Authentication is changing from challenge to trust

Like with everything payments, authentication has evolved. There are more technologies, smoother user journeys, and different ways to establish trust. The next challenge for e-commerce is authentication orchestration.

Renan Renner Portrait
Renan Renner  ·  Group Product manager - Adyen Uplift, Adyen
September 29th, 2026
 ·  7 minutes
Digital payment processing illustration showing integration of transaction data and devices by Adyen.

Payments made in the absence of physical cards have always challenged issuers and merchants. The most obvious one is how to ensure that the person making the payment is the legitimate owner of that method.

To verify the authenticity of card-not-present (CNP) transactions, issuers and legislators made authentication a requirement. 

Traditional authentication layers like 3-D Secure (3DS) were achieved with redirects, one-time codes, or prompts in banking apps that made security visible. While these methods worked, they also stopped every shopper in the payment flow and added substantial friction and caused drop off.

Like everything in payments, authentication has evolved. Today, there are more technologies, smoother user journeys, and different ways to establish trust. 

That’s great news for the e-commerce industry in general. For individual businesses it raises new challenges on when to offer what, what methods to integrate, and where to get the resources to do so.

In other words, the next challenge for e-commerce is authentication orchestration.

Authentication started as a challenge

Authentication began as a way to combat fraud. In 3DS 1.0, the question centered on whether the issuer could verify that the person attempting a payment was the legitimate cardholder with a visible challenge and limited transaction context.

Authentication protocols were quickly adopted as regulation in certain geographies. Regulators in Europe were quick on making authentication protocols mandatory with the Payments Service Directive 2 (PSD2) and SCA requirements. 

Regulation cemented authentication as a central design concern for the payments ecosystem. Yet regulation explains only part of what is happening.

Authentication is growing globally, regardless of legislation

If authentication was only valuable because regulators demanded it, it would only be used in markets with broad authentication mandates. Instead, we see a global shift to authentication as a key feature of an online transaction.

Let's take a look at the US. While there isn’t a broad, PSD2-style SCA mandate for online card payments, we see significant growth in the use of authentication. A 2025 US Payments Forum estimated that approximately 3% of US transactions were sent over EMV 3DS rails. Our data shows a broadly comparable trend of 3.5% share by transaction count in Q2 2025. 

Those transactions represented 17.4% of customer-initiated online card value, up from 9.2% a year earlier.

The data shows that merchants increasingly have reasons to authenticate, even when compliance isn’t a factor.

Authentication infrastructure is expanding

The first iterations of authentication were suboptimal in many ways. The most obvious way is how 3DS 1.0 stopped the payment and asked the customer to prove who they are, breaking a payment journey and adding friction. 

Emerging authentication models are contextual. They aim to use the evidence already present, and ask for more only when confidence is insufficient.

There are multiple ways to collect evidence needed to create trust. 

  • A passkey can establish control of a cryptographic credential using the same action a customer uses to unlock a device. 

  • Remembering devices can indicate that a trusted device is used. 

  • A wallet can carry a tokenized payment credential or a verified identity attribute.

Google's Secure Payment Authentication (SPA) illustrates efforts to bring biometric confirmation closer to the merchant journey. Europe’s evolving Digital Identity Wallet (EUDI) framework points toward reusable, user-controlled identity credentials.

These mechanisms aren’t substitutes to 3DS. They establish trust differently by answering different questions that are all valid in the specific context of a simple payment.

So that begs the question for businesses: what technologies do you integrate and use when?

Why authentication success doesn’t mean payment success (yet)

There’s another crucial party in the payments chain that uses authentication: the issuer.

An issuer will only authorize a payment if they have confidence that the transaction is legitimate. This confidence is more automatic in markets where authentication is mandatory.

In unregulated markets like the US, though, it’s a bit more complicated. Many things can influence issuer confidence and trigger a decline, such as a transaction originating on a new device or from an unknown location. 

In these markets, adding authentication and sharing success rates with your issuer may help increase confidence and improve authorization rates as a result. However, your authentication strategy needs to shift. Using an approach that optimizes for authentication at all costs may add extra steps that affect your conversion rates, but avoiding authentication could mean you miss critical data that issuers helps issuers authorize a transaction. 

To truly optimize authentication for authorization, you should use your PSP’s ability to gather data that improves authorization in an intelligent way and share it with issuers. It should use new technology to evaluate ecosystem behavior, not just interpret protocols and regulations.

The future of authentication is contextual

The future of authentication isn’t a choice between 3DS, passkeys, Google SPA, digital identity wallets, data only flows, or the mechanisms that follow them. Instead, it’s about knowing when and how to use each, including when no additional customer action is needed.

The industry is shifting. What was once a regulatory protocol is now turning into an intelligent trust layer that helps all parties within the payments value chain. It helps them understand where a payment is coming from, authorize more legitimate payments, reduce customer friction, and maintain regulatory obligations.

As this layer becomes more embedded, authentication may become almost invisible to consumers. Consent, privacy, and clear recourse remain essential, but customers will spend less time thinking about the act of authentication itself.

They will simply expect commerce to recognize when they can be trusted, know when further verification is necessary, and use the least disruptive method available.

AI will define the winning strategy

Technology is helping authentication evolve. The winning strategy has to incorporate observed ecosystem behavior, not only a static interpretation of protocol and regulation. We need to focus on observed behavior observed ecosystem behavior, which is only possible thanks to innovations like AI.

This is the market evolution Adyen Uplift’s Authenticate addresses.

We've created a global authentication layer that isn't tied to a single protocol and can incorporate new mechanisms as they emerge.

Authenticate balances transaction characteristics, issuer behavior, market requirements, risk, customer history, and available authentication methods to automatically select the best authentication path for conversion. 

That is a different ambition from authenticating more payments. It is about making better authentication decisions in service of the payment outcome.

Authentication isn’t disappearing. Unnecessary interruption is. With Adyen Uplift’s Authenticate, you’ll be ready for the evolution of payment authentication.

Fresh insights, straight to your inbox