{"section":"faq","requestedLocale":"en","requestedSlug":"why-was-the-user-id-requested-at-checkout-when-the-purchase-was-concluded","locale":"en","slug":"why-was-the-user-id-requested-at-checkout-when-the-purchase-was-concluded","path":"docs/en/faq/shopping/why-was-the-user-id-requested-at-checkout-when-the-purchase-was-concluded.md","branch":"main","content":"A security rule exists at checkout, regarding the SmartCheckout purchase facility.\n\nBecause SmartCheckout purchases can be completed using only the email address and the card CVV when the customer has already completed a purchase before, we restrict the number of unsuccessful attempts to conclude the purchase to 3 before asking the customer for their user ID.\n\n![LoginEN](https://cdn.statically.io/gh/vtexdocs/help-center-content/refs/heads/main/docs/en/faq/shopping/why-was-the-user-id-requested-at-checkout-when-the-purchase-was-concluded_1.png)\n\nIn other words, if the customer concludes the purchase using only the email and the CVV of the credit card, and if the operator’s approval does not occur after 3 consecutive attempts, a user ID screen is displayed so that the customer can continue trying to purchase. This countdown starts again when the customer logs in and successfully completes their purchase.\n\n> ⚠️ Requiring a new authentication is only related to the established limit of 3 unsuccessful purchase attempts with the same card. This means that, **regardless of the time interval between each attempt, authentication will be requested when the customer tries for the third time to end a purchase without success.**\n\nThis measure is aimed at the security of customer data against attacks and attempts at fraud.\n\nFor more information about data protection, visit [SmartCheckout Security](/en/tutorial/seguranca-do-smartcheckout--3SrJuuhrqwePUg1rp1exfB#)."}