The ECI (Electronic Commerce Indicator) value is provided by the issuer (ACS). It indicates the level of authentication that has been performed on the transaction. The ECI value received from the authentication is transmitted in the authorization request and also determines whether a transaction benefits from liability protection.
Visa, American Express, Discover/Diners, JCB, Credit Cards (VISA), UPI
| ECI | Description | Merchant Liability Shift |
|---|---|---|
| 05 | Cardholder authentication successful (this includes successful authentication using risk-based authentication and/or a dynamic password) | Yes |
| 06 | Merchant attempted to authenticate the cardholder
| Yes |
| 07 | Non-authenticated e-commerce transaction
| No |
MasterCard, Credit cards (Mastercard)
| ECI | Description | Merchant Liability Shift |
|---|---|---|
| 00 | Non-authenticated e-commerce transaction
| No |
| 01 | Merchant attempted to authenticate the cardholder and received authentication value (Accountholder Authentication Value (AVV)) | Yes |
| 02 | Cardholder authentication successful (this includes successful authentication using risk-based authentication and/or a dynamic password) | Yes |
| 04 | Data share only: non-authenticated e-commerce transaction but merchants have chosen to share data via the 3DS flow with the issuer to improve authorization approval rates | No |
| 06 | Acquirer exemption | No |
| 07 | Recurring payments might be applicable for initial or subsequent transaction)
| Yes |