What is a 2D payment gateway, and how does it work?
Payments

What is a 2D payment gateway, and how does it work?


A customer enters their card number, expiry date and CVV, clicks Pay, and the transaction goes straight for authorisation without an OTP, banking-app approval or another cardholder challenge.

That flow is often described as a 2D payment gateway or non-3DS card payment.

“2D” is not an EMVCo authentication standard. In practice, it usually means an online card transaction that proceeds without EMV 3-D Secure (3DS) authentication.
TL;DR
  • A 2D payment gateway usually means a card-not-present payment flow that does not use 3-D Secure authentication.
  • 3-D Secure is the actual EMVCo authentication protocol; modern 3DS can be frictionless or require a customer challenge.
  • Non-3DS payments can reduce visible checkout steps, but may carry greater fraud, decline, compliance, or dispute risk depending on the market and card-scheme rules.
  • Do not choose between “2D and 3D” purely on speed. Modern payment stacks use authentication intelligently based on regulation, issuer requirements, transaction risk, and customer context.

What is a 2D payment gateway?


A 2D payment gateway is an informal industry term for an online card-payment setup where the transaction is sent for authorisation without a 3-D Secure cardholder-authentication step.

The customer may provide:
  • card number
  • expiry date
  • CVV/CVC
  • billing information where required


The gateway then sends the payment into the card-processing flow.

These details help process the transaction, but card number + CVV are not two independent authentication factors. A more precise term is non-3DS transaction.

How does a 2D card payment work?


A simplified non-3DS flow looks like this:

Customer enters card details → gateway sends payment → acquirer/processor routes it → card network → issuer → approve or decline

The issuer still performs its own risk and authorisation checks.

What is missing is the separate 3DS authentication exchange in which the issuer can verify the cardholder before authorisation.

Non-3DS payments can still use encryption, tokenisation, PCI DSS controls, CVV checks, fraud scoring, and issuer risk systems. Those controls are different from cardholder authentication through 3DS.

What is a 3D payment gateway?


“3D payment gateway” usually refers to a gateway that supports EMV 3-D Secure (EMV 3DS).

Modern 3DS has two main outcomes:

Frictionless flow


The issuer receives enough data to authenticate the transaction without asking the customer to complete an extra step.

Challenge flow


The issuer asks for additional verification, such as an OTP, banking-app approval, biometric check, or another supported authentication method.

Your gateway to seamless payments!

Accept 130+ global currencies | 40+ alternate payment methods |
Instant FIRA

Get started →
Global payments illustration

2D vs 3D payment gateway

Factor2D / non-3DS3DS-enabled
Cardholder authenticationNo 3DS authenticationEMV 3DS authentication
Visible extra stepUsually noneNone in frictionless flow; possible challenge
Issuer receives 3DS dataNoYes
Fraud protectionRelies on other payment/risk controlsAdds issuer-led cardholder authentication
Regulatory fitDepends on market and transactionCan support authentication mandates
Checkout frictionLowCan also be low with frictionless 3DS
Liability treatmentDepends on card-scheme rulesAuthentication can affect liability treatment, subject to scheme rules

The important comparison is therefore non-authenticated vs authenticated card flow, not simply “fast vs secure”.


RBI has long required Additional Factor of Authentication (AFA) for online card-not-present transactions involving India-issued cards in applicable domestic payment scenarios.

That means a merchant should not treat “2D checkout” as a shortcut around authentication requirements.

What about Europe and Strong Customer Authentication?


In the European Economic Area, PSD2 rules require Strong Customer Authentication (SCA) for many payer-initiated electronic payments.

The rules provide exemptions for circumstances such as certain:
  • low-value payments
  • recurring transactions
  • trusted beneficiaries
  • low-risk transactions assessed through transaction-risk analysis


3DS is widely used to support SCA for card payments, while the issuer can still allow a frictionless authentication flow where appropriate.

What are the risks of non-3DS payments?


Higher card-not-present fraud exposure


Without issuer-led cardholder authentication, stolen card credentials may be harder to distinguish from legitimate use.

More issuer declines


An issuer may be less comfortable approving an unauthenticated cross-border transaction, particularly where authentication is expected.

Compliance problems


A non-3DS flow may not satisfy authentication requirements where AFA or SCA applies.

Dispute exposure


Authentication status can affect fraud-dispute and liability treatment under card-network rules. The outcome depends on the transaction and scheme rules rather than a universal “merchant always pays” rule.

Is 3DS bad for conversion?


Not inherently.

Older authentication experiences often meant redirects and OTP friction. Modern EMV 3DS is designed to exchange richer data so issuers can authenticate lower-risk transactions without interrupting checkout.

A payment provider should optimise both authentication and authorisation rather than simply remove authentication.

How should an international business approach 2D vs 3D?


Do not choose one fixed mode for every transaction.

A stronger cross-border setup considers:
  1. cardholder and issuer country
  2. local authentication regulation
  3. card-network requirements
  4. issuer behaviour
  5. fraud risk
  6. transaction type
  7. available exemptions
  8. historical approval performance


How PayGlocal approaches international card authentication


PayGlocal's international payment gateway uses 3DS optimisation alongside intelligent routing, issuer-level logic, fraud scoring, and localised checkout.

The goal is not to add authentication to every buyer interaction. It is to send the issuer the right authentication and transaction context while keeping eligible low-risk flows as frictionless as possible.

PayGlocal currently supports customers across 180+ countries and advertises international Payment Success Rates of up to 96%.

Frequently Asked Questions

It usually means an online card-payment flow that proceeds without EMV 3-D Secure authentication. “2D” is industry shorthand rather than an official EMV authentication standard.
Typically no 3DS challenge is performed. However, the issuer or payment flow may still apply other security checks.
No. Modern EMV 3DS supports frictionless authentication, where the customer may complete the payment without an OTP or other visible challenge.
No. CVV is card-verification data, not a separate authentication factor in the same sense as an OTP, biometric, or banking-app approval.
They can still use encryption, PCI DSS controls, tokenisation, CVV checks, and fraud screening, but they do not include the additional issuer-led authentication provided by 3DS.
Usually not as a blanket strategy. Authentication requirements and issuer behaviour vary by market. A better approach is to optimise 3DS, routing, and fraud controls so legitimate transactions remain as frictionless as possible.
Related blogs