(upbeat music) - Welcome to Payments on Fire, podcasts from Glenbrook Partners about the payment industry, how it works, and turns in its evolution. At Glenbrook Partners, we work with great organizations to improve the way they operate and use payment systems around the world. Our services range from commercial management consulting to educational programming and publishing, to financial inclusion advisory services for NGOs and philanthropies. If you'd like to discuss an issue in payments, please just reach out to us at
[email protected]. - Hi everyone, I'm Chris Uriardi. In October, 2024, my colleague Brian Durman joined me in hosting Payments on Fire episode number 249, which was titled Two Decades of 3D Secure, Can Strong Customer Authentication Seek Seed in the US and Unregulated Markets. The genesis of that episode came from some interesting research led by Alan Deepatra at the Global PSP Stripe. We thought it would be a great idea to invite Alan Deep on the show alongside the Vault Notey, the Chief Strategy Officer and Co-Founder of Enterseq, an authentication technology company that works with many large global banks to implement their authentication and risk management solutions. What resulted from that combination was a rich discussion focused on the challenges and realities of 3D secure for both merchants and issuers and parts of the world where strong customer authentication is not mandated, such as the United States. Now, fast forward 18 months, and I'm in deep in the team at Stripe have published the results of updated research. This time focused on authentication trends observed in regulated markets, such as the EU, UK, and Japan. Again, it sheds important light on how the payments ecosystem uses authentication, this time to satisfy regulatory requirements, while simultaneously preserving overall payments conversion and performance rates. So it would have been very easy to have another conversation with Alan Deep to discuss these updated findings. But a lot has evolved since our first discussions over two years ago. Network tokenization has taken the industry by storm. Agente commerce wasn't even a term two years ago, but has occupied a massive amount of payments thought leadership bandwidth over the past 12 months. Visa Mastercard implemented comprehensive frameworks to incentivize merchants to increase their use of authentication, and regulation, of course, has continued to evolve, including new countries, and enhanced rules for those who have been complying with those existing regulatory regimes for the past decade. All this said, the topic of payments authentication now goes well beyond 3D secure. So we said, let's give it another go, and invite Alan Deep into all back to the podcast to have a more holistic discussion about the modern challenges that the payments world faces when it comes to authentication. I'm happy to have with me today, Amadeep Bacher from Stripe, the Waldenulti from EnterSec, Amadeep, the vault. Welcome back to payments on fire. Good to have both of you with me. How are you guys today? - Doing great, thanks, Chris. Happy to be here and looking forward to the discussion. - Yeah, so it's good to have both of you back with us. I have to know a couple things. You guys are kind of a bit of a distinguished group. We have had some return guests to the podcast for sure. So that's one group there as well. So good to have you back. We saw you back about a year and a half, two years ago. But this might be the first time that we've actually had two guests from two different companies come back doing two episodes. We'll have to go back and check with the statisticians back at the Clempert-Ket office to validate whether this is the first time that's happened. But really glad to have you both with us because in this topic today, we're really gonna be focused on some of the really key trends we're seeing around authentication. You know, I wanted to have you guys back because you're so articulate and most importantly, you guys have boots on the ground, experience with this, dealing with real merchants, real banks, real data, you know, rather than just pontificating about some of this stuff. So I'm really, really excited to get into some of the details of what you guys are seeing out there in the market today. Particularly since, you know, this is a topic that has continued to evolve fairly significantly, even over the course of the last 18 months or so since we first chatted on this topic. So let's get into it. I'm not sure that we need to get really, really deep into both of your companies, but it would be good to get a little bit of a background just for everybody. So maybe get us started with a little bit about your role at InterSecq and what InterSecq does out there. - Thanks, Circus. Chief Strategy Officer for InterSecq. So that was one of the co-founders of the companies. So, you know, been around right from the start for the journey and we are a transaction authentication company. So we really focus on securing digital transactions across all channels, whether it's access to digital stores of value. So think about bank accounts, think about merchant accounts, any store of value. So authenticating access to that and then authenticating transactions or, you know, money movements or value movements from that store of value, the whether that's card or account-based payments, during authentication of those transactions as well. That's really kind of where we focus, which is why we refer to ourselves as the financial authentication company. We really kind of focus on that movement of value and securing that. - Great. I've been tracking you guys over the last several years and I think you guys have hit some big milestones just to give our listeners a bit of an idea of scale for you guys. I think last year I read that you guys have crossed the 10 billion transaction process mark per year. Is that right? - Yeah, yeah. No, it's certainly been an interesting ride. And yeah, I think we, I forget how many countries it is now that we can have covered across the globe. But, you know, Imiah, APEC, Europe, LATAM, North America. So we've got a pretty good footprint across the globe, across a number of different markets. And so, able to really kind of see the trends. It's very interesting to also see how you see these patterns, right? Certain fraud trends kind of always emerging kind of in certain markets. And then they kind of, you know, progress to others. So certainly interesting to see how these things kind of move across markets. - Yeah, for sure. And I'm indeed great to have you back with us and with the team at Stripe. I don't think I need to introduce Stripe as a company. And I think most of the folks in the payments industry are very familiar with Stripe. Just for context, there with Stripe, I took a look at a Colossan's latest annual letter, $1.9 trillion in total payments value in 2025, pretty significant. To put that into context, they say that that relates to about 1.6% of global GDP running through Stripe. That is pretty incredible for sure. But why don't you give us a little bit of background as your role there at Stripe, Amundi? - Yeah, absolutely. Chris, do all great to be here. And, you know, back on this podcast with our favorite topic. Take it secure, right? So, yes, Stripe's main motto is to go the GDP of the internet. And you've quoted the numbers from our annual letters from our founders. Specific to my role, so I'm Amundi, and I lead the payments performance team for the AMAIR region. Our team basically focus on building optimization strategies that support some of the largest and most strategic merchants that process on Stripe to help them, you know, increase their revenue by helping them optimize their payment acceptance across authentication, authorization, reducing fraud, helping them optimize for the network cost, and also help them in global expansion needs. So, yeah, we look at the full-fledged payments funnel across the multiple businesses and help them achieve their revenue targets and their not-starts that they have for them when it comes to payments performance. - Well, great to have you with us. I know you get some great exposure to some amazing data out there, so looking forward to your insights. I think we set the stage a little bit for today's topic, but I want to start with a very, very basic question because authentication is really the core thing that we're gonna be talking about today. In that word, I think has really morphed into a lot of different definitions to a lot of different people here in the payments industry. I think, obviously, when we first think about authentication in payments, 3D secure comes to mind first, right? But now there's a lot of other things, some of which we're gonna get deeper into today. So we have this concept of authenticated tokens, for example, you've got the concept of just authentication of tokens into maybe mobile wallets that provisioning. I think most consumers these days are familiar with that. Some people maybe think of authentication in more of kind of a regulatory context. So you very often hear this term strong customer authentication within the context of the European Union's PSD2, soon to be PSD3 and PSR. And we're seeing just this continued conversation around things like past keys or things that have been around for a long time like click to pay kind of being revived again with some announcements coming from MasterCard visa around the elimination of pens. And those are just some examples there, but that's a lot to start with. So we'll talk about a lot of these things today, but maybe the first question to all, I'll go to you. I mean, sounds like this conversation around authentication is getting a lot more complicated. I mean, how do you even start to address the realm of authentication and what that really means with
