Skip to main content
Mastercard

Mastercard

Mastercard ECI Code 01: Attempted Authentication

soft declinetechnical decline

Last updated: September 25, 2026

About 01 - "Authentication was attempted but not completed (e.g. timeout, user abandon)"

Key details

Brand
Mastercard
Code
01
Category
ECI Codes
Response
01
Detailed Response
Authentication was attempted but not completed (e.g. timeout, user abandon)
soft declinetechnical decline

What it means

Mastercard ECI Code 01 indicates that a payer-authentication flow was initiated, but the cardholder authentication could not be fully completed. This typically corresponds to a PARes status of 'A', meaning proof of the authentication attempt was generated despite an interruption like a timeout, user abandonment, or the issuer not participating. It is an authentication indicator passed to the subsequent authorization, rather than an authorization decline itself.

Classification & retryability

softtechnicalRetryable: conditional

Do not repeatedly resubmit the same payment authorization. Instead, consider one controlled re-authentication attempt if the root cause appears to be transient, such as a session timeout or customer abandonment during checkout.

Why does code 01 occur?

  • The cardholder abandoned the checkout process while the 3D Secure authentication window was open.
  • The authentication session timed out before the customer could successfully verify their identity.
  • Authentication was unavailable because the specific card or issuer is not currently participating in the program.

How to solve 01?

First, ensure your payment gateway integration correctly captured the attempted authentication data, including the directory-server transaction ID, raw ECI, and Mastercard UCAF authentication data. You must pass this data in your subsequent authorization request to qualify for a merchant-only liability shift and prevent the transaction from being downgraded or refused. If the issue is persistent across customers, verify that your 3D Secure integration is not prematurely timing out.

Solving as a merchant

Pass the complete set of authentication data (including the ECI 01 value and PARes status A) in the subsequent authorization request. Assess your risk tolerance, as this status generally grants a merchant-only liability shift rather than full protection. If the customer is still active in the checkout flow, you may prompt them to try authenticating again or offer an alternative payment method.

Solving as a customer

If you encountered a timeout or closed the verification window by mistake, please try completing the checkout process again. Alternatively, use a different payment method to finalize your purchase.

Tip from SmartRetry Avoid immediately forcing the cardholder back into a 3D Secure challenge, which frequently triggers cart abandonment. Instead, route the authorization forward using the captured attempt cryptogram to secure liability protection, only re-prompting the user if the issuer explicitly responds with a soft decline demanding full step-up authentication.

Frequently asked questions about this topic

Share this article

Share on XShare on FacebookShare on LinkedIn
Kyle Regacho

Author

Kyle Regacho
LinkedInFind me on Linkedin

Focused on payment recovery, decline codes, and authorization optimization at SmartRetry. Helps payment teams turn failed transactions into recovered revenue

Read all articles >
View all