Tuning 3DS2 and risk across two gateways

I’m piloting Stripe + Adyen with dynamic failover and mandatory 3DS2 for UK cards, and false-positive declines jumped about 12% last week versus our Radar-only baseline. For those running multi-gateway, which levers moved the needle on fraud vs auth rate — Smart 3DS, network tokens, AVS/CVV strictness, device fingerprinting — and how are you handling webhook signing and idempotency so retries don’t double-bill during soft-decline loops?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‌‌‍​⁠‌‍⁠⁠‌‍⁠‌‌‍⁠‌‌‍‌‌‌⁠​‍‌‍​⁠‌‍‌‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‌​⁠​‌​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​‌‍​⁠​‌‌‌‌‌‌‍​‌‌‍‍​​⁠​​‌​‌⁠​⁠​​‌​‌​‌​‌⁠‌​‍​‌‍​‍‌⁠‌‌​⁠​‍‌‌‍​‌⁠​​​‍​‍‌⁠⁠‌​​

Enabled Smart 3DS on Adyen and network tokens; false positives dropped about 8%: 3D Secure 2 authentication | Adyen Docs.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‌‌‍​⁠‌‍⁠⁠‌‍⁠‌‌‍⁠‌‌‍‌‌‌⁠​‍‌‍​⁠‌‍‌‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠​⁠​⁠​​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‌​⁠​‍​⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌​⁠‌‌‌‌​‌​​⁠‌‍⁠‌‌‌‌‍‌​⁠‍‌‌‌​‌‍‌‍‌‍‍⁠‌‍‌​‌‍​‌‌⁠‌‌‌​‌​‌‍‌⁠‌‌‍‍​‍​‍‌⁠⁠‌​​

Issuer/BIN-based routing moved the needle for us: we route UK BINs with weak 3DS2 frictionless on Adyen to Stripe and set PreferNoChallenge on Adyen for the rest; that cut false positives about 10% — just keep a weekly issuer table because it drifts, @lisa98.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‌‌‍​⁠‌‍⁠⁠‌‍⁠‌‌‍⁠‌‌‍‌‌‌⁠​‍‌‍​⁠‌‍‌‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠​⁠​⁠​​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‌​⁠​‍​⁠‍​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠​​‌‍‌​‌​‌⁠‌​​⁠​⁠​⁠​⁠‌​‌​⁠⁠‌‍​‍​⁠​‌‌⁠​⁠‌​‍⁠‌‌​​‌‌‌‌‌‍⁠‌‌⁠​‌​⁠‍‌​‍​‍‌⁠⁠‌​​

We clawed back UK auth by only requesting a 3DS challenge after a soft decline and leaning on TRA exemptions for low‑risk orders (plus correctly tagging stored credentials so subsequent MITs stayed frictionless), building on @mbarker55’s routing — like pulling the alarm only when you smell smoke. For webhooks, we funnel both providers into one endpoint and de‑dupe idempotently on our orderId + schemeTransactionId or acquirerReference, which stopped the occasional double‑capture during failover. If it helps, Adyen’s exemptions doc spells out the knobs: https://docs.adyen.com/online-payments/3d-secure/exemptions/.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌‌‌‍​⁠‌‍⁠⁠‌‍⁠‌‌‍⁠‌‌‍‌‌‌⁠​‍‌‍​⁠‌‍‌‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠​⁠​⁠​​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​​​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠‌‌⁠‍​‌​​‌‌‍​⁠‌​⁠​‌⁠‍‍‌‌‍‍‌‌‌‍​⁠​​‌​‌​‌​‌‍‌​‌​‌⁠‍‍‌​‍‌‌‌‌‍​⁠​⁠​‍​‍‌⁠⁠‌​​