ℹ️ This guide applies to one-time (single) card payments for stays under 90 nights, processed through Toss Payments.
For bookings under 90 nights paid via one-time payment, guests using VISA, MASTER, or JCB cards must complete 3DS (3-Domain Secure) authentication before the payment can be approved.
What is 3DS?
3DS is an international security standard used by card networks and issuing banks to verify that the person making the payment is the actual cardholder. It adds a layer of verification beyond the card number and CVC, typically completed through the cardholder's banking app or a one-time passcode sent by the issuer.
Authentication is branded differently depending on the card network. 👇
🔒 3DS Authentication by Card Network
Each network uses its own branded name for 3DS.
VISA Visa Secure
MASTER Mastercard Identity Check
JCB J/Secure
📋 How Authentication Works
- Step 1 Select "Credit / Debit card (Global)" as your payment method and enter your card details.
- Step 2 Your card-issuing bank runs an automatic risk assessment on the transaction.
✅ If the risk is assessed as low → the payment may be approved instantly without any extra step ("frictionless" authentication).
🔄 If the risk is higher, or your bank's policy requires it → the bank will send a "challenge" authentication request.
Depending on your bank and country, this may take one of the following forms:
- Push notification Approval request in your banking app (e.g., tapping "I want to pay")
- OTP (One-Time Password) Sent via SMS or email
- Biometric verification Fingerprint or Face ID within your banking app
- Security question A separate password registered with your bank
- Step 3 Review the transaction details shown on the verification screen, including the payment amount, merchant name ("TOSS*ENKORWITHUSCO.,LT"), and the last digits of your card.
- Step 4 Complete the authentication using whichever method your bank requires (app approval, OTP entry, biometric check, etc.).
- Step 5 Once authentication is successful, the payment is processed automatically and your booking is confirmed.
💬 Note on JCB & Mastercard
For JCB cards, the issuer may first attempt automatic verification using device and location data, only requesting OTP or biometric confirmation if needed.
Mastercard uses a similar risk-based approach called "Identity Check Insights" to determine whether additional authentication is required.
🛠 Payment Declined? Follow These Steps
Even if your card is active and works for everyday purchases, payments on Enkostay may still be declined. Follow the steps below in order — most issues are resolved by Step 1 or Step 2.
Step 1 — Quick Fixes You Can Try Right Now
These are the most common causes that you can resolve on your own, without contacting your bank.
🖥 Browser & Popup Issues
Your browser may be blocking the 3DS authentication popup from opening. If the popup never appears, authentication cannot begin — even though nothing is wrong with your card.
- Allow popups & cookies — In your browser settings, enable popup windows and allow cross-site cookies.
- Switch browser or use Incognito mode — Try Chrome, Safari, or Edge. Incognito / Private Window mode can also help.
- Disable extensions — Temporarily turn off ad-blockers, VPNs, and privacy extensions.
- Try a different device — If mobile doesn't work, try PC — and vice versa.
📩 OTP (One-Time Password) Not Arriving
If you're abroad or your bank's contact info is outdated, the SMS or email OTP may never reach you.
- Check roaming — If you're in Korea, make sure your home carrier's SMS roaming is active.
- Use an alternative method — Ask your bank if you can authenticate via banking app push notification, email OTP, or biometrics (fingerprint / Face ID) instead.
- Update your contact info — Confirm that the phone number and email registered with your bank are current.
📮 Billing Address Mismatch
If the address or ZIP code you enter doesn't match your bank's records, the fraud detection system may block the payment.
- Check the exact address and ZIP code in your bank account profile, and enter them in the payment form exactly as they appear — including spelling, formatting, and abbreviations.
✅ After trying the fixes above, attempt the payment again. If it still fails, move on to Step 2.
Step 2 — Settings Your Bank Needs to Fix
If the quick fixes didn't help, the issue is likely a restriction on your bank's side. These are settings that only your bank can change.
⚠️ 3D Secure (3DS) Not Enrolled or Blocked
Your card may not be enrolled in 3D Secure for overseas online transactions, or your bank may have placed a security block on this specific merchant — preventing the authentication step from even starting.
⚠️ Foreign Currency (KRW) / DCC Transactions Blocked
Your bank may have Dynamic Currency Conversion (DCC) or foreign currency transactions disabled. Since Enkostay processes payments in Korean Won (KRW), this restriction can cause the payment to be automatically declined — even though the card itself works fine for domestic purchases.
⚠️ Fraud Detection (FDS) Blocking the Transaction
Even if 3DS is enabled, your bank's fraud detection system may automatically block the transaction if it looks unusual — for example, a high-value payment on an overseas website you haven't used before.
📞 To resolve any of the above, you'll need to contact your bank directly. See the ready-to-use scripts in Step 3 below.
Step 3 — What to Tell Your Bank
Call your card-issuing bank's customer service and ask them to check the following. You can read these scripts directly to the agent:
1️⃣ Unblock KRW / DCC Transactions
"I am trying to make a payment in Korean Won (KRW) on a South Korean platform. Please check if there is a block on 'Dynamic Currency Conversion (DCC)' or foreign currency transactions and lift the restriction."
2️⃣ Unblock 3D Secure Authentication
"The payment is being declined during the 3D Secure authentication process. Please ensure my card is enrolled in 3D Secure for overseas online transactions, and if there is a security block on this specific merchant, please remove it so the payment can go through."
3️⃣ Remove Fraud Detection Hold (if applicable)
"I am attempting to make a legitimate payment on a South Korean online platform. Please remove any security hold on this transaction and allow the payment to go through for this merchant."
After confirming and updating these settings with your bank, please try the payment again. If the issue persists, please try using a different credit card.
💡 Still Need Help?
Authentication issue (OTP not arriving, popup not opening, bank app not responding)
→ Contact your card-issuing bank first. 3DS authentication is handled entirely by your bank — only they can verify and resolve it.
Bank authentication succeeded, but a payment gateway (PG) error appeared
→ Contact Enkostay support. This may be a system-side issue, and our team can look into it for you.
⚠️ Important Notes
- Make sure your banking app is installed, updated, and that you're logged in (or that you have access to the phone number / email registered with your bank) before starting the payment.
- If authentication is not completed within the time limit, the payment will fail and you will need to restart the booking process.
- The exact appearance of the 3DS verification screen varies by card issuer and country, but the underlying security process is the same across all supported banks.
- Even if your card works for everyday purchases, it may still be declined on Enkostay if your bank has separate restrictions on overseas merchants, KRW-denominated transactions, or 3D Secure enrollment. These are independent settings from your card's general activation status.
※ Supported card networks: VISA, MASTER, JCB. Payments are processed through Toss Payments. For issues related to card authentication, foreign currency blocks, or browser compatibility, please refer to the troubleshooting steps above or contact your card-issuing bank first.