with your different customers that are out there, it just seems like it's getting incredibly complex to have this conversation these days. - It certainly evolved a lot, Chris. That's quite evident. Just if you take a step back and you can look at it, there's been a bit of an evolution that's kind of driving some of this complexity in the sense that you go back a couple of decades, payments were mostly initiated by an in-person transaction, and that was kind of like most of where you would kind of see that. And then it became too okay, the internet started kind of coming up and then it was pretty much a PC, but it was a PC at home, it kind of always stayed at the same place. And then with mobile, now you have this very powerful device in your hand that you can kind of like initiate a payment from, from anywhere, right? So the amount of places that you can actually initiate a payment from then, you know, becomes a lot wider. And then of course, just recently we decided to make it a little bit easier for ourselves by introducing something called agents that can transact on your behalf, right? And so I think the long and the short of it is the points of where transactions can be initiated from as evolved a lot. It certainly seemed a lot of growth. It's much more convenient obviously for the consumer, but that means that unfortunately, as you're planning for securing that and authenticating that to make sure that this is the right person making the payment, that does become a bit more complex in making sure you have to really think about all the different use cases and all the different technologies behind it. So I'd say the surface area that we have to cover when we think about authenticating payments has certainly evolved and an expanded lot, which kind of does bring with it a little bit of complexity. But at the same time, it's not like the tools we have at our exposure and has kind of stayed in the stone age while this was happening. So we also have a lot of more tools kind of available to us to make sure that we can authenticate these transactions in a secure way and in non-intrusive way. So I'd say yes, it's getting more complicated because there are more tools to master, but certainly it's not an unsolvable problem. And Amadev, I have to believe from sort of a service provider perspective working with merchants that this also really increases the complexity of the stack that you have to offer to these merchants. I think particularly in your role, if I'm in your seat in payments optimization payments performance, all of a sudden sort of the matrix of all of these in the way that they interact also becomes incredibly more complex, right? How do you guys view this? And how does this sort of change your world both in the way that you're servicing your customers and the way that you're looking at payments performance and optimization? - Yeah, I mean, as the world was quoting, a lot has changed and evolved since like, let's say authentication first started on online payments when we had probably only one way to apply these measures to really understand whether the card holder is who they say are. Ultimately, it is about showing the ID, but while making an online payment in an online context, is what authentication is solving for. But there has been a lot of evolutions across the globe. You touched upon strong customer authentication in context to PhD, do slash three or PSR now. So I'd say like the evolution has been there on the 3D secure rails itself when it comes to what can you do in the realm of authentication, right? From just being able to authenticate yourself, it has moved on from that to actually passing the real metadata around the transaction so that it's a security layer can be enabled around it to make sure that it is the right card holder in the right context making that transaction. So this has definitely added complexity. And when it comes to the regulated framework, the framework has really designed itself in a way that it has given how do you move from a monolithic way of authenticating to really defining some parameters if those exist around a transaction, then you quote it as a securely authenticated or strongly authenticated transaction, whereas if it is not there, it's not a strongly authenticated transaction. So two factor authentication is another kind of, let's say name or label that authentication has gotten in this market, whereas in certain, it's where it is not yet regulated, you don't say to a fair two factor authenticated multi factor authentication, you simply say 3DS, does it really mean anything? Sometimes yes, sometimes no, because it really depends on the factors that come into play. And to your question on the complexity, it has added for us as solution providers. So yeah, I think providing an authentication solution as part of your payments product stack has become like a table stake now. It is important that you have it. And the PSP model of 2026 is no longer just to be like a provider that moves money for businesses from A to B. It is actually that the PSP becomes that intelligent layer around like the merchant ecosystem, the issuers and the card networks. And you are able to make thousands of micro decisions at that stage when the transactions happen is what the PSP of today is like. And that's what we look at when we talk about payments performance. We look at the holistic life cycle of a transaction right from when somebody hits the pay button to all that goes behind the scene around the transaction metadata, two, the issuers, this transaction would go to and the scheme rules attracter and be able to intelligently make a decision whether you need an authentication in first place. If you need it, how you should apply it because the rails have evolved, it is not just purely asking for a challenge. There is much more that is now available. And then ultimately passing the information in the right way when it comes to authorization decisions. So it is all come to totality in a way when it comes to kind of the payments performance life cycle and strive what we do is we try to abstract that complexity from a merchant side and do things for them. Be the intelligent layer for that merchant that they don't have to worry about these micro decisions that are happening behind the scene. Rather, strive take that, look at our ecosystem, look at our overall portfolio of signals when it comes to different tools available and then apply it accordingly. So each transaction has become like a multi-decision making process before it could actually be a successful transaction. So lots of complexity, lots of decisions that need to be made. But we've mentioned 3D secure now a number of times, which I guess will consider to be the granddaddy of all payments, authentication, techniques that continues to evolve. And we see a lot of changes as you've noted in both kind of the protocol specs and how it is actually used. I'm curious though as to kind of your view around the current state of play with 3D secure from a merchant perspective, let's start there. Are merchants adopting it more? Are they adopting it less? Are they getting smarter at this? Is all these things that we're talking about making it more complicated such that 3D secure is it easier? Is it more difficult than it used to be? Would love to kind of hear your view on that. Yeah, sure. So I would say like overall, if we compare it to when the last spoke a few years ago to now, the usage of 3D secure has gone up definitely. And that's like going up globally. And there are multiple different factors depending upon the context of the market you refer to. But overall, we see so many things that have changed purely from a need of the regulation perspective or let's say the evolution that their networks have brought in. So if I start with the context of regulated markets, right? Inregulated markets like Europe, we have SCA as the underlying, let's say framework. But then you see like certain countries such as France, they have tightened the rules beyond like what the SCA needs were to really request 3D secure or need for an authentication on almost 100% of traffic when it comes to card hold-issuated payments. They even mentioned that they really want to see proper chaining of transaction when it comes to subscription-based payments that the first transaction has to be fully authenticated. And the transaction IDs should be chained well to those merchant-initiated transactions. So that has really played a factor in markets which are regulated to have like the usage of authentication protocols gone up. And 3D secure as it said is grand daddy is the main, let's say protocol even today, EMV 3DS, as we call it, is the main rail or a vehicle to apply that. So we see usage going up in those markets as a result of a change to the lay of the land of the rules. And then we also saw new markets that have become mandated since we last spoke. So we saw Japan mandating 3D secure only in April 2025. So there has been like a high volume of 3D secure in the APAC region purely because more markets are not there. And lastly, I would say when it comes to markets that are not yet regulated, where 3DS still is seen as, hey, 3DS skills friction, 3DS equals friction, let's avoid it or let's not use it. And then it is definitely required. In those markets, we have seen an evolution from the schemes now that there are more ways that you can use 3D secure without having a friction added to the card holders journey. So the reference of like 3DS data only protocol or like information only message. We've seen an uptick of that as well globally as a result of some network programs that have evolved. So all of that in totality has really
