American Express SafeKey®
Prevent fraud while reducing friction for online transactions
Overview
The growth of digital commerce has placed greater emphasis on Merchants and Issuers to enhance their fraud prevention techniques while ensuring their customers can transact quickly and easily on whatever device they choose.
American Express SafeKey 2.0 is a security solution that leverages the global industry standard, EMV® 3-D Secure, to detect and reduce online fraud—providing an extra layer of security when consumers shop through web browsers or in-app.
SafeKey 2.0 enables Merchants and Issuers to exchange detailed information, which helps reduce fraud and minimize the need for a one-time passcode—improving the user experience and reducing shopping cart abandonment.
Building consumer confidence can help expand your market reach. Enhanced fraud protection through SafeKey may encourage online customers to spend more and help grow your business. Enroll in SafeKey today!
EMV® is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo.
Benefits
Merchants
Reduce Fraud Liability
-
Transfers liability for fraud chargebacks on SafeKey authenticated and attempted transactions to the Issuer
-
Works alongside other tools to manage fraud
Increase Profitability
-
Helps customers feel more secure about online purchases potentially increasing their confidence to spend
Reduce Shopping Cart Abandonment
-
Allows Issuers to use additional data elements already part of the checkout process to authenticate a Cardmember without a ‘challenge’* reducing friction, leading to a higher conversion of sales
*A ‘challenge’ is when an Issuer can request the Cardmember to prove his/her identity, e.g. by use of a One-Time Passcode (OTP).
Issuers
Reduce Fraud
-
Lowers fraud with an extra layer of security
-
Leverages richer data to make smarter, more sophisticated risk decisions
Increase Sales
-
Helps increase Cardmember confidence by reducing friction leading to reduced
cart abandonment
Authenticate Securely
-
Richer data allows targeting of higher risk transactions where stronger customer authentication would be beneficial
-
Supports a variety of Cardmember authentication methods, including one-time passcodes, biometrics, and out-of-band
Cardmembers
- Helps protect against the fraudulent use of Cardmember details
-
Simplifies enrollment as Issuers will do this automatically for Cardmembers
-
Expands protection of SafeKey from web browsers to include in-app purchases
SafeKey Comparison
Features | SafeKey 3.1 | SafeKey 4.1 | ||||
---|---|---|---|---|---|---|
SafeKey 3.1
(EMV 3.1.0) |
SafeKey 3.2
(EMV 3.2.0) |
SafeKey 3.3
(EMV 3.3.0) |
SafeKey 3.4
(EMV 3.4.0) |
SafeKey 4.1
(EMV 4.2.0) |
SafeKey 4.2
(EMV 4.2.1) |
|
Based on industry-standard 3-D Secure |
|
Test |
|
|
Test |
|
Extra layer of security at checkout |
|
|||||
Payment authentication |
|
|||||
Browser-based authentication | ||||||
Flexibility for Issuers to use a variety of authentication methods (i.e. one-time passcodes, risk-based decisioning, etc.) | ||||||
Support for PSD2 compliance | ||||||
Support for more data elements promoting frictionless authentications | ||||||
App-based (in-app) enablement | Test | |||||
Nonpayment authentication | ||||||
Token-based transactions | ||||||
Out-of-band authentication | ||||||
Merchant initiated authentications | ||||||
Decoupled authentication | ||||||
PSD2 additional indicators | ||||||
Test | Test |
|
|
|||
Testing Safekey |
|
|
|
Note: SafeKey 1.0 will be decommissioned globally on 14 October 2022 (except for India). New SafeKey 1.0 certifications are no longer supported. Some SafeKey 2.0 features may require additional certification.
How It Works
Enrollment & Implementation
ACS & 3DS Server (MPI) Provider
-
Click here to register your company with the AMEX Enabled Program
(Please note SafeKey merchants DO NOT need to register and should contact their Payment Service Provider to set up SafeKey)
-
Confirmation email contains link to product enrollment form
-
Complete product enrollment form
-
Enroll one or more users to access the AMEX Enabled Dashboard
-
Log in to the AMEX Enabled Dashboard to access certification documentation
-
Access SafeKey Test Lab from AMEX Enabled to complete testing and certification of your solution
SDK
A Merchant’s app processes SafeKey transactions using a Software Development Kit (SDK). SDK Providers are required to enroll with American Express to provide proof of their EMVCo certification.
-
Click here to register your company with the AMEX Enabled Program
-
Confirmation email contains link to enrollment form
-
Complete enrollment form, provide your EMVCo SDK Reference Number(s)
-
Enroll users to access the AMEX Enabled Dashboard
-
Log in to the AMEX Enabled Dashboard and read the "SDK SafeKey Instructions" document for next steps
Issuer
Please contact your American Express representative if you would like to certify for SafeKey.
Acquirer
Please contact your American Express representative if you would like to certify for SafeKey.
Merchant
Engage 3DS Server (MPI) Provider
- See www.amexenabled.com for list of certified providers
- Integrate 3DS Server’s authentication flow into Merchant’s website
Note: 3DS Requestors are not required to enroll directly with American Express
ACS & 3DS Server (MPI) Provider
-
Click here to register your company with the AMEX Enabled Program
(Please note SafeKey merchants DO NOT need to register and should contact their Payment Service Provider to set up SafeKey)
-
Confirmation email contains link to product enrollment form
-
Complete product enrollment form
-
Enroll one or more users to access the AMEX Enabled Dashboard
-
Log in to the AMEX Enabled Dashboard to access certification documentation
-
Access SafeKey Test Lab from AMEX Enabled to complete testing and certification of your solution
SDK
A Merchant’s app processes SafeKey transactions using a Software Development Kit (SDK). SDK Providers are required to enroll with American Express to provide proof of their EMVCo certification.
-
Click here to register your company with the AMEX Enabled Program
-
Confirmation email contains link to enrollment form
-
Complete enrollment form, provide your EMVCo SDK Reference Number(s)
-
Enroll users to access the AMEX Enabled Dashboard
-
Log in to the AMEX Enabled Dashboard and read the "SDK SafeKey Instructions" document for next steps
Issuer
Please contact your American Express representative if you would like to certify for SafeKey.
Acquirer
Please contact your American Express representative if you would like to certify for SafeKey.
Merchant
Engage 3DS Server (MPI) Provider
- See www.amexenabled.com for list of certified providers
- Integrate 3DS Server’s authentication flow into Merchant’s website
Note: 3DS Requestors are not required to enroll directly with American Express