If you use financial apps in Europe, you've probably noticed more verification steps popping up recently — a code sent to your phone, a fingerprint scan, or a prompt from an authenticator app. This isn't a bug or an extra hoop to jump through for no reason. It's called Strong Customer Authentication (SCA), and it's designed to keep your account and your money safer.
What is SCA?
Strong Customer Authentication is a security standard that requires verifying your identity using at least two independent factors before certain actions can go through. Rather than relying on a single password, SCA combines things like:
Something you know — a password or PIN
Something you have — your phone, a hardware key, or an authenticator app
Something you are — your fingerprint or face (biometrics)
The idea is simple: even if one factor is compromised — say, someone gets hold of your password — they still can't access your account or move your money without the second factor too.
How Bringin implements SCA
We've built SCA into the moments that matter most:
Logging in. After your email and password, you'll confirm it's really you with a passkey, an authenticator app, or an SMS code — whichever you've set up.
Activating your EUR account. Once your identity is verified, a quick verification step finishes activating your virtual Euro IBAN.
Buying into your wallet. Verification is now required at both the swap and withdrawal steps.
Sending euros. Every transfer is confirmed with a verification step before it goes through.
Setting up Buy/Sell Connections. Verification is part of getting this set up.
If your usual method isn't available — your phone was reset, or you're temporarily locked out of biometrics — you can always fall back to an SMS code, so you're never stuck.
Passkeys and authenticator apps: better than SMS
While SMS codes are supported as a fallback, we'd recommend setting up a passkey or an authenticator app instead:
Passkeys use your device's built-in biometrics or PIN. There's no code to type, and nothing that can be intercepted or phished — your device does the verifying. Passkeys are stored in the passkey manager of your choice (iCloud, Google Password manager, 1password, etc.). You unlock the passkey with your biometrics and you're good to go.
Authenticator apps generate a time-limited code directly on your phone, without relying on your mobile network. This means they're not vulnerable to SIM-swap attacks or SMS interception, which can affect text-message codes.
You can set up either method in Login & Security, in just a couple of minutes.
Why this matters
SCA is part of a broader regulatory push (including PSD2 in the EU) to reduce fraud in online payments and account access. For you, it means an extra layer of protection against unauthorized logins and transactions — with minimal added friction, especially once you've set up a passkey or authenticator app.
If you have any questions about setting up a verification method or run into an issue during a verification step, reach out to us and we'll help you sort it out.