and have played its role in making sure like you know, we are seeing more 3D secure and more 3D secure means more data associated to a transaction. So overall good for an ecosystem perspective that you're seeing more data, more rich data because 3DS from a Rails perspective and design perspective can hold more metadata points, pointers as compared to how to encode the authorization rails of today. So with 3DS, the richer information is flowing to the system and like we see the update going up across the region. - Yeah, we're gonna get deeper into some of this nuance throughout the show today, but I think that's a great perspective in regard to the drivers that are doing this. So overall general uptick in the use of 3DS developed, one thing I think in our intro that we didn't hit upon, that's probably worth to remind our users is you and the team at UNERSAC historically have worked very closely on the institution side, on the FIs side, right? Providing authentication solutions to banks and to other financial institutions. You also work on the merchant side as well, important to note, but I think from the issuing side, right? What is the view that you're seeing from financial institutions? How are they looking at this evolution on the other side of the transaction? I mean, we've seen this growth as I'm on deep as given us some color about from the merchant perspective, have they continued to evolve? How are they keeping up with it? Yeah, and I think it's encouraging to start to see more uptake also from the merchant side. So a willingness to send through some of the data to the issuer because I think that's the part that I get a little excited about when I see what's happening in the industry is that three secure used to be, and I mean, even if you listen to how we've spoken about it here, it used to be the card holder authentication program or well protocol, right? In the sense that it was only used to challenge, mostly, you know, kind of you think about the first version of that kind of that that was rolled out to the secure one. And because of that, because it was always a challenge, it was perceived to be this thing that kind of introduced this friction to the card holder to the journey. What's starting to happen now, which is what really kind of excites me, is that because of the evolution of how the merchant platform is all starting to use this with things like that and only info only will get to that a bit later, and with the amount of data that the latest version of of three secure actually has that comes through from the merchant all the way to the issuer, you now get the point where the issuer is able to actually make the decision on a transaction without having to actually, you know, challenge the card holder. There's enough data many times in the transport, especially the transaction as the data that's actually sent by the merchant is good quality. That enables the issuer to actually make a decision frictionlessly. If you look at this is a returning user, we've seen the mini-times, everything's good, let's go, no challenge required, but it is authenticated. And that's a very different, very important thing, it's that these transactions are still authenticated, but they're done so silently. And what that means is that it now for the first time really like we're starting to kind of see that, that realization from both the merchant side and the issuing side, that hey, wait a minute, this isn't just a challenge mechanism, this is now a mechanism to actually optimize our authorization strategy. We can actually, if you send us the right data, you know, from our side, we can frictionlessly prove so there's no challenge really that, you know, there's no risk there if you send us the right data. And because we've seen this data and we've approved it, when it hits the authorization leg and there's a, you know, a cryptogram that says, hey, the issuer's seen this, everything's on Kidori, you know, UCN uplifted authorization rates. And that's the part where, you know, we're starting to see a realization slowly in the industry, but wait a minute, this has the ability to actually make more transactions become successful. And certainly what that means is, it's this chicken and egg kind of slow process there where the more transactions that merchants kind of send through to the issuer's, the issuer starts to invest more in the authentication space, there's more transactions coming through and so they invest more. And so the benefit kind of bolts and we're starting to seeing really, really good results there. So I think from an issuer perspective, there's excitement about the fact that, you know, more data is coming through. I certainly am seeing a lot of kind of investment in that area of, yeah, how do we optimize, how do we use this as a way to improve our authentication rates? How do we make sure that we can kind of use all the data that comes in here to understand our customers better and make their journeys, you know, if the returning kind of uses, good users, how do we use it to make their checkout experiences better? And so I'd say that V is really exciting because that means now more people can make more transactions without the frustration of either the client or a challenge transaction might you get to the sweet spot? - Yeah, so I think there's chicken and egg issue. We've talked about before, but I think it's really important to highlight. I think historically, like we've heard from merchants basically saying in these unregulated markets in particular, I don't want to use three to secure it out or I don't want to expand my 3D secure strategy because I'm not getting good quality results from issuers or I'm getting inconsistent results. And then we speak to issuers about it in these unregulated markets. We say, well, what are you doing to improve your results? And at the end of the day, we basically hear that maybe they're not investing at the level they should be investing because merchants are not using 3D secure to the level that they hope they would be. That's sort of situation, but I think you make the very good point that, I talked about 3D secure being the granddaddy of payment authentication. This is sort of not your grandfather's 3D secure anymore, this is not 3D secure V1, this is not the initial 3D secure V2, we're at a point that we've basically created a much more robust channel enhanced data to be sent to the issuer to make a much more informed decision in which they have perhaps the actual fallback to step up authentication still available to them, but it's not at the fault anymore, right? I think that's really where we are, is that right? - Absolutely, I think, Chris, and you touch on a couple of really important points here, right? Answer your direct question first. - Absolutely, right? It has evolved so much, and I mean, even if you look at some of the guidelines kind of provided by some of the schemes, you'll see that there's a push towards a certain authentication rate that they would like to see for best practices, right? To say like, hey, we'd like to see at least 80% of transactions frictionlessly approved, right? And so I think those are things that you can really kind of point you to say, it's not just a card hold of challenge kind of protocol anymore. It has really become a real time rich data sharing protocol and when implemented correctly, can really help you to optimize that authorization strategy. To just quickly address the point that you made earlier in terms of some of the unregulated markets, because I do think it's very important to perhaps, you know, just talk about that for a while. It was interesting in the sense that, from a merchant perspective, you were in a difficult position when three secure one was around, right? Because you at that stage, it was mostly a challenge card holder challenge mechanism. And what merchants at that stage experienced was, if you implemented, okay, you get liability shift, right? Which was something that the merchants kind of enjoyed. But the problem was that because it was always challenged, they saw some card abandonment. And the card abandonment of the consumers was at that point, so