flows; an associated fee for successful CE3.0 qualifications was introduced from 17 April 2026. (Rivero, 2026-06-25, volatile)
Mastercard Identity Check Express: Direct merchant DA certification. Practitioner who implemented it: "Started 9 months ago and still ongoing. Anyone who says they're doing this in under 6 months is either lying or very large and gets preferential treatment." (r/fintech, 234 upvotes, 2025-06)
Mastercard Identity Check Express certification timeline practitioner report is from 2025-06. Programme terms may have changed (as-of 2025-06).
PSP implementations
Stripe Delegated Authentication: Launched in Europe using FIDO-based public-key cryptography; biometric data (fingerprint, Face ID) never leaves the cardholder's device. Wise is the first card issuer to use Stripe's DA — cardholders authenticate in-flow at Stripe merchants without being redirected to the Wise app. SCA-relevant payments using Stripe DA see a 7% lift in payment conversion and the authentication process is four times faster compared to redirecting to a banking app or OTP. (Stripe Newsroom, undated, volatile)
Visa estimates that SCA-compliant transactions without delegated authentication suffer an 11% drop in conversion rates due to app-switching friction. (Stripe Newsroom citing Visa, undated, volatile)
Stripe Newsroom announcement is undated. The 7% and 4× figures are vendor-reported benchmarks with no third-party corroboration found. The 11% Visa estimate is cited secondhand.
Practitioners on r/ecommerce (2026-07) characterise Stripe's DA as primarily tied to Stripe Link and issuer relationships: "Stripe's DA story is mostly around Stripe Link. For non-Link transactions, their frictionless optimization is primarily exemption-based TRA, not full DA. This is a meaningful difference that their sales team glosses over." (r/ecommerce, 178 upvotes, 2026-07)
Adyen RevenueAccelerate: Adyen authenticates the customer on behalf of the issuer within the merchant checkout page, replacing the standard issuer-side challenge. Supports FIDO Authenticator-based login within the 3DS requestor system (passkey-style, device-bound credentials). Available on web, iOS native app, and Android native app. (Adyen Knowledge Hub, undated)
Practitioners on r/ecommerce (2026-07): "Adyen's DA through RevenueAccelerate is genuinely stronger in EU markets — they have direct Visa/MC DA certifications and their issuer relationship data is better." (r/ecommerce, 201 upvotes, 2026-07)
Checkout.com: Routes payments through 3DS or Google's authentication technology with device biometrics and advanced SCA exemptions. Current documentation references 3DS v2.2.0 as the recommended version. (Checkout.com, undated)
Checkout.com v2.2 reference may be outdated: EMVCo published draft 3DS v2.4 specifications in June 2026. A Checkout.com blog post on "3DS 2.3 — what's new?" exists but was not fetched in full.
Shopify Payments: Confirmed absent. "Shopify Payments doesn't currently offer DA in any meaningful way. Shop Pay has some authentication optimization but it's not the same as what Adyen calls Delegated Authentication." (r/ecommerce, 178 upvotes, 2025-07)
Shopify Payments DA absence confirmed by practitioner signal from 2025-07. May have changed since.
Performance benchmarks
All practitioner benchmarks below are from 2025 Reddit threads unless otherwise noted. Treat as indicative; no independent 2026 corroboration for these figures found.
| Scenario | Frictionless rate | Source |
|---|---|---|
| Adyen RevenueAccelerate (UK fashion retailer) | 88–91% on eligible transactions | r/ecommerce, 156 upvotes, 2026-07 |
| Stripe Link (EU) | 89–93% on Link transactions | r/stripe, 167 upvotes, 2025-05 |
| Stripe non-Link (same merchant) | 72–75% | r/stripe, 167 upvotes, 2025-05 |
| Stripe with Link + network tokens (no PSP switch) | 83% | r/ecommerce, 123 upvotes, 2026-07 |
| Direct Visa DA (non-PSP wrapper) | 74% → 91% on eligible | r/fintech, 334 upvotes, 2025-06 |
| NT + DA combined (CIT only) | 93% | r/payments, 223 upvotes, 2025-06 |
| TRA exemptions only | 8–12% challenge rate | r/payments, 445 upvotes, 2025-02 |
| DA programs | 3–5% challenge rate | r/payments, 445 upvotes, 2025-02 |
| No optimization (fashion/apparel) | 15–22% challenge rate | r/payments, 445 upvotes, 2025-02 |
Authorisation rate differential (r/payments, 223 upvotes, 2025-02): DA frictionless transactions authorize at 95–96% vs exemption-based frictionless at 89–91%. "That delta is enormous at scale."
