Why Spendesk requires strong authentication — and what it means for you.
For: All Spendesk users.
Why is Spendesk securing your access?
A European payment regulation called PSD2 (Payment Services Directive 2) went into effect on 14 September 2019. Enforced by the European Banking Authority, it requires all financial services to implement Strong Customer Authentication (SCA) — a multi-step identity verification process applied when accessing accounts or making payments.
💡 Note: PSD2 and SCA officially apply to payments and account access within the EEA and the UK. Spendesk has extended these requirements to all markets globally to ensure a consistent and high level of security for every user.
What is Strong Customer Authentication (SCA)?
SCA is a verification process that requires you to confirm your identity using at least two of the following three factors:
Factor | What it means | Examples |
Something you know | Information only you know | Password, PIN, or code |
Something you have | A device only you possess | Mobile phone, smart card, or hardware token |
Something you are | A personal biometric trait | Fingerprint, face, or voice recognition |
How does SCA apply to Spendesk?
SCA is triggered in the following situations on Spendesk:
Situation | Who is affected |
Accessing all transaction data on the Spendesk web app | Account Owners, Controllers, Admins (every 90 days) |
Initiating a wire transfer from the Spendesk web app | Account Owners |
Opening the Spendesk mobile app | All users |
Confirming an online card payment (3D Secure) | All users making card payments |
How Spendesk implements SCA
Two-step authentication (account access and sensitive actions)
To confirm your identity when logging in or performing sensitive actions (such as revealing a card PIN or approving a wire transfer), Spendesk supports three authentication methods:
Authenticator app (TOTP) — A time-based one-time password app (e.g. Google Authenticator, Microsoft Authenticator, 1Password) generates a 6-digit code every 30 seconds. Available since June 26, 2026.
Spendesk mobile app — A push notification is sent to your registered device. You approve the action directly in the app.
Text message (SMS) — A one-time code is sent to your registered mobile number.
⚠️ Security note: SMS is less secure than other methods and is vulnerable to SIM swap and SS7 attacks. We recommend using the Authenticator app or the Spendesk mobile app when possible.
👥 Roles: Only Account Owners and Admins can configure company-wide login settings (e.g. enabling SAML SSO).
Card payment authentication (3D Secure)
For online card payments, Spendesk uses the 3D Secure (3DS) protocol to verify transactions on websites that support it. When a payment requires 3DS verification:
Make a payment with your Spendesk card on a website that requires 3DS.
Open the Spendesk mobile app when you receive a push notification.
Review the payment details and confirm the transaction in the app.
If you do not receive a notification, open the Spendesk app manually — the confirmation screen appears automatically if a payment is awaiting authentication.
Note: For recurring card payments, 3DS may still be required for the first payment to a merchant or for any transaction exceeding €500, even if the merchant has requested an exemption.
Who is impacted?
PSD2 is mandatory for European users. However, Spendesk has extended these security requirements to all markets globally, as they significantly improve platform security for everyone.
Frequently asked questions
Why do I need to authenticate every 90 days?
PSD2 requires Account Owners, Controllers, and Admins to re-authenticate with SCA every 90 days to access transaction data. This is a regulatory requirement, not a Spendesk-specific policy.
What if I lose access to my authentication method?
Contact your Account Owner or Administrator. They can issue a recovery code to restore your access. You can also set up multiple authentication methods in advance to avoid being locked out.
Can I use multiple authentication methods?
Yes. Spendesk recommends configuring more than one method so you always have a backup available.
Does SCA apply to users outside Europe?
Officially, PSD2 covers the EEA and UK. However, Spendesk has extended SCA to all markets globally to ensure platform-wide security.
Related articles
Set up two-step authentication (Authenticator app, SMS or Spendesk mobile app)
Strong customer authentication (SCA) on mobile
3DS common issues
Reset or change your Spendesk security code