severe that, you know, they had to make a trade off to say, okay, should I send all of my transactions here? And it effectively became this thing where they would only send high risk transactions by this rail to the issuer. Now, let's take the viewpoint of the issuer then, and then the issuer starts to see, oh, if a transaction comes on three secure, it's always high risk. And so it became almost this thing around, you know, where because of the way that, you know, three secure was kind of implemented at the time, that the issuer at that stage was kind of looking at three secure, almost as a risk signal. You know, if someone's sending a three secure transactions, because it was risky, and then, you know, they would kind of implement it appropriately and then, you know, kind of keep it with a challenge. So the biggest change now, you know, that they're first starting to see here is kind of having to reverse that. And that's kind of the challenge that we have, right? And that perception of, oh, three secure is always challenge or you should only send high risk towards something to say, hey, actually, this is something where, if I send the right data, it can be a glide path for me, and it's not necessarily going to be a challenge. And there's even some programs like, you know, the in-for-ownual data-owney programs, where the issuer doesn't even have the ability to challenge. And so I think from that perspective, some of the evolution of the protocol has really kind of addressed some of that older challenges that we've kind of had as an industry to be like, okay, you know, as a merchant, I have to kind of choose, you know, between whether I want to use this or not, because it really kind of hit their conversion rates. Yeah. Lords now, something that can actually help them improve the conversion rate. So this issue that you bring up around, particularly in the unregulated markets of 3D security that as a risk signal versus what I would call
call a trust signal is really a big issue. And I'm a deep, I think this is one of the themes that came out of your initial research that first sparked our conversation a couple years ago. You did some very interesting research looking at how issuers were treating transactions in both the step up and the frictionless flows. And we'd love to just get a little bit of a recap for our audiences to what you found in the unregulated market as part of that research. Could you just bring us through that a little bit for our listeners and maybe didn't initially read it or didn't hear our first episode? - Yeah, sure. So basically what we did back in 24 was we did a pilot where we started requesting 3D secure on a set of transactions for select merchants. And what we identified at the time was when 3D secure was being applied on a transaction, almost all of those transactions were not being challenged, meaning they were going through the frictionless journey from a cardholder's perspective. So authentication successes were there, but the issuers were declining the authorization on those transactions at a higher rate. So ultimately there was no friction added. So when people think about 3D secured, they say, oh, 3D assist friction, we shouldn't be using it as a merchant because it kills conversion. But in this case, there wasn't any friction added at the first place, but still like there were a drop in the authorization rates. Now, I know that analysis was few months back now. The things have definitely evolved and I can touch on what we are seeing now. But back in those days, when we last spoke, we saw like a conversion drop on transaction when 3D secure was associated to a transaction in comparison to the ones where there was no 3D secure and they were going directly to authorization. So that is almost like a paradox it created, right? - Yeah. - On that day world is touching, right? That A3DS usage is already low in that market. Merchants have been selective in choosing when to use 3D secure when not to. The protocol which was originally designed to authenticate and prevent fraud was being used by issuers as a signal whether a fraud can be associated to a transaction, meaning it was perceived as high-risk transaction of 3D secure was associated to it. That created that paradox almost that, you know, like high-risk transactions coming in, there wasn't many mechanisms at that time, if you say, for like issuers to have a better user experience given to their card holders that when they challenged them, can they challenge beyond one time passwords? I don't think many issuers in the market at the time had invested in improving the user experience. So there were not many challenges anyways coming in. There was more frictionless transactions going through. But then the liability would have shifted to the merchant for those transactions. Is why like that, the actions were being declined. So that was the hypothesis of the time and is what was happening, right? So yeah, that's the recap. That's what we did in grade 24. But I mean, if I refresh on some of what's we are seeing now, we definitely see the authorization rates going up even in the non-regulated markets for when secure is applied on a transaction. And I think there is a lot of attributions which are playing its role to why probably a slight shift is happening. Even in unregulated markets, we touch parts of that. The world says the invisible authentication exists now, which is the data only or information only flow. And the acceptance of that coming in with network programs now across the globe, especially in the unregulated markets, we are seeing that more 3D secured data is being passed to the issuers and issuers are honoring that. There is also, I think, more investments done by like issuers in those unregulated markets to build in some biometrics based authentication, for example. Now the protocol has evolved. It supports in app to app redirect. So the redirect almost looks invisible from a cardholder's perspective when you even go through a challenge journey. So there are more let's say issuers who have those type of technologies now available within their own banking apps that is playing its role. So we are seeing the uptick as compared to how things were in the past. But the uses is pretty low. The data set is still small. So I think there is more work to be done by the ecosystem in those markets ultimately is how we would see it. But it's probably trending in a good direction. So let me recap this evolution that we've been talking about in some of the behaviors that you've seen, which I think speaks directly to the point that the wall made. I'm an issuer in an unregulated market. I have this 3DS system, the Southernication system, which we call an ACS, right? An access control system sitting in the background, just sitting around, torturing its thumbs, waiting for transactions to come in. Rather small use across the US market. I think what we're saying sub 3% now or something along those lines get sent by a 3DS is that kind of what you guys are seeing. So small universe of transactions that are actually being sent to the issuer. When the issuer does see a transaction, it's most likely the most risky type of transaction because the logic on the merchant side has been, I'm not really sure about this transaction. This for whatever reason looks very risky. So now I'm going to send it down the 3DS path because I get a liability shift associated with that and I'll let the issuer do it with the authentication. And thus as a result, I mean, the issuer is only seeing a very small universe of transactions. And that universe of transactions that they are seeing are kind of dirty transactions. They're fairly risky transactions. But as you said, over the last couple of years, we've seen a little bit of an evolution in this unregulated market whereby I think, as you've both rightly noted, the protocol itself and the technology behind it has enabled better and more robust transfer of data, more seamless user experience based on the footprint, et cetera. So I think that's a really interesting story. I think what's also interesting is you decided this past year to continue your research and shift the focus onto regulated markets and to look at some of the behaviors there. And there are some really interesting findings I think that you found there. So why don't you take us through that because I think it's a really, really interesting compare and contrast scenario. Yeah, sure. So the last block that we released in 2025, we shifted our research to regulated markets. There were a few factors that were driving that. One of the key factor was that more markets were becoming mandated. So it was interesting to see like, OK, what might happen when 3D secure becomes mainstream in those markets. So I'll start with Japan first. So when we rolled it out, there was a lot of pre-work that was done by the ecosystem. So it wasn't that one fine day we flicked into started using 3D secure. I think the whole ecosystem worked together when it comes to merchant community. The issuers in there, the service providers and the card schemes to actually lay the groundwork around what will happen come April 2025 and the regulation will kick in or the mandate will kick in. And