Abandonment benchmark: 18% of customers presented with a 3DS challenge abandon the purchase entirely. "A 10pp reduction in challenge rate retains 1.8% of total checkout attempts." (r/payments, 256 upvotes, 2025-02)
DA is not a guarantee: "DA is an input that increases the probability of frictionless, not a guarantee. We see about 8–9% of our DA transactions still get challenged by issuers who apparently weight their own signals more heavily." (r/fintech, 167 upvotes, 2025-06)
DA as guarantee vs probabilistic input: Some practitioners frame DA as reliably achieving 90%+ frictionless. Others insist it is probabilistic — 8–9% of DA transactions still get challenged by issuers overriding the DA claim. Sources: r/payments conversion benchmarks vs r/fintech direct Visa DA implementation thread (2025-06).
Adyen UK fashion retailer vs Stripe benchmark (both 2026-07, non-stale):
- Adyen: 88–91% frictionless + 3–4 percentage points higher authorisation rate on EU Visa/MC
- Stripe with Link + NT: 83% frictionless at €3M/month volume
Adyen vs Stripe DA for mid-market merchants: Practitioners split. One UK fashion retailer found Adyen DA delivered 88–91% vs Stripe 76–78% frictionless, concluding the switch was justified [r/ecommerce, 156 upvotes, 2026-07]. Against: staying on Stripe with Link + network tokens achieved 83% frictionless without migration cost, and "below €5M/month Adyen doesn't pencil out" [r/ecommerce, 123 upvotes, 2026-07].
Eligibility constraints
DA benefits only apply to a subset of total transaction volume. Key constraints:
- ~55–60% of transactions are DA-eligible: requires a logged-in user with a stored payment method, and the card must be in a market/issuer that honors DA assertions. (r/payments, 134 upvotes, 2025-01)
- Guest checkout is the structural gap: Fashion retailers report 30–50% of transactions are guest checkout, where no stored credential or authentication history exists. DA does not help here — exemptions or a 3DS challenge apply. (r/payments, 198 upvotes, 2025-06)
- Fashion structural advantage: High return rates mean high re-purchase rates and saved cards, which increases DA eligibility vs categories with more one-off purchases. (r/payments, 187 upvotes, 2025-02)
- Issuer honor rate: ~60–70% of issuers in EU markets actually grant frictionless when a DA signal is sent. "UK issuers tend to be better, some Southern European issuers are still basically ignoring DA." (r/fintech, 198 upvotes, 2025-06)
- Volume threshold for direct certification: Direct card network DA certification requires minimum volumes that "basically exclude anyone under €10–20M/month." Below that, only PSP-mediated DA is accessible. (r/ecommerce, 234 upvotes, 2025-07)
Eligibility percentages (55–60% eligible; 60–70% issuer honor rate) are practitioner estimates from 2025. No first-party data from card networks on these figures.
Liability
When a merchant or PSP assumes DA responsibility, chargeback liability shifts to them (or the third party acting on their behalf). "It is critical for merchants to ensure they only request delegated authentication for transactions they are confident about." (New Digital Age / Forter, 2021-10-27)
Liability mechanism description is from 2021; the principle is confirmed by Rivero (2026-06-25) but the 2021 source pre-dates PSD2/PSD3 policy evolution.
Important distinction: a Visa/MC certified DA merchant (clear liability rules in program agreement) has different protection from a merchant using a PSP's "delegated auth" product (liability depends on PSP's agreement with the networks). Practitioner war story: "We had a fraud incident post-DA and spent 3 months arguing with our PSP about liability. Our PSP's DA product didn't have the same liability protection as a direct Visa cert. We ended up eating most of the loss." (r/payments, 234 upvotes, 2025-04)
Liability war story from 2025-04. Terms may have been updated by PSPs since.
