When the bank says yes but the merchant doesn’t know: How Entersekt’s Merchant Callback closes the 3DS gap
Successful 3-D Secure (3DS) authentication should be a good outcome for everyone. The shopper proves they are legitimate. The issuing bank approves the authentication. The merchant or payment service provider (PSP) can continue the payment with greater confidence.
But authentication succeeding doesn't necessarily mean the transaction succeeds. There is one critical point in the journey where that successful outcome can still get lost: the handoff back to the merchant.
In a challenged 3-D Secure checkout, the shopper may be redirected to their banking app to complete authentication. Once they approve, the authentication result needs to make its way back to the merchant or PSP through the browser. If that browser session stalls, closes, reloads, or otherwise loses its place, the merchant may never receive the result.
The bank has said yes. The shopper has authenticated. But the merchant doesn't know.
That gap between successful authentication and completed checkout is exactly what Merchant Callback, a feature of Entersekt’s 3-D Secure Server (3DSS), is designed to close.
When authentication succeeds but checkout doesn’t
Consider a typical challenged checkout. A shopper starts a purchase online. The merchant or PSP initiates 3-D Secure authentication, and the issuing bank determines that the shopper needs to provide additional proof.
So, the shopper completes that challenge — potentially in their banking app — and the issuer approves the authentication. At this point, the authentication itself has worked, but the journey isn’t necessarily over.
The browser still has to return the result to the merchant or PSP. In real-world mobile journeys, that browser session can be interrupted. A shopper might switch between apps, close a browser window, reload a page or simply lose the session’s place. The result can therefore become disconnected from the checkout.
-
For the shopper, this may look like a payment that is stuck or unclear. They may not know whether the transaction succeeded and could abandon the purchase or attempt it again.
-
For the merchant or PSP, the consequences can be more tangible: an approved shopper may be lost before the purchase can progress.
So, the authentication worked, but the customer journey didn’t. That distinction matters. A failed authentication and a failed handoff are not the same problem — and they shouldn't be treated as one.
Merchant Callback is designed specifically for the latter: making sure a successful authentication result can still reach the merchant or PSP when the browser can't complete the handoff.
Closing the gap between authentication and checkout
Merchant Callback, a feature of Entersekt’s 3-D Secure Server, addresses this specific gap between authentication and checkout. Rather than relying on the shopper’s browser to return the completed authentication result, the result takes a more direct path:

The difference is subtle but important: the browser no longer has to be the thing that determines whether a successfully authenticated transaction can continue. This creates a more resilient path for communicating the outcome of authentication.
The merchant or PSP receives the information it needs, including evidence that authentication was completed, whether authentication succeeded or failed, and a transaction reference that can be matched to the purchase. The result is securely delivered and verified using existing certificates.
The important distinction is that Merchant Callback doesn’t approve the payment itself. It confirms and communicates the outcome of the security check, allowing the merchant or PSP to determine what should happen next. That means its role is not to make the authentication decision, but to help ensure that a decision already made can be acted on.
Why this matters to merchants and PSPs
For online merchants and PSPs, the value isn't simply more successful authentication. It's making sure successful authentication actually counts.
A shopper who has authenticated successfully is already a verified opportunity to complete a purchase. When that result gets lost on the way back to checkout, the merchant can still lose the sale. Merchant Callback helps close that final gap, translating into several business benefits:
-
More revenue retained
Fewer authenticated shoppers are lost between successful authentication and payment completion. -
Better checkout conversion
More challenged purchases can progress toward completed payment rather than ending in a stalled checkout. -
Lower cost to serve
Fewer ambiguous transactions can mean fewer status checks, duplicate attempts, customer support contacts and manual investigations. -
Greater customer confidence
A clear, consistent checkout outcome reduces the uncertainty shoppers experience when an authentication succeeds but the browser does not return them cleanly to the merchant. -
Making authentication work harder for the transaction
3-D Secure is designed to help authenticate legitimate shoppers while managing payment risk. But authentication only creates commercial value when the merchant or PSP can act on the result. Merchant Callback addresses that last-mile gap — helping turn a successful security decision into a transaction that can actually move forward.
Why acquiring banks and PSPs should care
The challenge isn’t limited to individual merchants. For PSPs and acquiring banks, the reliability of the payment experience is part of the value they provide to their merchant customers.
A merchant doesn’t necessarily see the underlying complexity of the 3DS ecosystem. They see a checkout that either progresses or doesn’t. From their perspective, it doesn't matter whether the problem was authentication, the browser, or the handoff between them. The customer simply experiences a failed checkout.
That is why the gap between authentication success and transaction completion matters.
When a shopper has successfully authenticated but the merchant doesn’t receive the result, the distinction between “authentication failure” and “communication failure” can become invisible at the checkout. But Merchant Callback helps address that communication gap.
For PSPs and acquirers, that means an opportunity to provide merchants with a more resilient 3DS experience — particularly as commerce increasingly takes place on mobile devices and across fragmented browser and app journeys.
A small change with a meaningful commercial impact
Merchant Callback isn’t about adding another step to authentication. It’s about removing a point of uncertainty after authentication has already succeeded.
The bank has completed its security check. The shopper has done what was required. The remaining question is whether the merchant receives the answer.
With Merchant Callback, that answer can be delivered directly and securely to the merchant or PSP, even when the shopper’s browser cannot return it.
Because authentication success is only half the story. The real outcome is a transaction that can move forward.
The approval happened. Entersekt's 3-D Secure Server made sure it arrived.
Ready to take the next step?
Get into the details of Entersekt's 3-D Secure Server, or get in touch for more information.