the results we saw from that mandate were promising. So what we saw was, yeah, the usage of 3D has almost quadrupled in that market after the mandate came in. The work fears around whether it will hurt conversion because initially there are hiccups. We have seen that in Europe and UK as well when initially SCA was rolled out over here. But like, yeah, those learnings were there with the participants when we were preparing for that. So leveraging on to that, we saw like, yes, after the mandate was applied, the conversion rate still stayed healthy in those markets. The secure was being applied to that. And ultimately, why 3D secure was mandated? It is all about combating fraud. I think every party in the ecosystem wants to see the fraud go down is why some of these mandates also exist when it comes to authentication. And what we saw in our data back when we did the research was we saw actually the dispute rates have started to go down significantly on those transactions where we were normally seeing disputes due to fraud. So it went down by 30%. It is still somewhere around that. So yeah, like very promising kind of outcome which we saw. The ultimate message was that when the universe participated, when the participants is your reversal, I mean, the results are promising. So it's not always about, hey, there is some additional fiction coming into the play. It is about how conversion can be maintained in a healthy manner across, let's say, the authentication aspects, the authorization aspects, and the fraud aspect. So I think in totality, we saw like healthy conversion on 3D transactions in that market and disputes went down. So that was one of the themes. We also double clicked on the usage of 3D secure in markets like Europe while we were doing the research or publishing that blog. And one interesting thing that was happening or taking place in France in particular was the central bank of France has mandated the stricter laws around usage of 3D secure. It had almost 100% of transactions to go to 3D secure. And for those who are familiar with strong customer authentication, it gives the ability to request exemptions. And exemptions mean that you can say that the transaction is either below a certain amount value or it's definitely low risk because every party in the ecosystem actually do some risk analysis on transactions. That it is lowest transaction. We don't think 3D secure challenge would be required on that transactions. Prior to that, mandated large proportion of those transactions where an exemption was available, we're going directly to authorization. They started to use 3D security as a
a protocol to request those exemptions because 3DS version 2.2 onwards, this is an option available. You could request different flavors of 3DS secure. That started to evolve in that market. We saw the uptake in the 3DS usage in France, but the conversions still stayed healthy because the exemptions were being honored basically by issuers. So ultimately, Amanda forces the need of doing certain things, certain ways, and that plays it part in the regulated markets. Yeah, and I think you've also seen some really, really good performance in the UK market as well in our analysis, which is a significant market to look at. I think you've also had some very good alignment between regulators and between issuers as well. I think the wall at this all really just supports everything that we've been talking about around the, basically the one thing that sticks out to me and tell me if I'm wrong here is this consistent use of 3DS in these markets. So you're seeing, of course, it's being done by mandate, of course, it's being done by regulation. But nonetheless, there is this consistent use of 3DS. And as a result, even though you have a very, very, very high number of transactions that are being pushed through the system, through 3DS, conversion is still maintained. And these scenarios, so it's, it sounds to me that this really supports everything that we're seeing. I mean, from the issuer side, are you seeing issuers in the regulated markets just getting smarter at this? What's interesting about the point that you make, right, is as a quick contrast between the unregulated versus regulated in the regulated market, you typically see a very high number of transactions kind of going through 3DS because it's mandated by it. And so the thing about that is that as an issuer, you start to see a lot of interactions with your cloud holders. So I start to get a very good idea of like, yeah, this is Chris. I've seen him a lot. This is normal frame. I started to get a sense of what's normal for Chris. And then when I see something that's out of the ordinary for Chris, that's easy to spot because I've got a lot of examples of what is good for Chris. In an unregulated market, what we saw there, you know, from an issuer's perspective is, if you're only sending bad transactions my way, it's very difficult to kind of distinguish, okay, but, you know, I mean, my models are trained that this is always bad. I never see good examples of data coming through. And so if you're sending more transactions through that rail, the issuer has more data to actually train the models and you actually didn't get rewarded for it because if the majority of the transactions that you send are good, guess what, the issuer starts to say, yeah, this is a good one. Yeah. So they start responding well because the model learns that hey, this is mostly good stuff coming through. But if you're only sending bad, guess what, you know, yeah, the signal to noise ratio changes here most stuff. Yeah. Right. Exactly. Right. And that's something that I mean, we've seen it in so many examples where that kind of approach of only sending high risk transactions, right, the recent one kind of the tokenization will also start to kind of, you know, trend that way there's this kind of thinking that, hey, you should only once you, when you issue the token the first time do, you know, authentication after that, you never have to think again. Guess what? That means it's only a high risk coming through and you never see any transactions after any good data after what do you think is going to happen, right? And so I think that the point kind of being that because in the regulated markets, you are forced by the regulator to actually send more transactions, your signal to noise ratio is forced by the regulator. Yeah. Have to work with transactions and then you see the results. And so that's why there's such an interesting opportunity kind of in the unregulated markets where the protocol does have the ability to have a really good outcome. But that means we have to kind of get the usage out. Yeah. So you mentioned tokenization. I think that's a great segue to that topic, which is increasingly laying an important part in authentication and risk decisions as well. I think just for our listeners here, our regular listeners to the podcast, know we talk a lot about tokenization here. Just to put us in context as to where we are now, Visa Mastercard love to talk about tokenization and their quarterly earnings reports. Last one that we've heard from Visa, Visa's now issued over 17 and a half billion tokens. They're saying that 50% of their network transactions are now tokenized and more than three times of many tokens have been issued as cards have been issued as well. Mastercard on the other hand, saying that over 30% of their transactions are tokenized, both networks continue to really stress the importance of tokenization from a security perspective, but also the benefits from an authorization uplift perspective, quoting anywhere from say three to 6% authorization uplift and then all the good stuff that comes along with tokenization related to life cycle management as well. So this continues to be a really, really hot topic for merchants. I'll say that also one of our most listened to podcasts of all times is still one that gets downloaded every day from like four years ago, which is called we can't stop talking about tokenization. And we really can't hear merchants can't stop talking about it either. It's sort of a tokenized world and we're just living in it. It seems sometimes from a merchant perspective. But though I think getting deeper into the context of authentication, maybe talk us through where tokenization fits into this conversation. Yeah. So it's an interesting one from the perspective that tokenization in and of itself, you know, it is right from the start and where it has a lot of let's say benefit when it comes to authentication is when you issue the token. First of all, there's the opportunity many times to do authentication at the point of issuing right. And so, you know, that's always the case, but let's just say that that is an option and many times that is the approach where before a card is tokenizing to a wallet or something like that, the card holder actually authenticates that action. So there's some security in terms of like where these tokens actually end up. And then the other thing that's very interesting about that is that, you know, with tokenization, you achieve a couple of things from a security perspective in that you can kind of limit the scope of, you know, where that token