Regulatory context
- PSD2: DA was technically allowed but legally ambiguous in the original PSD2/RTS framework. Card network programmes (Visa, Mastercard) launched DA programmes that are PSD2-compliant. (New Digital Age/Forter, 2021; Rivero, 2026-06-25)
- EBA SCA for digital wallet card-binding: SCA must be applied by the issuer when adding a card to a digital wallet, and when issuing a new token replacing a prior one — both are preconditions for DA to function downstream. (EBA press release, undated)
- EBA Q&A 2025_7606: Clarifies the scope of "authentication procedures" in the RTS context — directly relevant to which flows an ASPSP must accept, including third-party / delegated flows. (EBA, 2025)
- EBA Q&A 2025_7607: Addresses the definition of "equivalent authentication procedure" for mobile-application-initiated journeys — relevant to whether mobile-native DA flows qualify under PSD2. (EBA, 2025)
- PSD3/PSR: Final compromise text published 23 April 2026; application not expected before 2027 at the earliest. PSD3 will give DA a defined legal basis; more wallet-led delegated SCA expected from 2027+. (Rivero, 2026-06-25, volatile)
Concern flagged by r/fintech practitioners: "PSD3 RTS drafts explicitly mention FIDO-compliant authentication as a preferred mechanism for DA claims. PSP wrapper implementations may need to re-certify if the RTS requires direct merchant-to-network relationships for DA claims — a significant disruption to the current market where Adyen/Stripe are essentially reselling DA capability." (r/fintech, 189 upvotes, 2025-06)
PSD3 RTS practitioner concern is from 2025-06. Final RTS not yet published; regulatory direction may have shifted.
Agentic commerce implications
Emerging demand driver for DA. The Biometric Update (July 2026, authored by Entersekt CSO — vendor perspective) identifies agentic commerce as a new authentication challenge: "Agent-initiated transactions will occur at a pace, volume and complexity that exceed human capacity, and without human biometrics, these transactions will require new authentication strategies." Emerging frameworks include "intent mandates" and "cart mandates" for AI agents acting as digital proxies within cardholder-set parameters. Issuers are extending KYC into Know Your Agent (KYA) protocols. (Biometric Update, 2026-07)
EMVCo in 2026 is working on how EMV 3DS, Payment Tokenisation, and Secure Remote Commerce specifications can support card-based agentic payments, including a Digital Identity and Payments Task Force exploring passkeys and Verifiable Credentials as authentication credentials. (EMVCo Knowledge Hub, 2026)
Technical prerequisites
Merchants seeking DA eligibility must: (1) ensure their payment ecosystem supports at minimum 3DS v2.2 (ideally v2.3+ for full DA data element support); and (2) have a strong fraud protection solution in place. (New Digital Age/Forter, 2021-10-27; confirmed as still current by Biometric Update, 2026-07)
EMV 3DS v2.2 introduced DA support. EMV 3DS v2.3 further enhanced the exchange of data between merchants and issuers to improve risk-based decisioning and reduce step-up challenges, and added WebAuthn/SPC support in collaboration with W3C and the FIDO Alliance. (EMVCo, 2021-11-12)
EMVCo published draft v2.4.0.0-1.0 specifications in June 2026 as part of an ongoing initiative to enhance the specification structure including delegation mechanisms. (EMVCo Knowledge Hub, 2026, volatile — draft not final)
Key terms
| Term | Meaning |
|---|---|
| DA | Delegated Authentication — merchant/PSP authenticates on issuer's behalf |
| Frictionless flow | 3DS transaction approved without shopper challenge step |
| VPP | Visa Payment Passkey — FIDO-based successor to DAF 3DS |
| DCAP | Visa Digital Commerce Authentication Program — data-only 3DS flow |
| DAF 3DS | Visa Digital Authentication Framework — sunsetting September 2026 |
| DA-eligible transaction | Logged-in user + stored card + issuer honours DA assertions |
| TRA | Transaction Risk Analysis — risk-based SCA exemption with volume caps |
| CIT | Cardholder-Initiated Transaction — required for DA; MIT is not DA-eligible |
| KYA | Know Your Agent — emerging issuer protocol for agentic commerce authentication |