Skip to main content
Mastercard · ECI Codes

Mastercard ECI Code 0: Authentication Failed or Not Attempted

Authentication failed or not attempted (e.g. card not enrolled, technical issue)

What it means

Mastercard ECI 0 (often represented as ECI 00) is an Electronic Commerce Indicator signifying that 3D Secure (3DS) authentication either failed, was not attempted, or could not be performed. Because the transaction lacks successful authentication data, there is no liability shift to the issuer, leaving the merchant fully liable for potential fraud. While ECI 0 is an authentication status rather than a hard authorization decline, proceeding to authorization with this indicator often leads to issuer declines and increased fraud risk.

Classification & retryability

technicalsoftRetryable: conditional

Do not automatically retry ECI 0 transactions in the same form. If the cause was a temporary timeout or configuration error, retry the transaction through the 3D Secure flow to achieve a successful authentication (aiming for Mastercard ECI 01 or 02). If the issuer does not support 3DS, assess your fraud risk tolerance before proceeding to authorization without a liability shift.

Common causes

  • The cardholder abandoned the 3D Secure challenge or closed the authentication window.
  • The issuing bank or the specific card product does not participate in the 3D Secure program.
  • A technical error, timeout, or misconfiguration occurred at the Access Control Server (ACS) or merchant 3DS server.
  • Merchant 3D Secure configuration issues prevented the transaction from being properly routed or executed.

How to resolve it

Verify that your 3D Secure implementation is correctly configured for Mastercard BIN ranges and is routing properly through your 3DS server. Investigate gateway logs for recurring technical errors, timeouts, or ACS failures that might be triggering ECI 0 responses. If the issuing bank simply does not support 3DS, decide whether to authorize the payment without a liability shift based on your internal risk thresholds, or require the customer to provide an alternative payment method.

For merchants

Monitor your payment logs for unexpected spikes in ECI 0 to catch 3DS integration breaks early. Configure your payment gateway or SmartRetry rules to either block these transactions, route them for alternative verification (like additional KYC), or re-trigger the 3DS flow to obtain ECI 01 or 02. Ensure your risk management policies explicitly account for the lack of a liability shift on these payments.

For customers

Ensure that pop-up blockers, security extensions, or network timeouts are not preventing the authentication window from loading. If the issue persists, contact the issuing bank to verify if the card supports 3D Secure, or use an alternative payment method.

Sources