can be used. You can kind of limit the amount with what which merchants it can be used with. So you can really kind of make sure that when these tokens are issued, first of all, let's say the blast radius of when this thing when something goes wrong is limited, right. So that's a big benefit of that. And then the other side of it is if that token is compromised, right. So your storage, let's say kind of requirements around that is not as strict, right, because it's not the actual plan. It's just a token that's that's kind of linked to that that's caught, you know, in another itself. And so, so what that means is that from a storage perspective, if you're kind of holding onto a token, there are less, let's say there's less risk for you in terms of someone gets a hold of that token. And so, so there's a lot of benefits around that. And I think at the end of the day, when a transaction comes through and it's tokenized, right. And you can kind of look at the mandate, you can kind of look at the scope of the token. Those are all signals that kind of help inform the risk of the transaction as you're evaluating it from the issues perspective, right. In terms of making a decision of, hey, is this high risk, is this not. And so from that perspective, a very, very useful, let's say tool, right, when it comes to securing online transactions. But I think that that I have to call out here is tokenization secures the credential, right. So we've spoken about the fact that the credential itself that's being used to initiate the transaction can be, you know, secured with tokenization. That 3D secure still plays a very important role in actually authenticating the transactions that are then initiated using that token, right. And so you can kind of see that tokenization, 3 secure kind of are 2 complementing technologies, right. The 1 kind of securing the credential, making that more secure. And then the other one making sure that the transaction that is being performed with that token is secured. And I think many times there is a question in the market, are these two opposing forces, right. And that's not true. It's actually, they are focused on two very different things. One is about, you know, making the, the thing that's used to initiate the payment, you know, a bit more secure. And the other one's making sure that the person using that token to actually initiate the transaction is still the actual owner of it. So there's so many interesting things to dig into here. I just want to recap and maybe add a little color to a few things. I think one thing that you've pointed out is sort of not all tokens are created equal, right. Is we have two flavors of tokens when it comes to an authentication perspective. You can have a fully unauthenticated token. We're just emerging requests to token associated with a pan. There's no authentication steps there. There's no way of authenticating that the person who has presented you, the pan, is actually the owner of the account. So I think that's an important distinction to make to start with. And the other as we've been talking about is some forms of authenticated tokens were at token provisioning. And I think that's the key that you're hitting on here at token.
Disation provisioning there is an authentication that takes place, but that is this one time authentication that provisioning and you can go a week a month a year using that token and perhaps it's still good behavior, good card holder, good owner of the account. And then all of a sudden that same token or the use of that token in the wallet or card on file or something on those lines could effectively go bad, right? There could be a bad actor that takes over a device or an account or something along those lines. So I think the point that you're making is that's where 3D secure comes in is we're still authenticating on the transaction level beyond just the token issuance and thus these two kind of have to work together in a layered approach, right? There's a story there, Chris. I have a card that's kind of like my main card that I use my online purchase subscriptions all of that. And the one day I get the call, hey, you know, fraudulent transactions, suspected fraudulent transactions, sure enough I look at it and I'm like I didn't recognize these transactions and they're, you know, okay, we're going to reissue your card. And I remember I was kind of like where I stand in my office, I can kind of see the mailbox for my home office, right? And I see the mailman come and I know, oh yeah, that's that's delivering my card because you know you get the notification it's two stops away and just as I'm walking up, I mean that new card is still in the envelope, I haven't even opened it yet. Yeah, I think to myself, it's just right and so I opened the banking app and I look and sure enough, some more transactions that I don't recognize. I'm like that's strange. And so I call them again, I go, hey, I see some more transactions. Can you tell me is that are the new card or the old card? And they're like, no, no, that's on the new card and I'm like, well, I mean, I haven't even opened it. Now, I was that I was that okay. And they're like, now, can it will cast its new new card and I said, no, no, no, no, no, wait, wait, wait, where did those transactions come from? Oh, there's this wallet. There's this wallet where it's being, you know, initiated from, I was like, ah, so what you're going to do is that token that you've got in that wallet, can you disconnect that and then reissue my card. So we were very conveniently reissuing the token to the wallet that was compromised. And it was a wallet that I, you know, was an unauthenticated token. And so this kind of shows you that not all tokens, you know, equal and the thing is, you still have to have the ability to honor transaction that will look at and go, hey, this looks weird. This is strange and be able to authenticate when that happens. But yeah, that that was a very interesting kind of, you know, experience, especially standing with a brand new card in your ad unopened. And this will already again, on that same card. That's a great story. I want to transition a little bit to this topic of data only rails that we've mentioned several times before. It's a bit of a topic that folks have been in various circles, been very engaged with, have no nothing about our kind of whispering about. They've heard a little bit about it. I think this story is not exactly clear here. So I think I first like to take a look at what exactly are we talking about when we're mentioning data only rails. And you know, perhaps the wall, you could bring us through that first and the nominee by would love your perspective as well as to how you guys are thinking about this. Sure. And so I think data only is a version of off the 3CQ transaction where the merchant can initiate a transaction, which goes by the 3CQ rules rails. But it has a it's flagged as data only or information only. And what that means is the merchant is selling the issue. Hey, here's all the data that I would typically send you in a 3CQ transaction. But I don't want you to challenge. I don't want to shift liability to you. I just want to give you the data so that you can, you know, look at it and take it into consideration for authorization without, without kind of introducing the challenge. And so what happens in this case is the merchant is able to share the data to the issuer. The issuer can look at it and evaluate it risk score and all that without the merchant having the risk of a challenge, which then impacts the car abandonment risk that they have. So they can manage that risk. And then when there is a myth of transaction, when it gets to the authorization side, they can show with this data only transaction that, Hey, this is a transaction that we've actually sent you away. There is proof that we've actually sent it you away in the form of a cryptogram, which is something new that some of the programs are rolling out now. So you're able to effectively get the benefit of 3CQ without the risk of car abandonment from a merchant perspective when it comes to this. So you're sharing the data, informing the issuer and have proof of the fact that you've shared it with the issuer on the authorization side. The nuance here is that because you did not allow the the issuer the ability to actually challenge for those transactions, there's not a liability shift to the issuer because you're just using the data only. So you're saying, here's the data and your benefit that you get as the merchant is that you get the authorization reward in that you've already given them the transaction data and context on that. So it's kind of this golden midway of here's the data I can get the benefit of 3CQ without the bad side of 3CQ and I say bad side in terms of like the where issuer authentication implementations as a merchant I can actually now manage that risk to say, Hey, this transaction is probably low risk but instead of not sending advice to you secure, I'm going to give good examples over to the issue to to teach the issuer that I'm a good merchant without actually the risk of having you know, challenge and cost abandonment. So it's that golden midway that the networks have come up