A subscription renewal fails with authentication_required when the customer's bank wants a 3D Secure confirmation for that charge, and the customer isn't there to give it. It happens mostly with cards issued in Europe and the UK, where Strong Customer Authentication (SCA) rules apply. Retrying won't help: the bank will keep asking for the same confirmation. The only fix is to get the customer to open a page and approve the payment themselves.
Renewals are normally exempt. When the customer authenticates at signup and agrees to future charges, later renewals can go through as merchant-initiated transactions without a new challenge. But the issuing bank has the final say, and some banks ask for authentication anyway. Usually it's on a larger amount, after a price change, or after the card was replaced.
How many of your failures are 3D Secure? Free audit, decline codes for the last 90 days.
Run free payment audit →How it shows up in Stripe
- The invoice's payment intent moves to
requires_actioninstead of failing outright. - The decline code on the charge, when there is one, is authentication_required.
- The subscription moves to past due, and Stripe's normal retries keep failing the same way.
If you see a sudden jump in these right after a price change, that's the cause: the new amount no longer matches what the customer authenticated, so the bank asks again.
How to get these payments confirmed
- Tell the customer right away, with a link. The link has to open a page where they can complete 3D Secure for that exact invoice. Stripe's hosted invoice page does this, and so does a payment page built with Stripe Elements that confirms the payment intent.
- Say what's happening in plain words. "Your bank needs you to confirm this payment" works much better than "authentication required". The customer has to expect a code from their bank app or an SMS.
- Turn on Stripe's 3D Secure emails if you don't have your own. In Billing settings, Stripe can email customers a link when a payment needs authentication. It's a single email, though, so add a reminder if the invoice is still unpaid a few days later.
- Don't retry on a schedule. Each retry is another declined attempt on the customer's statement and doesn't change anything.
3D Secure is a confirmation in the customer's bank app or by SMS code. It takes seconds once they know it's needed.
How to reduce them in the first place
- Authenticate properly at signup. Set up the subscription so the first payment or the saved card goes through 3D Secure, with the customer agreeing to future charges. Stripe Checkout and Stripe Billing do this by default. Custom integrations that save cards without it get many more challenges later.
- Warn before price changes. If the price goes up, tell customers beforehand. A charge that's different from what they agreed to is more likely to be challenged.
- Handle
requires_actionin your integration. If your code treats it as a plain failure and stops, the customer never gets the chance to confirm.
For the other reasons renewals fail, see why Stripe payments fail. Rebounce detects authentication_required renewals, skips the useless retries, and sends the customer a link where they can confirm and pay, by email, SMS or WhatsApp.