ℹ️ This guide applies to one-time (single) card payments for stays under 90 nights, processed through Toss Payments.
For bookings under 90 nights paid via one-time payment, guests using VISA, MASTER, or JCB cards must complete 3DS (3-Domain Secure) authentication before the payment can be approved.
What is 3DS?
3DS is an international security standard used by card networks and issuing banks to verify that the person making the payment is the actual cardholder. It adds a layer of verification beyond the card number and CVC, typically completed through the cardholder's banking app or a one-time passcode sent by the issuer.
Authentication is branded differently depending on the card network. 👇
🔒 3DS Authentication by Card Network
Each network uses its own branded name for 3DS.
VISA Visa Secure
MASTER Mastercard Identity Check
JCB J/Secure
📋 Authentication Steps
- Step 1 Select "Credit / Debit card (Global)" as your payment method and enter your card details.
- Step 2 Your card-issuing bank runs an automatic risk assessment on the transaction.
✅ If the risk is assessed as low → the payment may be approved instantly without any extra step ("frictionless" authentication).
🔄 If the risk is higher, or your bank's policy requires it → the bank will send a "challenge" authentication request.
Depending on your bank and country, this may take one of the following forms:
- Push notification Approval request in your banking app (e.g., tapping "I want to pay")
- OTP (One-Time Password) Sent via SMS or email
- Biometric verification Fingerprint or Face ID within your banking app
- Security question A separate password registered with your bank
- Step 3 Review the transaction details shown on the verification screen, including the payment amount, merchant name ("TOSS*ENKORWITHUSCO.,LT"), and the last digits of your card.
- Step 4 Complete the authentication using whichever method your bank requires (app approval, OTP entry, biometric check, etc.).
- Step 5 Once authentication is successful, the payment is processed automatically and your booking is confirmed.
💬 Note on JCB & Mastercard
For JCB cards, the issuer may first attempt automatic verification using device and location data, only requesting OTP or biometric confirmation if needed.
Mastercard uses a similar risk-based approach called "Identity Check Insights" to determine whether additional authentication is required.
🛠 If You Get Stuck During Authentication
If you don't receive a push notification, the one-time code never arrives, or approval in your banking app keeps failing:
1️⃣ Contact your card-issuing bank's customer service first.
Since 3DS authentication is handled directly by your bank, only your bank can verify and resolve issues at this step.
2️⃣ If bank authentication succeeds but you encounter a payment gateway (PG) error afterward → contact Enkostay support.
This type of issue may relate to the payment system itself, and our team can look into it for you.
⚠️ Important Notes
- Authentication requests are sent directly by your card-issuing bank, so make sure your banking app is installed, updated, and that you're logged in (or that you have access to the phone number/email registered with your bank).
- If authentication is not completed within the time limit, the payment will fail and you will need to restart the booking process.
- The exact appearance of the 3DS verification screen varies by card issuer and country, but the underlying security process is the same across all supported banks.
※ Supported card networks: VISA, MASTER, JCB. Payments are processed through Toss Payments. For issues related to card authentication, please contact your card-issuing bank first.