with you're going to get the the data to be shared and that authorization kind of benefit to to then take shape in in in unregulated markets. So I'm a deep I know that stripe and a number of other service providers out there kind of ranging from acquirers to fraud service providers have worked over the course of the last several years to improve merchant issuer data sharing through sort of proprietary more bilateral type arrangements but I think the difference here right is that this is actually using the standard eyes 3DS rails right. So how are you at stripe supporting this from a customer perspective and what observations have you seen thus far in the use of these data only rails. Yeah, so I think you have you have rightly outlined like the big benefit that 3DS secure in the data only rails brings it is that it standardizes the way in which the information exchange can happen. There is nothing that knew that has to be implemented by anybody in the ecosystem in order to support this because version two of the protocol since it existed. I'd say it started to be mainstream from version 2.1 but 2.2 actually brought it to the proper mainstream is when you have the ability to flag or 3DS secure transaction as an information only transaction. Was a specific version of this data only insights that existed in the market specifically by mastercard. So mastercard had its own program called I think identity check insights if I'm not wrong back in the days and it was built on the same framework that you have a specific sort of a pipe of data that you have built where you are only passing the information to the issuers for their informational use or read only use. They cannot challenge the card holder they cannot disrupt the checkout experience the card holder is going through. So that's what it has become now but in the mainstream meaning the main protocol has a specific challenge indicator that we can refer that this is a data only transaction. So it's being now I think supported by all schemes especially the major ones and they have the usage going up from their side in terms of the issuers that are on boarding onto adopting this. So we've seen that shift happening from when where things were I'd say in 2023-24 to where things are right now and as it becomes like an invisible authentication mechanism it kind of is like the golden passage as the world said or a best of both worlds when it comes to we know the transaction and we know there is associated to a transaction. A merchant does its own assessment, the service provider does its own assessment and based on that assessment we know whether this transaction actually is a high risk or not a high risk transaction then you can decide what sort of 3ds type that you want to request from the issuer on these transactions. Certainly if there is any risk signal associated to it as a PSP we would go through requesting a challenge and not use information only in those cases but in instances where we know the risk levels are low the transaction has kind of the data around it which is healthy we would request this and issuers actually get additional richer information because one 3ds secure is good at us the protocol supports multi-million fields I would say like under a different field so there is much more data that is pumped in through these rails as compared to authorization so there is more information that goes into the issuer so the issuers can also assess the transaction and the associated authorization when they see that in a better manner and make a decision on it. Yes issuers can
still decline the authorization. Sure. Of course, the actions, but at least from a card hold a perspective, there isn't an additional step that will come in the way from a 3D secure perspective. And I got to believe that like everything else in this 3DS world, though your performance, your mileage may vary based on the issuer, right? That the card is associated with because I think one of the questions we often get from merchants and sort of everybody else is, you know, what good is sending this data through the network if nobody's there to catch it and to look at it, right? So I think we're still in a, at a point where like everything else in 3D secure world and just general risk management altogether, issuer strategies, issuer sophistication, you know, issuer models, etc. very greatly from issuer to issuer. So I have to assume I'm a deep that you have seen variations in issuer performance, some issuers that are probably using this data quite in quite a sophisticated manner and others that are probably not using it at all, right? Yes. No, that definitely exists today. There is variance that comes into play depending on who the issuer is. And we have been working very closely with the, with the card networks as well, sharing what we see and the performance numbers that we get from using the data on relays rails. And as a result, we have seen that the card schemes have brought in newer programs that have brought in issuers into the mix for adopting these rails and making the benefit that they claim that it comes with it, which is more data. So network programs have also evolved across like the evolution of this rail has become mainstream. So we have now specific programs. I'm sure like we would touch on their digital commerce authentication program. Yeah, let's talk about that. I think this is a good segue to talk about this program that's been introduced by Visa, which is actually going into force this month here at least in the United States, but it is a proposed global program, which is called the decap, visa decap, visa digital commerce activation program. Of course, we know the card networks love these acronyms for these programs. My understanding of it is that it's a new program to essentially incentivize merchants to send enhanced data directly to the networks using these data only rails, right? We have some incentives through interchange savings there. And of course, the broader incentive that we've talked about is merchants should see better authorization performance as a result of it. But would love to kind of hear your take on the program and kind of any work that you've been doing with it thus far. Yes, I think it is a continuation to our kind of previous point about data only. So I think with with Visa's decap digital commerce authentication program, they're actually kind of trying to build like a layer of incentives for the ecosystem so that more usage of 3D secured on data on the days can happen. And if that happens, there are some benefits that they can pass to the ecosystem. So decap is bringing in some additional fields which are optional or conditional when you regularly use 3D secure into the mix. And if those fields are passed with the transaction over data on the rails, these incentives will will start to apply on those transactions. So things like device ID, IP address, card holders, email address, phone numbers in some markets. I think not in United States, but in markets like Canada, etc. and billing address. They are the core fields which currently are optional or conditional in like the protocol. Those fields, if they are passed to the transaction and sent via the information only rails, will get the benefit of lower interchange. So five bips of interchange is the incentive that is that decap is bringing in as a result of this program. I think in the core of it, I believe because Visa have done a few other programs as well before this decap come into the market. And it's timely we are talking about it. I think it's next week. It's going to be applicable in the US, 18th of April, I believe. So effectively Visa initially brought, I think a couple of years ago, brought in the data only program and made it a mandate for issuers to adopt it. Once they see the adoption is going up, the next thing is that a merchant starts to pass more information onto those rails. And that's what is probably going to happen using now this mechanism. The decap, just one last point to reference on decap is it will continue to apply to only card holder initiation initiation. That's what I was going to jump in and say if there's a lot of caveats to this program, right? And I think the topic of decap probably requires an hour conversation in and of itself, but it's important for merchants, I think, that are exploring this to speak to Visa, speak to their PSPs and their requires around this because, you know, number one, there's some important rules around the program. As you've said, CIT transactions only the other thing is it has some important economic implications here in regards to does provide a cost savings of 10 bips for eligible transactions, but there is also a program fee of five bips. So it kind of brings you to a five of BIP cost savings net. But then as we were talking about before, I'm on this also is coupled with a reduction in the US and interchange savings that have been traditionally associated with the use of tokenization work that tokenization savings is being reduced from 10 bips to five bips. So if you look at the five bips of tokenization savings, if you use tokenization and five bips on decap eligible transactions, that kind of brings you back to a 10 BIP savings. There's