Strong Customer Authentication (SCA) in Subscriptions for Shopify Checkout
Strong customer authentication (SCA) is a security requirement of the EU's revised Payment Service Directive (PSD2) for payment service providers operating within the European Economic Area (EEA). This requirement ensures that electronic payments are performed with multi-factor authentication to help reduce fraud and increase the security of electronic payments.
SCA is triggered by your customer's bank and requires that your customer authorize their payment. Authentication can be required at the time of initial checkout as well as for a recurring order.
Requirements
If your customer's initial payment triggers SCA they are required to authorize the payment in the checkout before the order will process successfully. For recurring orders, Shopify will send out an email to your customer with a link to authorize their payment.
If your customer does not receive their authorization email, they can login to the customer portal to generate a new link.
You can also enable the Payment Requires Strong Customer Authentication email notification in Bold Subscriptions so that your customer receives email reminders up until the time they authorize their payment. For more information, please visit Email Notifications.
Limitations
Orders pending SCA cannot be edited by customers or admins.
Customer perspective
If SCA is triggered, Shopify sends an email to your customer with a link to authorize their payment. Your customers are also able to authenticate the payment from within the customer portal.
If the link expires, they can generate a new link in their customer portal. This triggers a new email to be sent to the customer.
Example
Merchant perspective
If SCA authentication is still pending, a message is present on the customer's subscription in the Bold Subscriptions admin.
Example