When to Use
- Production environments with both a fraud provider and a 3DS provider configured.
- Risk-based authentication where you want to apply 3DS selectively based on fraud score rather than on every transaction.
- European payments that must comply with PSD2/SCA but where you want to minimize unnecessary 3DS challenges for low-risk transactions.
- Merchants processing a mix of transaction risk levels who need different handling for different risk tiers.
Flow Diagram
Step-by-Step Build Instructions
1. Create the Workflow
- Navigate to Workflow Studio in the admin portal sidebar.
- Click Create Workflow.
- Name your workflow (for example, “Full Authorization with Fraud and 3DS”).
2. Add the Start Authorize Trigger
- Click Add step on the canvas.
- Under Triggers, select Start Authorize.
- The trigger appears on the canvas as the entry point.
3. Add the Fraud Check Step
- Click Add step and select Fraud Check under Actions.
- Draw a connection line from Start Authorize to the Fraud Check step.
- Click the Fraud Check step to open its settings panel.
- Select your fraud provider from the Provider dropdown.
4. Handle Fraud Check Non-Completed Outcomes
Paused outcome:- Add a Notify step and connect it to the Paused outcome.
- Name it “Notify — Fraud Check Paused”.
- Add a Notify step and connect it to the Requested outcome.
- Name it “Notify — Fraud Check Requested”.
5. Add the Risk-Level Condition
This is the key decision point of the workflow. The Condition step evaluates the fraud result and routes the transaction into one of three risk tiers.- Click Add step and select Condition under Actions.
- Draw a connection line from the Completed outcome of Fraud Check to the Condition step.
- Click the Condition step to open its settings panel.
- Name it “Check Risk Level”.
6. Configure the Risk-Level Branches
Add two custom branches. The Default branch serves as the high-risk path. Low Risk branch:- Click Add Condition.
- Name the branch “Low Risk”.
- Define a rule that matches when the fraud assessment indicates low risk. Use the field dropdown to select the fraud result field, choose the appropriate operator, and set the threshold for low-risk transactions.
- Click Add Condition again.
- Name the branch “Medium Risk”.
- Define a rule that matches when the fraud assessment indicates medium risk — above the low-risk threshold but below the level you consider unacceptable.
7. Build the High-Risk Path (Default Branch)
High-risk transactions are rejected immediately without reaching a payment provider.- Add a Notify step and connect it to the Default branch.
- Name it “Notify — Fraud Rejected (High Risk)“.
8. Build the Low-Risk Path (Direct Authorization)
Low-risk transactions skip 3DS and go directly to authorization for the fastest checkout experience.- Click Add step and select Authorize under Actions.
- Draw a connection line from the Low Risk branch to the Authorize step.
- Click the Authorize step to open its settings panel.
- Select your payment provider from the Provider dropdown.
- Name the step “Authorize (Low Risk)” to distinguish it on the canvas.
Connect each outcome to its Notify step.
9. Build the Medium-Risk Path (3DS Then Authorization)
Medium-risk transactions require 3D Secure authentication before authorization. This adds cardholder verification for elevated-risk transactions while keeping the checkout frictionless for low-risk ones. Add the 3DS step:- Click Add step and select 3DS under Actions.
- Draw a connection line from the Medium Risk branch to the 3DS step.
- Click the 3DS step to open its settings panel.
- Select your 3DS provider from the Provider dropdown.
- Add a Notify step and connect it to the Paused outcome. Name it “Notify — 3DS Paused”.
- Add a Notify step and connect it to the Requested outcome. Name it “Notify — 3DS Requested”.
- Click Add step and select Condition under Actions.
- Draw a connection line from the Completed outcome of 3DS to the Condition step.
- Name it “Check 3DS Result”.
- Add a branch named “Authenticated” with a rule that matches successful 3DS authentication.
- The Default branch handles failed authentication.
- Add a Notify step and connect it to the Default branch.
- Name it “Notify — 3DS Not Authenticated”.
- Click Add step and select Authorize under Actions.
- Draw a connection line from the Authenticated branch to the Authorize step.
- Select your payment provider. Name the step “Authorize (Medium Risk + 3DS)”.
Connect each outcome to its Notify step.
10. Save and Activate
- Click Save.
- Review the entire canvas to confirm:
- Every Fraud Check outcome has a connected step.
- The risk-level Condition has all three branches (Low Risk, Medium Risk, Default) connected.
- On the low-risk path, every Authorize outcome has a Notify step.
- On the medium-risk path, every 3DS outcome has a connected step, the 3DS Condition has both branches connected, and every Authorize outcome has a Notify step.
- On the high-risk path, the Default branch connects to a Notify step.
- Activate the workflow when ready.
Understanding the Outcome Paths
This workflow has thirteen terminal paths. Every path ends with a Notify step.Fraud Check outcomes (2 paths)
High-risk path (1 path)
Low-risk path (4 paths)
Medium-risk path (6 paths)
Why Risk-Based Routing Matters
Applying 3DS to every transaction would maximize security but hurt conversion rates. Rejecting anything above the lowest risk would decline legitimate transactions. Risk-based routing lets you apply the right level of security for each transaction:
This approach concentrates friction where it matters most — on the transactions that need additional verification — while keeping the checkout smooth for your trusted customers.
Customization Ideas
- Adjust risk thresholds. Fine-tune the Low Risk and Medium Risk condition rules to match your business’s risk tolerance. Start with conservative thresholds and widen them as you gain confidence.
- Add more risk tiers. You can add additional condition branches for finer-grained routing — for example, a “Very Low Risk” tier that skips certain provider checks.
- Add a Fraud Update step. After the Authorize Completed outcome on both the low-risk and medium-risk paths, add a Fraud Update step to feed the authorization result back to the fraud provider. This improves future fraud scoring accuracy.
- Route to different providers by risk. Use different provider selections on the low-risk and medium-risk Authorize steps to route transactions to providers best suited for each risk tier.
Next Steps
- Review the Simple Authorization example if you want to start with a basic workflow and build up from there.
- See Authorization with Fraud Screening or Authorization with 3D Secure for simpler workflows that use just one of the two security steps.