3DS SDK

Your customers shop on their phones. The 3DS SDK makes sure the security layer never breaks that experience. Available for Android and iOS, authentication inside the app, where it belongs.
Contact us

Authentication inside the app. Integrate the 3DS SDK.

For processing in-app payments based on the EMV 3DS 2.x standard. Merchants, acquirers, and PSPs can perform security functions, collect device information, and handle challenge flows.
Better data in, better risk decisions out

The SDK enables configurable device data collection, the information that helps an issuer's risk system decide whether to approve a transaction frictionlessly.  

Better risk scoring, more frictionless transactions.

Authentication inside the app

Full support for both EMV 3DS frictionless and challenge flow, handled entirely within the merchant app. When a challenge is needed, it appears inside the app — not in a browser.

Native UI or HTML UI for challenge screens. No redirects, no context loss, no abandonment.

PCI ready and tested against real components

PCI ready product. G+D Netcetera builds both the 3DS SDK and the 3DS Server it communicates with. Testing is done against the actual counterpart, not a simulation.

That difference shows in production — fewer integration surprises and better performance from day one.

Benefits of our 3DS SDK solution

PCI ready, fast to integrate, built by the same team that builds the 3DS Server it communicates with in production.
Abandonment down, transaction volume up

Authentication that stays inside the app, completes in seconds, and never confuses the customer is authentication that does not cost you sales. Better user experience, significantly reduced abandonment rate, increased transaction volume.

Easy integration in native shopping apps

Designed as a showcase for integration of 3DS SDK in merchant native shopping apps. The Netcetera Demo Merchant (NDM) application for Android and iOS which comes along with the 3DS SDK delivery shows exactly what SDK integration looks like inside a real shopping app.

Tested against the real components it talks to in production

G+D Netcetera builds the 3DS SDK, the 3DS Server, the Access Control Server, and the Directory Server. The SDK is tested against the actual server-side components, not a third-party simulation. That is a different quality standard, and it shows in integration and in production.

Better risk scoring leads to more frictionless transactions

The SDK collects richer, more relevant device context with every authentication request. More context gives the issuer's risk system more signal. More signal means more transactions approved frictionlessly. For a PSP processing meaningful volume, that frictionless rate is a direct revenue driver.

Compliant with all major schemes

3DS SDK Is compliant with all major schemes’ 3DS programs and updates the schemes certificates automatically. No action from the Customer is needed. Scheme compliancy is fully taken care of.

What is inside the G+D Netcetera 3DS SDK?

Every component needed to handle in-app EMV 3DS 2.x authentication — from device data collection to challenge screen rendering — in a single, well-documented SDK.

Benefits of our 3DS SDK solution for your customers

When a challenge is needed, it feels like part of the app — not a detour away from it.
Better payment experience from frictionless flows
 

The vast majority of genuine transactions complete without any challenge at all. The SDK processes authentication invisibly. The customer taps pay, the result comes back clean, and the purchase completes. No interruption, no re-orientation, no reason to abandon.

Same look and feel — customized to the merchant application

When a challenge is required, Native UI renders it using the same visual language as the merchant app. The customer never feels like they have been handed off to a different product. The transition is seamless because technically it never happened, they stayed in the app throughout.

Compliant with all major card scheme EMV 3DS programs

Whether the card is Visa, Mastercard, AmEx, or any other supported network, the cardholder gets the same contained, consistent authentication experience. No surprises based on which card they reach for.

What the experts behind this product say

Authentication is not PSD2 hygiene. It is the control that decides whether a suspicious payment is stopped early or becomes a loss, a complaint, and a regulator headline. Treat it like the revenue-and-trust lever it is."

Christopher Omloo
Sales Director Europe - Payment & Identity
G+D Netcetera

How the SDK fits into your mobile payment stack

The SDK is the mobile piece of the authentication chain. Here is exactly where it sits — and why the same team building the Server makes a difference.
Where the SDK sits in the EMV 3DS authentication chain

The 3DS SDK lives inside the merchant's native mobile app. When a payment is initiated, the SDK: (1) performs device security checks, (2) collects device information, (3) initiates the 3DS authentication request to the 3DS Server, (4) handles the frictionless result or triggers the challenge flow if needed, (5) renders the challenge screen inside the app using Native UI or HTML UI, and (6) returns the authentication result.  

The merchant app does not leave the 3DS flow at any point.

In a world of AI-driven fraud, device intelligence matters

As fraud becomes more sophisticated — AI-driven attacks, synthetic identity fraud, device spoofing — the quality of the device data sent in the 3DS authentication request becomes increasingly important.

An SDK that collects richer, more accurately characterized device context gives issuer risk systems better raw material. Better raw material leads to better decisions. Better decisions mean fewer genuine customers challenged and fewer fraudulent transactions approved. 

Compliant with 3-D Secure schemes’ programs


Trusted by industry leaders


FAQs

Real questions from developers and PSP product leads evaluating the G+D Netcetera 3DS SDK.
What does the 3DS SDK do and what does the 3DS Server do?

