You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

订阅支付SCA合规问题:3D Secure 2集成故障排查求助

How to Trigger 3D Secure 2 for Stripe Subscriptions (SCA Compliance)

Let's break down why your 3DS flow isn't triggering and how to fix it to meet SCA requirements:

Why 3DS Isn't Triggering in Your Current Code

Your implementation has two critical issues that block Stripe from initiating the 3D Secure flow:

  1. Duplicate Subscription Creation: You first create a Checkout Session (built to handle user payment and SCA), but then ignore that Session and manually create a Customer + Subscription using a Source. This skips the user-facing payment flow where 3DS would normally be triggered.
  2. Outdated Source API Usage: The Source API is deprecated in favor of PaymentMethod, and attaching a Source directly to a Customer in the backend doesn't trigger SCA. Stripe requires user interaction (like the Checkout page) to initiate 3D Secure authentication for transactions that mandate it.

Fixes to Enable 3DS & SCA Compliance

You need to lean fully into Stripe Checkout Sessions for your subscription flow—this is Stripe's recommended way to handle SCA-compliant payments, including 3DS. Here's how to adjust your code:

Step 1: Simplify Your Code to Use Checkout Session Exclusively

Remove the manual Customer/Subscription creation code. Instead, configure your Session to handle customer association and subscription setup, then redirect the user to the Session's URL to complete payment (where 3DS will trigger for required cards).

var api = Settings.Stripe.SecretKey_SK;
StripeConfiguration.ApiKey = api;

// Create Product (this part works as is)
var optionsProduct = new ProductCreateOptions {
  Name = "Medlemskab " + companies.Name,
  Type = "service",
};
var serviceProduct = new ProductService();
Product product = serviceProduct.Create(optionsProduct);

// Create Plan (this part works as is)
var optionsPlan = new PlanCreateOptions {
  Currency = "dkk",
  Interval = Interval,
  Nickname = "Medlemskab - OrderId: " + OrderId + " InterVal: " + Interval + " Name: " + companies.Name,
  Amount = amount,
  Product = product.Id,
  IntervalCount = getPricInfo.Months,
};
var servicePlan = new PlanService();
Plan plan = servicePlan.Create(optionsPlan);

// Configure Checkout Session to handle subscription + SCA
var options = new SessionCreateOptions {
  SuccessUrl = "https://www.xx.com/Members/Success?session_id={CHECKOUT_SESSION_ID}",
  CancelUrl = "https://www.xx.com/Members/Cancel", // Add a cancel URL for better user experience
  PaymentMethodTypes = new List<string> { "card", },
  CustomerEmail = model.Email, // Pre-fill customer email (use CustomerId if they already exist)
  SubscriptionData = new SessionSubscriptionDataOptions {
    Items = new List<SessionSubscriptionDataItemOptions> {
      new SessionSubscriptionDataItemOptions { PlanId = plan.Id },
    },
  },
};
var service = new SessionService();
Session session = service.Create(options);

// Redirect the user to Stripe's Checkout page (this is where 3DS will trigger)
// In ASP.NET, you'd implement this like:
return Redirect(session.Url);

Step 2: Handle Webhooks to Confirm Subscription Status

You can't rely on initial Session creation to confirm the subscription is active—you need to listen for Stripe webhooks, specifically the checkout.session.completed event. This event will notify you when the user has successfully completed payment (including 3DS) and the subscription is active.

  • In your Stripe Dashboard, set up a webhook endpoint (e.g., https://www.xx.com/Stripe/Webhook)
  • Listen for checkout.session.completed, then retrieve the subscription and customer details from the event to update your database.

Step 3: Test with the Required 3DS Card

When using the test card 4000-0000-0000-3220, Stripe's Checkout page will automatically trigger the 3D Secure flow. You can complete the test authentication by entering any 3-digit code when prompted.

Key Notes

  • Never skip the user-facing Checkout flow for SCA-compliant payments. Backend-only subscription creation won't trigger 3DS for cards that require it.
  • The Source API is deprecated—Stripe recommends using PaymentMethod via Checkout or Elements for all new integrations.

内容的提问来源于stack exchange,提问作者J. Petersen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 06:50:15