Glossary

What is step-up authentication?

Step-up authentication is asking a user for extra proof of identity, such as a one-time code, a passkey or a biometric check, only when a session or action carries more risk than usual. Low-risk users continue without friction. It is the practical middle ground between letting everything through and forcing every user through every check.

How step-up authentication works

A user logs in once, with a password or a passkey, and the session starts at a certain level of trust. Most actions, like browsing or reading messages, stay within that level. Some actions need more: changing the email or password, adding a payee, withdrawing funds, viewing full card details. For those, the system asks for a second factor right then, even though the user is already logged in.

Step-up can also be triggered by risk rather than by the action. If a login comes from a new device on a new network in another country, the system can ask for extra proof before the session starts, while the same user on their usual phone goes straight in. This is often called risk-based or adaptive authentication.

Good step-up also learns: once a user passes, the device can be marked as trusted for that account, so the same person on the same phone is not asked again next week.

Common triggers and step-up methods

TriggerWhy it is riskyTypical step-up
Login from a new device and networkA classic sign of account takeoverOne-time code or passkey
Change of email, phone or passwordAttackers lock out the real owner this wayPasskey or code to the old contact
New payee or withdrawal addressWhere stolen funds leavePasskey or in-app approval
High-value or unusual paymentCard and account fraud3-D Secure challenge
Medium risk score at signup or checkoutPossible bot or spoofed deviceInvisible challenge first, then a code

Step-up vs always-on MFA

Always-on multi-factor authentication asks every user for a second factor on every login. It is simple and strong, but it adds friction to every session, and users who face it constantly learn to approve prompts without thinking. Step-up keeps the extra check for the moments that need it, which makes each prompt meaningful.

The weak point of step-up is the decision about when to trigger it. If the risk signal is poor, attackers on a clean-looking session get through, and real customers are challenged for no reason. SMS codes also have limits: they can be phished or intercepted through SIM swaps, and sending them can be abused for SMS pumping. Passkeys and in-app approvals resist phishing better.

How Kavra decides when to step up

Kavra gives your backend the signal that makes step-up precise. Each login or sensitive action is compared with the account's own history: known devices, usual networks, impossible travel, known-bad devices. It returns a recommendation to allow, verify or block, with the reasons. You trigger step-up on verify, and trusted devices per account keep regular customers free of prompts. See how it protects logins in account takeover prevention and credential stuffing protection.

FAQ

Frequently asked questions

Something else? Talk to our team.

What is the difference between step-up authentication and 2FA?

Two-factor authentication describes what is asked: two separate proofs of identity. Step-up describes when it is asked: only when an action or session carries extra risk. Step-up authentication usually uses a second factor, so the two work together. The difference is that step-up adds the factor on demand, instead of on every login.

Is 3-D Secure a form of step-up authentication?

Yes. With 3-D Secure, the card issuer decides whether a payment can go through frictionlessly or needs the cardholder to confirm it, for example in their banking app. Under European strong customer authentication rules, this is how many online card payments are verified. For merchants, a successful challenge usually shifts fraud liability to the issuer.

When should step-up authentication be triggered?

At actions where a mistake is costly and hard to undo, like changing account contact details, adding a payee or withdrawing money, and whenever a session looks different from the account's normal pattern: a new device, an unusual network, impossible travel or signs of automation. Everyone else should pass without an extra prompt.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.