a lot to digest there folks, so take a look at that. I mean, it will definitely be a topic that we're going to be exploring. It's just the new ones that comes with many like programs that drop in at a different places is that this network tokenization incentive reduction from 10 bips to five bips, purely using just the network tokens is not directly within the decap program by Visa. It's a separate announcement. It's a separate initiative. That's a great point. Yeah. So if you combine these two together, then you as a merchant will see like, okay, what's my net savings by using this and that I would have loved for Visa to probably combine these things together and see like what's the totality saving for merchants. Yes. That would have made our life easier as well. But yeah, I mean, overall, I believe for listeners, I think when you look at decap, you should also look at the network tokenization based interchange reductions that they have announced, they combine together to give you the overall benefits in case it will apply. That's a really good point. I want to wrap up today on a couple quick hits here. A lot of things coming in the future, you know, these regulatory changes we've been talking about, programs like this, like that are being implemented by the card networks. But we've got the big forces that are working either with us or against us depending on how you're looking at it and what seat you're sitting in. What's the big big thing? Is one of them here, this again, a really, really big topic. You mentioned it before, what's some just high level quick hit considerations when we're thinking about authentication and agentic that we should be thinking about? Yes. You know, when it comes to, to agentic, one of the things that I come across a lot is that, not a lot of people really understand what that is, right? And, like, agentic commerce and then everyone's afraid, but nobody really knows why they're afraid. And I think one of the things that is important when we talk about agentic commerce is to actually define what it is, right? And there's, there are very well defined framework that agentic commerce will kind of, you know, follow. And so, I think we should probably be honest and kind of just remove the, you know, agentic fraud where you use an agent that uses a normal card to do a transaction from agentic commerce, which is where there's a very well defined program where, you know, merchants enable agents to act on behalf of consumers, right? For different types of transactions. And there are two main ones that I think we perhaps kind of need to call out. There's a, what they call an intent mandate. And so, this is where, you know, you're giving one of your agents, you know, a mandate based on an intent. So, so something like, hey, you know, there's a concert coming up that I want to attend. And it's going to be in two weeks from now. And I want you to bid for a ticket and you can buy it as long as it's kind of this section and lower than $150. So there, there's a mandate and an intent that I'm giving to this agent. And then the agent can kind of go in and negotiate and figure out how to get a ticket for $150. But that transaction happens in the future. But at the point of actually creating that mandate, there is a car holder authentication that happens to say, okay, I'm authentic. I'm proving that this is the mandate that I'm giving this agent. And there's typically a token associated with that that the agent can then use that there has limitations around it. And then the other one is a car mandate, which is one where as I'm shopping. So I'm actually doing shopping, but the agent is actually helping me to put a cart of things together, like, you know, shoes from here, whatever the case might be, like these are the items. So a cart is being put together. But as the car holder, I'm still involved in actually then approving the contents of the cart at the end when I check out. And so, yeah, who's not going to two mandates there that, you know, when it comes to agent commerce that's probably important to know.
know about. And I think it's important to also know that there's a whole framework that's been developed by I know players such as Stripe, I know you guys have been very involved with, you know, with some of the schemes and with some of the, with the W3C in terms of actually defining what that that framework looks like. And so I think it's very important to know that agentic commerce, the framework for is actually way very well thought out. And there's, there's very good tools to control that. And it shouldn't be confused with something like, you know, rogue agents to do transaction. Those are two very different things. So I appreciate that you're kind of talking about this high level and sort of generally because there are so many different frameworks out there. There's a lot of proposed standards. There's a lot of different ways in which they were. But I think the punchline here is you mentioned authentication has to curse at some point within all these different flows. So certainly the authentication conversation is going to continue as we talk about agentic. I'm on I know you guys have do all this said I've been working closely with a number of ecosystem players on agentic anything to add on this. Yeah, I mean, if you would have noticed our kind of annual letter, you would have seen like a section dedicated to a lot that's type as we are in building around agentic commerce. And now we have a working solution around it. So we have the agentic commerce suite that kind of provides the tooling for businesses to sell across multiple AI interfaces now. And as it rightly said, the protocols like not just this is not the only protocol. There are other protocols that exist as well. We've been working in making sure that we lay the foundation of a genetic in such a way that it becomes a system to be leveraged irrespective of what the protocol is around it. So we all cool on shared paper and payment tokens as we talked about tokens quite a bit. So that payments primitive. That's the agent initiate payments without exposing credentials slightly different from the network tokens that we spoke about. I mean, ultimately when you look at agentic and we talk about it, I think we are now in that AI powered world where everyone's doing the discovery using some form of a AI powered surface layer. The regular like Google search on things probably was the thing of the past. It is now very much heavily reliant on those services that that are AI powered. And we're not far from the time where you know, the world will be that the commerce becomes like it's already becoming semi-autonomous that will become fully, fully autonomous, right? That's that's what is being referenced in our in our annual letter as well. And when it comes to authentication, I guess like my thoughts on this is like authentication will become much more important than ever before with the advent of the agentic commerce because you would ultimately need some form of like human approval attached to the transaction that will be coming through any agentic channel, right? I believe like there is a layer that exists within the current frameworks, even within 3D secure, which could become mainstream as a result with all that is happening in the agentic world, especially like decoupled authentication. It exists from quite a while, but the use case has not yet become mainstream. This could well make it mainstream when it comes to kind of different forms of authentication. And yeah, they all refer to like the consents and intents. They all have to be some form of multifactored or authenticated at some stage. And I know like Pasquies are being seen as one possible vehicle in which all of this may work out. So we're working very closely with all of the cards schemes actually who are building their specific programs on the agentic layer to see what the what the art of the possible is in the future. Yeah, so guys, we've got a lot more to talk about and follow up episodes. Obviously, there's going to be no shortage of topics around agentic for sure. Decap we've talked about the evolution of token organization data only rails. We might have to come back in another 12 months just to revisit where we've been, but I appreciate you guys coming back on the show today. It's been a great discussion. I'm a deep mantra from Stripe, the Vault, Mil tea from EnterSec. Great to have you again and to all our listeners. Thanks very much for joining us today. Do good work and have a great day. Thank you very much. If you enjoy payments on fire, someone else might too. So please feel free to share this podcast on your favorite social media outlet. Payments on fire is a production of Glembruck Partners. Glembruck is a leading global consulting and education firm through the payments industry. Learn more and connect with us by visiting our website at glenbrook.com. All opinions expressed in our podcast are those of our hosts and guests. While companies featured or mentioned on our show may be clients of Glembruck, Glembruck receives no compensation for this podcast. No mention of any company or specific offering should be construed as an endorsement of that company's products or service.