Authentication

Authentication Outcomes

Electronic Commerce Indicator

The Electronic Commerce Indicator (ECI) is a value returned by Directory Servers (for example Visa, Mastercard, American Express, JCB), which represents the authentication outcome of 3D Secure 2 transactions.

A cryptogram is a unique value returned by Directory Servers when authentication is successful. The liability shifts to the issuing bank when 3D Secure authentication is successful, except for a few cases where it depends on the cryptogram being available from the card scheme's directory server.

Card schemes observe liability shift rules based on a combination of ECI values and the presence of the cryptogram in the response from the Directory Server.



Authentication Successful

The liability shifts to the issuing bank when authentication is successful (following the frictionless or challenge flow), except for a few cases where it depends on the cryptogram being available.

3D Secure Authentication Result

Electronic Commerce Indicator

Card Scheme

Liability Shift

Tip

Authentication Successful

05

Visa Amex JCB

YES



Authentication Successful

02 N2

Mastercard

YES



Authentication Successful

06

Mastercard

NO

ECI value of 06 from Mastercard indicates the transaction is out of scope for Secure Customer Authentication.

In this case, the merchant is not covered by liability shift.

Authentication Successful

06

Visa Amex JCB

YES

ECI value of 6 when received along with a cryptogram when authenticating Visa, Amex, JCB cards, indicates the authentication is successful.

Authentication Successful

01

Mastercard

YES

ECI value of 1 received while authenticating Mastercard cards, indicates the authentication is performed by a stand-in service, and is classed as successful.

In this case, the merchant is covered by liability shift.



Authentication Attempted but not Successful

3D Secure Authentication Result

Electronic Commerce Indicator

Card Scheme

Liability Shift

Tip

Authentication Attempted but not Successful

06

Visa Amex JCB

NO

ECI value of 6 when received without a cryptogram when authenticating Visa, Amex, JCB cards, indicates the authentication has not been successful.

In this case, the merchant is not covered by liability shift.

Authentication Attempted but not Successful

04

Mastercard

NO



Authentication Attempted but not Successful

01

Mastercard

NO

ECI value of 1 when received without a cryptogram when authenticating Mastercard cards, indicates the authentication has not been successful.

In this case, the merchant is not covered by liability shift.



Authentication could not be Performed

3D Secure Authentication Result

Electronic Commerce Indicator

Card Scheme

Liability Shift

Authentication could not be Performed

Any values not already listed

ANY

NO



Authentication Failed

3D Secure Authentication Result

Electronic Commerce Indicator

Card Scheme

Liability Shift

Authentication Failed

07 00

Visa Amex JCB

NO

Authentication Failed

NO

Mastercard

NO