Payment authentication verifies that the person or system initiating a payment is authorized to use the selected payment credentials. It is separate from authorization, which decides whether the transaction may proceed.
How is a payer authenticated?
Methods can include passwords, one-time codes, banking-app approval, biometrics, device signals and certificate-based controls.
Authentication versus authorization
Authentication verifies identity or authority. Authorization checks funds, limits and risk and returns an approval or decline.
When is stronger authentication used?
Providers may require additional steps based on regulation, transaction risk, amount, device or issuer decision.
Does authentication prevent every dispute?
No. It may reduce fraud and shift liability in eligible cases, but it does not resolve non-delivery, duplicate or amount disputes.
What should be retained?
Keep method, timestamp, outcome, transaction identifier, challenge result and related authorization response without storing prohibited sensitive data.