The SDK handles the mobile client side: device data collection, security checks, and the challenge flow if one is triggered inside the merchant app.

The 3DS Server handles the acquirer or PSP side: initiating the authentication request, managing the Directory Server conversation, and processing the response. The SDK and 3DS Server are separate components that work together. 

The SDK is the mobile piece — it cannot replace the Server, and the Server alone cannot deliver in-app authentication. Both are needed for a complete EMV 3DS implementation in a native mobile environment.

What is the difference between Native UI and HTML UI for challenge screens?

Native UI renders the challenge screen using native mobile components — the same building blocks as the rest of the merchant app.

The challenge content comes from the ACS, but the presentation is native. It looks and feels like part of the app. HTML UI renders the issuer's own HTML-based challenge screen inside the app — giving the issuer full control over branding and design. Neither option uses a browser redirect.

The right choice depends on whether priority is matching the merchant app experience (Native UI) or giving the issuer maximum flexibility over their challenge design (HTML UI).

Why does it matter that G+D Netcetera builds both the SDK and the 3DS Server?

Because authentication is a two-way conversation between the SDK and the 3DS Server. When the same team builds both, integration testing is done against the actual counterpart — not a third-party mock that approximates what the Server might do. The device data the SDK collects is designed with the Server's data handling in mind.

The challenge flow the SDK renders is tested against the ACS behaviour the Server expects. That internal coherence shows up as fewer integration surprises and better production performance.

What does the annual license include?

The annual license includes the 3DS SDK for Android and iOS — both with separate EMVCo certifications — comprehensive technical documentation, the Netcetera Demo Merchant app for Android and iOS, full online support, and webinar education sessions.

G+D Netcetera commits to regular product improvements, so as the EMV 3DS specification evolves, the SDK is updated and clients stay current. SDK download requires login to the G+D Netcetera partner portal.

How does better device data collection reduce cart abandonment?

Frictionless authentication happens when the issuer's ACS decides the transaction is low-risk — based on the data it receives. The SDK's role is to maximize the quality and relevance of that data with every authentication request: device fingerprint, payment context, security check results. The richer and more accurate that data, the more transactions the ACS can confidently approve without challenging the cardholder.

Fewer challenges means fewer interruptions at checkout. Fewer interruptions means fewer abandoned carts. Better device data is the upstream cause of the downstream conversion improvement.

Related resources

Find out more about our 3DS SDK solution
Technical documentation
EMVCo approvals

Related solutions 

The SDK works best as part of a complete acquiring and authentication stack.
3DS Server

The server-side companion to the 3DS SDK. Built by the same team — which is why the data formats are designed to work together. The natural first companion when mobile in-app authentication is in scope.



Discover the solution​

Click to Pay SRCI

3DS authentication and Click to Pay are natural partners in mobile commerce. Click to Pay handles payee recognition and one-click checkout. The 3DS SDK handles the in-app authentication when a transaction needs it.

 

Discover the solution​

eCOM Tokenizer

Network tokenization and 3DS authentication address different problems but reinforce each other. The eCOM Tokenizer gives merchants access to major card network token services through a single connection — pair with the 3DS SDK for a complete in-app payment security layer.
 

Discover the solution​

3-D Secure Issuer Service

The 3DS SDK communicates with the issuer's Access Control Server during authentication. G+D Netcetera also provides the ACS for issuers — so both ends of the authentication conversation can run on G+D Netcetera infrastructure.

 

Discover the solution​

The G+D Netcetera Email Newsletter

Latest updates and news in your inbox

Subscribe now

Talk to our experts


Related Insights

The Friendly Fraud Problem

The Friendly Fraud Problem

First-party misuse is now the world’s leading type of fraud, yet it is almost impossible to spot at checkout. Discover why friendly fraud is rising, what it costs the payments industry, and how better data sharing could help distinguish genuine disputes from deliberate abuse.

Passkeys? Pass what?

Passkeys? Pass what?

Your Essential Introduction to Passwordless Authentication. Tired of password resets, phishing attacks, and frustrated customers? It's time to discover passkeys—the authentication technology that's making passwords obsolete.

S01E08: Click to Pay: Smart, Simple, Secure

S01E08: Click to Pay: Smart, Simple, Secure

Remember the last time you abandoned a purchase because you couldn’t find your card? How much time, energy, and mood did you waste filling in the requested information? Ultimately, you just left your purchase because it was too time-consuming, data-consuming, and energy-consuming. Sound familiar? That’s exactly why Click to Pay was created. In this episode with Suzana Kordumova Nikolova, we explore what makes Click to Pay different from Apple Pay and Google Pay, how it enhances security, and why businesses adopt it.

S01E09: Passkeys, pass what?

S01E09: Passkeys, pass what?

Passwords are becoming a thing of the past. Passkeys deliver a safer, faster, and more seamless way to log in and approve payments. Payment expert Nakjo Shishkov explains how passkeys, 3DS, Click to Pay, and FIDO authentication set new standards for secure digital experiences. Learn how passkeys work, why they improve security, and how they drive better user journeys and higher conversion rates.