3D Secure Authentication
What is 3D Secure (3DS)?
3D Secure (3DS) is an authentication protocol for online Card-Not-Present transactions, which requires additional verification before the payment can be approved.
Without 3DS, some transactions will not complete until authentication is successful.
How does authentication work?
There are two methods:
In-App 3DS
It applies if you usually log into the Capital on Tap app.
- A push notification is sent to the app.
- The transaction can be approved or declined directly in the app.
- The request expires after 8 minutes. If no action is taken, the authentication times out and the payment declines.
SMS 3DS
- A one-time password (OTP) is sent to the registered mobile number.
- The OTP must be entered on the merchant's checkout page.
- If the OTP is entered incorrectly or expires, the payment will decline.
These are the only two available methods for 3DS, we do not offer any alternative.
Why is authentication required for small purchases?
Authentication may be required for online transactions if:
- The total value of online purchases since the last 3DS check exceeds the limit, or
- 5 consecutive online transactions have been made without a 3DS check.
Why is 3DS not required for Apple Pay or Google Wallet?
Digital wallet payments, including Apple Pay and Google Wallet, include their own authentication method and additional 3DS verification is not required.
What is Express Checkout?
Express Checkout allows you to trustlist selected merchants so that 3DS authentication is skipped for future transactions with those merchants.
Once a merchant is added to your Express Checkout list, neither an SMS OTP nor an In-App push notification will be prompted when transacting with them.
Note: Express Checkout is set at the card level. If you have multiple cards, you will need to add merchants to Express Checkout separately for each card.
How to add a merchant to Express Checkout
To add a merchant to Express Checkout, you must have already completed at least one successful 3DS transaction with that merchant.
There are three ways to manage your Express Checkout list:
Via the Transactions tab
- Go to the Transactions tab in the web portal or app.
- Select a transaction made to the merchant you wish to add to your trustlist.
- On the Transaction Details screen, below the transaction value, select Add to Express Checkout if the option is available - this will only appear if the merchant is eligible.
Via the Cards tab
- Go to the Cards tab in the web portal or app.
- Select the card you want to add the merchant to.
- In Card Settings, scroll down and click on Express Checkout.
- From there you can add or remove merchants from your trusted list.
After completing a 3DS authentication
After approving a 3DS request, a confirmation screen will appear. If the merchant is eligible, you will have the option to add them to your Express Checkout list directly from that screen.
Which merchants are available for Express Checkout?
The following merchants are currently eligible to be added to your Express Checkout list:
- B&Q
- Companies House
- DVLA Personalised Registrations
- DVLA Vehicle Tax
- DVSA
- HMRC
- Screwfix
- Toolstation
- Wickes
- Royal Mail
- Amazon
- Howdens
- Travis Perkins
- UK Visas and Immigration
- British Airways
- Airbnb
- Travelodge
- Tesco
- Sainsbury's
- DHL
These are currently the only merchants available.
Why are transactions failing?
SMS code is not received
If an SMS One-Time Passcode (OTP) does not arrive it might be because you haven't logged into the Capital on Tap app recently. Please:
- Confirm the registered mobile number on the account is correct.
- Check mobile signal and roaming status.
- Wait 10 minutes, restart the device, and request a new OTP.
If the issue persists, contact our Support team through the available channels.
SMS code not received when travelling abroad
If SMS delivery for 3D Secure fails due to international roaming, there are alternative authentication options:
- Use a Digital Wallet, such as Apple Pay or Google Pay, which uses an alternative authentication method.
- Log into the Capital on Tap app to complete and authorise the payment via the In-App 3DS feature.
In-App 3DS prompt not appearing
If a push notification is expected but does not appear:
- Confirm push notifications are enabled for the Capital on Tap app.
- Check the app is updated to the latest version.
- Confirm the device has an active internet connection.
If the issue persists, contact our Support team through the available channels.
Transaction declined with message: 3D Secure Authentication Failed By Card Holder
This decline message means the authentication step was not completed successfully. Common causes include:
- The OTP was entered incorrectly or expired.
- The push notification was not approved within 8 minutes.
- The registered mobile number is incorrect.
Retry the transaction and complete authentication when prompted.
Transaction declined after the OTP is entered
If the OTP was entered correctly but the transaction still declined, the merchant may not have completed the authorisation request on their side. You can contact the merchant directly to confirm.
Transaction declined due to incorrect card details or billing address
A Card-Not-Present transaction may decline if the details entered at checkout do not match the information held on the account. Check the following before retrying:
- Card number - entered in full, with no transposed digits
- Expiry date - matches the date printed on the card
- Billing address - matches the business address registered on the Capital on Tap account