Understanding PSD2 and Strong Customer Authentication (SCA)
The Payment Services Directive 2 (PSD2) is a European Union regulation that requires banks and payment providers to use Strong Customer Authentication (SCA) to verify account access and payment transactions. Spendesk applies SCA to protect your account and your card payments.
For: All Spendesk users with a card, and Account Owners and Admins managing login settings. Applies to companies operating in the European Economic Area (EEA) and the UK.
Before you start
Requirement | Detail |
Region | Applies to payments and account access within the EEA and the UK |
Plan | Available on all Spendesk plans |
Mobile app | Required to confirm 3D Secure (3DS) prompts and to log in with certain authentication methods |
Phone number | Add your phone number in My profile > Security phone number to enable mobile authentication |
Login method | Password, Google Authenticator, Microsoft Authenticator, or SAML SSO, depending on your company's setup |
What is Strong Customer Authentication (SCA)?
SCA is a verification process required by PSD2 for accessing accounts and making payments. It requires at least two of the following three factors:
Factor | Definition | Example |
Something you know | Information only you know | Password, PIN, or code |
Something you have | A device only you possess | Mobile phone, smart card, or token |
Something you are | A personal biometric trait | Fingerprint, face, or voice recognition |
💡 Tip: PSD2 and SCA apply to payments and account access within the EEA and the UK. Transactions with merchants based outside these regions may not require the same authentication steps.
How Spendesk applies SCA to account access
Spendesk secures account access using one of the following methods, depending on your company's configuration:
Password protection
Google Authenticator
Microsoft Authenticator
SAML SSO
👥 Roles: Only Account Owners and Admins can configure or change your company's login method (for example, enabling SAML SSO).
How Spendesk applies SCA to card payments (3D Secure)
For online card payments, Spendesk uses the 3D Secure (3DS) protocol to verify transactions on websites that support it. When a merchant or your card issuer requests 3DS verification, you confirm the payment through the Spendesk mobile app.
Confirm a payment with 3D Secure
Make a payment with your Spendesk card on a website that requires 3DS verification.
Open the Spendesk mobile app when you receive a push notification.
Tap the notification to open the payment confirmation screen.
Review the payment details shown on screen.
Confirm the payment in the app to complete the transaction.
If you don't receive a notification, open the Spendesk app manually and log in: the confirmation screen appears automatically if a payment is awaiting authentication.
Recurring card payments and SCA
For a new recurring payment (for example, a software subscription), you generally need to confirm the first payment through 3DS. Once the merchant has set up the recurring billing agreement correctly, most subsequent payments for the same subscription don't require you to re-confirm through 3DS, in line with network rules for merchant-initiated transactions.
⚠️ Warning: Some recurring payments, particularly high-value transactions or ones flagged as a fraud risk, may still be challenged for 3DS confirmation by your card issuer, even if the merchant requested an exemption. If a recurring payment is declined for this reason, open the Spendesk app to check for a pending confirmation request.
Troubleshooting
Symptom: A recurring subscription payment is declined and asks for 3DS confirmation, even though it was previously exempted.
Cause: Your card issuer's fraud-prevention rules can still request re-authentication for certain recurring transactions, independent of the merchant's exemption request.
Resolution: Open the Spendesk mobile app and confirm the payment through the 3DS prompt. If no prompt appears, contact support@spendesk.com with the transaction date, merchant name, and amount.
Symptom: No 3DS notification appears on the mobile app when a payment requires confirmation.
Cause: Your phone number isn't added to your profile, notifications are disabled, or your device isn't registered in the app.
Resolution:
Go to My profile > Security phone number and add your number.
Go to your phone's Settings > Notifications > Spendesk and allow notifications.
Open the Spendesk app, log in, and follow the prompts to set your PIN and register your device.
If the issue persists, uninstall and reinstall the app, then retry the payment.
Symptom: A payment is rejected and the merchant says Spendesk isn't SCA-compliant.
Cause: The merchant's payment system may not support 3DS correctly, or the merchant is misidentifying the exemption rules.
Resolution: Ask the merchant to retry the transaction with a 3DS challenge, or contact support@spendesk.com if the issue continues.
FAQs
What happens if I forget my password or lose my authentication device?
Contact support@spendesk.com for assistance. Set up backup recovery methods for apps like Google Authenticator or Microsoft Authenticator in advance.
Why do some merchants request exemptions from 3DS?
Merchants can request exemptions for low-risk or recurring transactions. Your card issuer's security rules may still override these exemptions for certain transactions to protect you from fraud.
How can I update my authentication method?
Account Owners and Admins can manage login settings in the Spendesk Settings tab. Contact support@spendesk.com for help.
Does SCA affect all payment methods?
SCA mainly applies to card payments and account access. Other payment methods may follow different security rules.
Who do I contact if I have authentication issues?
Contact support@spendesk.com for help with login or payment authentication.
