La valeur ECI est fournie par l'émetteur (ACS). Il indique le niveau d'authentification qui a été effectué sur la transaction. La valeur ECI reçue de l'authentification est transmise dans la demande d'autorisation et détermine également si une transaction bénéficie d'une protection de responsabilité.
Visa, American Express, Discover/Diners, JCB, Cartes Bancaires (VISA), UPI
| ECI | Description | Merchant Liability Shift |
|---|---|---|
| 05 | Cardholder authentication successful (this includes successful authentication using risk-based authentication and/or a dynamic password) | Yes |
| 06 | Merchant attempted to authenticate the cardholder
| Yes |
| 07 | Non-authenticated e-commerce transaction
| No |
MasterCard, Cartes Bancaires (Mastercard)
| ECI | Description | Merchant Liability Shift |
|---|---|---|
| 00 | Non-authenticated e-commerce transaction
| No |
| 01 | Merchant attempted to authenticate the cardholder and received authentication value (Accountholder Authentication Value (AVV)) | Yes |
| 02 | Cardholder authentication successful (this includes successful authentication using risk-based authentication and/or a dynamic password) | Yes |
| 04 | Data share only: non-authenticated e-commerce transaction but merchants have chosen to share data via the 3DS flow with the issuer to improve authorization approval rates | No |
| 06 | Acquirer exemption | No |
| 07 | Recurring payments might be applicable for initial or subsequent transaction)
| Yes |