At a glance
The percentage of customers who abandoned at the 3DS challenge (Cardinal-Cardinal-Commerce-issued bank popup) without completing it. Different from 3DS-failed (issuer rejected). Indicates UX friction: customers can’t or won’t complete bank verification.
Calculation
Calculated automatically from your Authorize.net data. See the At a glance summary above for what the metric tracks and the worked example below for a typical reading.Worked example
“Heartland Hardware Co.” web checkout, 7 days ending 02 May 26.
Action map:
- 17.7% abandon rate is just above the healthy 15% line. Watch for trend movement. Above 25% triggers investigation.
- The challenge frequency itself matters. 96 challenges out of 408 total 3DS-attempted (96 + 312) is 23.5%. Issuers send to challenge when their device-fingerprint risk score is high. Better risk-data signalling reduces challenge frequency.
- The most common UX causes of abandon. (a) Customer doesn’t recognise the merchant on the bank page (Cardinal-Cardinal-Commerce-rendered popup may show the acquirer name, not the merchant). (b) The OTP / push notification is delayed and the session times out. (c) Mobile customer hits a non-mobile-optimised bank page.
- Per-issuer split is the real diagnostic. A 30% abandon on one BIN range while others sit at 12% means that issuer’s 3DS challenge UX is broken; raise with the acquirer.
- Cart-recovery email for abandoned-3DS customers recovers 8 to 15% of the dropouts. Lower than abandoned-cart recovery (which can hit 25 to 35%) because customers may have already re-attempted with a different card.
Sibling cards merchants should reference together
Reconciling against the vendor’s own dashboard
Where to look in the Authorize.Net Dashboard: account.authorize.net does not natively show 3DS abandon as a single metric. Closest views: Reports → Transaction Statistics (filter forexpired status which is the abandoned-session marker), and the Cardinal Cardinal Commerce console (separate login at cardinalcommerce.com) for 3DS-flow detail.
Why our number may differ:
Cross-connector reconciliation:
Known limitations / merchant FAQs
Why is my 3DS abandon rate so high? Three common causes: (1) The bank’s challenge page is poorly mobile-optimised and customers on phones bounce. (2) OTP / push notification arrives slowly and the session times out (typically 10 minutes for Cardinal). (3) Customers don’t recognise the merchant name on the bank page. Fix: ensure your acquirer is sending the correctmerchantName field; A/B-test mobile vs desktop; instrument cart-recovery for abandon-3DS customers.
Is the US even using 3DS materially?
Patchy. EU PSD2 mandates 3DS for card-not-present above EUR 30; the US has no equivalent mandate. Most US merchants use 3DS for higher-value transactions (USD 1,000+) or as a chargeback liability shift, but it’s optional. B2B Authorize.Net merchants typically have 3DS off by default; consumer-facing merchants on aggressive fraud-prevention enable it.
3DS-failed vs 3DS-abandoned, the difference?
- Failed: customer attempted, the issuer rejected (wrong OTP, biometric failure).
- Abandoned: customer didn’t attempt (closed the popup, didn’t get the OTP, session timed out).