Treezor joins Shares to expand Banking Offering.Read more →

How does the SCA solution distributed by Treezor work?

The system combines at least two independent authentication factors (something I know, something I have, something I am) and adapts to the sensitivity of each operation.

1

Step 1: Device enrollment (validation of the “possession” factor)

During onboarding, a component representing the device’s identity is created locally:

  • Via WebNative / WebAuthn: Creation of a Passkey secured by the device.
  • Via Mobile SDK: Creation of a dedicated digital vault within the application.

This component generates and stores unique asymmetric cryptographic keys.

2

Step 2 : User prompting (“Knowledge” or “Inherence” factor)

When a sensitive operation is initiated, the second factor is required. The mobile SDK or WebAuthn protocol prompts the user to validate their identity via their PIN code (knowledge factor) or biometrics (inherence factor), seamlessly leveraging the device’s native interfaces.

3

Step 3: Cryptographic signature using a private key (SCA Proof / JWS)

Once authenticated locally by the device’s secure environment, the Passkey or SDK uses its private key to generate a cryptographic signature (JSON Web Signature – JWS). This serves as tamper-proof authentication proof.

4

Step 4: Validation by the Treezor API

The SCA proof (JWS) is transmitted along with the request to the Treezor API. Treezor verifies the authenticity of the signature using the associated public key. If the proof is valid, Treezor securely authorizes the financial operation or account access.

Key figures

2

factors at least combined for each authentication

5

minute-validity for the active session, automatically renewed with each API action

180

days of exemption validity for per-session account consultation

100%

regulatory compliance with PSD2 / RTS

Key features of Treezor’s SCA solution

Treezor’s SCA solution stands out with four key elements:

1

Asymmetric cryptographic security: By generating private keys stored in a local digital vault (SCA Wallet), SCA proofs (JWS) guarantee non-repudiation and absolute protection for every transaction payload.

 

2

Delegated Mode or Standard Mode: If you already have your own approved SCA solution, Treezor offers a delegated mode subject to a compliance audit. If not, you can benefit from Treezor’s turnkey standard mode.

3

Lifecycle management & Fraud prevention: Full control via API and Dashboard allowing you to instantly block an SCA Wallet in case of suspected fraud, reset a PIN code, or unblock a device seamlessly.

4

Cross-platform & integration flexibility: We offer universal coverage thanks to our WebNative (WebAuthn) solution. Based on Passkey technology, it operates in a fully omnichannel manner: on desktop web browsers as well as natively on mobile devices (Android and iOS). For specific integration needs at the core of your applications, we also provide native SDKs (iOS, Android) and hybrid bridges (React Native, Flutter, Capacitor).

Treezor’s two SCA integration modes

To perfectly adapt to your technical architecture and user journeys, Treezor offers two complementary approaches to implementing strong authentication:

 The WebNative solution (recommended for universal coverage)

Based on the global standard WebAuthn (Passkeys & Passcode), the WebNative solution is the most versatile and modern approach.

  • Multi-device & Omnichannel: Natively compatible with Web browsers (Desktop), Mobile Web sites, and directly usable within your mobile applications (via embedded web views / In-App Browsers). Also works natively via Passkeys.
  • Smooth user journey: Leverages native device biometrics (Face ID, Touch ID, Windows Hello) or lock code (Passcode) without installing additional SDKs. Uses mobile-linked authentication methods via passkeys.
  • Fast implementation: A single integration based on web standards to cover all your screens.

The Mobile SDK solution (For native control within the application)

Dedicated to businesses operating primarily through a proprietary mobile app and seeking maximum visual and technical customization.

  • Native mobile integration: Native SDKs for iOS and Android.
  • Support for hybrid frameworks: Bridges available for React Native, Flutter, and Capacitor.
  • Experience control: Direct management of the local digital vault and deep integration into the mobile app.

Pourquoi utiliser la solution SCA de Treezor ?

Regulatory compliance: Fully comply with the obligations of the European PSD2 Directive (EU 2015/2366) and RTS standards, validated by the Banque de France and European regulators.

Enhanced fraud protection: Drastically reduce the risks of identity theft and payment data theft through systematic validation of every sensitive action on behalf of the end user.

Optimized and native User Experience (UX): Authentication occurs directly through the device’s system interfaces (PIN code and biometrics), offering a familiar, frictionless journey. Furthermore, intelligent session management (180-day exemption for consultation and 5-minute active session with automatic renewal) restricts strong authentication to high-risk operations only.

To facilitate deployment, Treezor accompanies you through the technical and functional setup of SCA in your applications.

Discover our technical documentation

DocumentationAPI Reference

Let’s talk about your project! 

Do you want to grow your payment project? Just fill out this form. One of our experts will contact you as soon as possible.

 

Contact our experts
iPhone 1 iPhone 2 image/svg+xml