Authentication

How individual end users authenticate to authorize actions, per src-functional-requirements §1.3.

Two paths

  • On the Eurosystem digital euro app: seamless authentication (public-key crypto + biometrics/PIN), letting the consumer stay in the merchant app for m-commerce without a visible redirect (FUR.16FUR.17). Default is still redirection; seamless auth is offered for selected use cases. E-commerce uses decoupled authentication (biometrics/PIN via a digital euro app notification) (FUR.18).
  • On a pilot PSP’s own proprietary app: PSP chooses its own strong customer authentication method (including EDIW support for online payments), subject to applicable regulatory/security requirements and the minimum UX requirements in src-user-journeys-ux-requirements (FUR.19FUR.20).

Offline

Relies on the device’s local authentication mechanism (digital euro app or proprietary app) — no server round-trip for the payment itself. Online connectivity is only needed for (de)funding or device-related operations (FUR.21).

online-and-offline-payments · pilot-psp · src-functional-requirements