# What is step-up authentication?

Source: https://kavralab.com/glossary/step-up-authentication/

**Step-up authentication** is asking a user for extra proof of identity, such as a one-time code, a passkey or a biometric check, only when a session or action carries more risk than usual. Low-risk users continue without friction. It is the practical middle ground between letting everything through and forcing every user through every check.

## How step-up authentication works

A user logs in once, with a password or a passkey, and the session starts at a certain level of trust. Most actions, like browsing or reading messages, stay within that level. Some actions need more: changing the email or password, adding a payee, withdrawing funds, viewing full card details. For those, the system asks for a second factor right then, even though the user is already logged in.

Step-up can also be triggered by risk rather than by the action. If a login comes from a new device on a new network in another country, the system can ask for extra proof before the session starts, while the same user on their usual phone goes straight in. This is often called risk-based or adaptive authentication.

Good step-up also learns: once a user passes, the device can be marked as trusted for that account, so the same person on the same phone is not asked again next week.

## Common triggers and step-up methods

| Trigger | Why it is risky | Typical step-up |
|---|---|---|
| Login from a new device and network | A classic sign of [account takeover](https://kavralab.com/glossary/account-takeover/) | One-time code or passkey |
| Change of email, phone or password | Attackers lock out the real owner this way | Passkey or code to the old contact |
| New payee or withdrawal address | Where stolen funds leave | Passkey or in-app approval |
| High-value or unusual payment | Card and account fraud | 3-D Secure challenge |
| Medium risk score at signup or checkout | Possible bot or spoofed device | Invisible challenge first, then a code |

## Step-up vs always-on MFA

Always-on multi-factor authentication asks every user for a second factor on every login. It is simple and strong, but it adds friction to every session, and users who face it constantly learn to approve prompts without thinking. Step-up keeps the extra check for the moments that need it, which makes each prompt meaningful.

The weak point of step-up is the decision about when to trigger it. If the risk signal is poor, attackers on a clean-looking session get through, and real customers are challenged for no reason. SMS codes also have limits: they can be phished or intercepted through SIM swaps, and sending them can be abused for SMS pumping. Passkeys and in-app approvals resist phishing better.

## How Kavra decides when to step up

Kavra gives your backend the signal that makes step-up precise. Each login or sensitive action is compared with the account's own history: known devices, usual networks, impossible travel, known-bad devices. It returns a recommendation to allow, verify or block, with the reasons. You trigger step-up on verify, and trusted devices per account keep regular customers free of prompts. See how it protects logins in [account takeover prevention](https://kavralab.com/solutions/account-takeover/) and [credential stuffing protection](https://kavralab.com/solutions/credential-stuffing/).

## FAQ

### What is the difference between step-up authentication and 2FA?

Two-factor authentication describes what is asked: two separate proofs of identity. Step-up describes when it is asked: only when an action or session carries extra risk. Step-up authentication usually uses a second factor, so the two work together. The difference is that step-up adds the factor on demand, instead of on every login.

### Is 3-D Secure a form of step-up authentication?

Yes. With 3-D Secure, the card issuer decides whether a payment can go through frictionlessly or needs the cardholder to confirm it, for example in their banking app. Under European strong customer authentication rules, this is how many online card payments are verified. For merchants, a successful challenge usually shifts fraud liability to the issuer.

### When should step-up authentication be triggered?

At actions where a mistake is costly and hard to undo, like changing account contact details, adding a payee or withdrawing money, and whenever a session looks different from the account's normal pattern: a new device, an unusual network, impossible travel or signs of automation. Everyone else should pass without an extra prompt.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
